Intel pulls the plug on its paid bug bounty programme
Intel has suspended the bug bounty programme that paid up to $100,000 for a serious flaw and replaced it with a disclosure programme that pays researchers nothing.

Intel has stopped paying for bug reports. The bug bounty programme it ran on the Intigriti platform, which paid researchers as much as $100,000 for a single serious flaw, now sits suspended and has been replaced by a disclosure programme that offers no money at all.
What Intel actually changed
The listing on Intigriti shows the programme as suspended, and the replacement tells researchers plainly: "This is a responsible disclosure program without bounties." Intel's own pages still carry the old terms, with awards "from $500 up to $100,000, based on quality of the report". The programme launched invite-only in 2017 and opened to all researchers in 2018, covering software, hardware, firmware and open-source projects, and Intel said almost half of the CVEs it addressed in 2020 - 105 out of 231 - arrived through it. Researchers can still submit vulnerabilities; they simply will not be paid for them. No reason was given, and AMD's page on the same platform is in the same state.
Why a chip giant stops paying for bugs
The timing is hard to miss. Security reporting has been swamped by AI-assisted submissions: Linux kernel CVEs have been approaching 2,000 per release against roughly 500 before, maintainers describe themselves as overwhelmed, Linus Torvalds has called duplicate AI-generated reports "almost entirely unmanageable", and the curl project shut its own bounty programme over the flood. When triage costs more than the flaw appears to be worth, the reward is the line item that gets cut.
What it means if you run Intel kit
Nothing changes about how flaws get fixed. Intel still wants reports and still patches what it can reproduce. What changes is the incentive: a researcher who finds something serious in firmware now chooses between an unpaid disclosure, a public write-up, or selling to a buyer who does pay. The same pressure is showing up across the industry, with HackerOne pausing submissions to its Internet Bug Bounty programme in March, citing AI-assisted research expanding discovery across the ecosystem.
Our opinion
Intel is entitled to stop paying, and it should not be surprised by what a zero-bounty programme signals. A bounty is not charity; it is queue management, and AI-generated noise has genuinely broken the queue. But the honest fix is better triage, not a smaller bill. Keeping the door open while removing the reward asks security researchers to work for free and calls it responsible disclosure, and the quiet risk is that the hardest, least glamorous reports - firmware, microcode, the stuff nobody writes blog posts about - are exactly the ones that stop arriving first. If that is the trade Intel has chosen, the next few months of patched CVEs will show it, and if the volume drops, so will the excuses.