INTEL Intel Suspends Bug Bounty Program, Ending $100,000 Payouts NINTENDO Lufia I & II: The Sinistrals Saga Announced for PS5, Switch 2, and PC STEAM Dust till Dawn PC Game Announced With Akira Yamaoka Music STEAM Virtue and a Sledgehammer Launches October 27 on PC STEAM Marked for Mayhem Announced for PC: Beta Sign-ups Open Now GAMES PIO: A Robot’s Story Preview: Retro-Futuristic Soulslite at Tokyo Game Show GAMES Honkai Star Rail 4.6 Update Adds New Character Pearl and Astral Imagea Mode STEAM Really Illegal Golf Announced for PC: Stealth Mechanics Meet Multiplayer GAMES DJ Alan Walker Maxes Old School RuneScape Account Live at Ultra Live GAMES Kojima Productions PHYSINT Shifts to Xbox After Sony Drops Funding ANDROID Honor 600 Elite 5G lists with 8,100mAh battery and IP69K protection LINUX Valve Open-Sources Lepton to Run Android Games on Linux GAMES GTA 6 Features Rockstar’s Most Diverse NPC Population Yet PLAYSTATION 5 Dynasty Warriors 3 Remastered Demo Launches September 24 Ahead of October 1 Release

Intel Suspends Bug Bounty Program, Ending $100,000 Payouts

Simon Ellis 0 comments 2 min read

Intel has suspended its bug bounty program, ending payouts up to $100,000. The move shifts security research to an unpaid model amid AI- generated noise.

Intel logo and security shield graphic
SOFTWARE AND UPDATES

has shut down its long-running bug bounty program, a move that removes a reliable channel for security researchers to earn payouts for finding flaws in Intel products. This change matters because it shifts the burden of vulnerability discovery from a paid, structured system to an unpaid disclosure model, potentially reducing the volume of high-quality reports Intel receives. Researchers who previously relied on the program for income must now adjust their workflow or find alternative platforms for compensated security work.

Intel logo and security shield graphic
Intel has shut down its long-running bug bounty program.

Intel shifts to unpaid disclosure model as AI floods security research with low-quality submissions

The program, which launched in 2018, covered hardware, firmware, software, and open-source projects associated with Intel. It offered payouts of up to $100,000 for critical security vulnerabilities, incentivizing deep technical analysis of Intel's complex product stack. In 2020, the program was responsible for identifying 105 out of 231 CVEs addressed by the company, demonstrating its significant role in Intel's security posture during that period.

Intel has not provided an official explanation for the suspension, but the timing aligns with broader industry trends where AI-assisted research has flooded other bug bounty programs with low-quality submissions. Programs for the kernel and Curl have seen similar issues, where automated tools generate vast numbers of false positives or minor findings that overwhelm human triage teams. Intel appears to be reacting to this shift by ending the paid incentive structure that may no longer be cost-effective against AI-generated noise.

Security researchers can still submit vulnerabilities through Intel's new Intigriti disclosure program, but this channel does not offer financial compensation for their findings. This transition marks a clear departure from the previous model where substantial rewards were standard for critical flaws. The change reflects a pragmatic adjustment to the current landscape of automated vulnerability detection, prioritizing operational efficiency over paid research incentives.

Source: TweakTown

Discussion

0 comments

Leave a comment