Intel drops paid bug bounty program, offering researchers nothing but thanks

By: Anton Kratiuk | today, 13:50
Intel's bug bounty program, active since 2017, has been suspended with no replacement payment structure in place. Intel's bug bounty program, active since 2017, has been suspended with no replacement payment structure in place.. Source: Photo: Intel

Intel has shut down its paid bug bounty program, replacing it with a disclosure scheme that offers security researchers zero financial reward. The program, which ran since 2017 and paid between $500 and $100,000 per verified flaw, is now marked as suspended on its original platform. A new program hosted by Intigriti explicitly states "no bounties." Intel has given no public explanation.

The old program, by the numbers

The scale of what's been dropped matters. In 2020, 105 of Intel's 231 fixed vulnerabilities — 45% of the total — were sourced through the paid bounty program, per Phoronix. That's nearly half of the year's security fixes coming from outside researchers motivated, at least in part, by the prospect of payment. Hardware-level vulnerability research is slow, expensive work that typically requires months in a specialized lab. Professional researchers rarely do it for free.

Out of step with rivals

Intel's exit looks especially stark against what competitors are spending. Google paid $17.1 million to security researchers in 2025 — a 40% increase year-over-year, covering 747 researchers across 68 countries, according to Digital Shield. Apple offers up to $1 million for critical flaws. Microsoft and Meta have also increased bounty spending in recent years. Intel's old $100,000 maximum was already at the low end of the big-tech scale; now the number is zero.

Intel's bug bounty program, active since 2017, has been suspended with no replacement payment structure in place.
Intel's bug bounty program, active since 2017, has been suspended with no replacement payment structure in place.

Cost-cutting or something else?

One charitable reading: the transition to Intigriti was botched and the payment structure simply hasn't been reconnected yet. If that's the case, a correction should appear within days. But Tom's Hardware reports no sign of that — the suspension appears deliberate, consistent with Intel's broader cost-cutting push as the company navigates significant financial pressure.

A secondary theory floating in security circles: AI-generated vulnerability reports have flooded bug bounty inboxes across the industry. Curl, Nextcloud, and HackerOne have all paused or restructured programs for similar reasons. But even if AI noise is a genuine operational headache, the standard industry response has been to tighten submission rules — not eliminate payment entirely.

For everyday users, the immediate risk is abstract: fewer financial incentives mean fewer researchers hunting for the kind of deep chip-level bugs that affect millions of PCs, servers, and data centers running Intel silicon. That's a slow-burn concern, not an emergency — but it's a gap that rivals will be happy to let Intel own.