Intel has suspended its paid bug-bounty program, which previously offered researchers $500 to $100,000 for valid vulnerability reports. The company’s Intigriti listing now operates as a responsible-disclosure channel without monetary rewards: researchers can continue reporting flaws, but Intel will not pay bounties. Intel has not publicly stated why it made the change.
Intel’s public information is inconsistent: a legacy bounty page remains online and marked as suspended, while other material still advertises financial rewards. The suspension follows wider pressure on vulnerability-reporting programs from duplicate and AI-generated submissions, affecting projects and services including the Linux kernel, curl, and HackerOne’s Internet Bug Bounty; however, no evidence links those issues to Intel’s decision.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
Linus Torvalds said that duplicate AI-generated reports had made the Linux kernel security mailing list nearly unmanageable.
Bug-bounty participants identified 105 of the 231 vulnerabilities Intel fixed during the year.
One year after launching the invitation-only program, Intel opened its bug-bounty program to all security researchers.
Intel launched its vulnerability-reward program, initially operating it on an invitation-only basis.
Intel suspended its paid bug-bounty program and changed its Intigriti listing to a no-bounty responsible-disclosure program. Researchers may continue reporting vulnerabilities, but Intel did not publicly explain why monetary rewards were suspended.
HackerOne paused acceptance of new submissions to its Internet Bug Bounty program, citing increased AI-assisted vulnerability discoveries.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.