Intel's Paid Bug Bounty Is Suspended, Replaced by Disclosure Without Rewards

Intel's Paid Bug Bounty Is Suspended, Replaced by Disclosure Without Rewards

Intel’s paid bug bounty programme, hosted on Intigriti, now displays as suspended. A replacement programme went live the following day carrying a single clarifying line:

“This is a responsible disclosure program without bounties.”

Intel has published no explanation.

What was there before

The former programme covered an unusually broad surface for a hardware company: hardware, software, firmware, and Intel’s open-source projects. Awards ranged from $500 to $100,000 depending on severity and component.

That range is not generous by industry standards at the top end, but the breadth was meaningful. Firmware and open-source coverage in particular gave researchers a sanctioned route to report findings in code that is genuinely hard to get paid attention for elsewhere.

The old programme page has been stripped of most of its detail. The Internet Archive retains earlier versions for anyone who needs the historical terms.

The likely pressure, stated carefully

No cause has been confirmed, and it is worth separating what is known from what is plausible.

Known: the paid programme is suspended and an unpaid disclosure programme replaced it.

Plausible, and widely suspected: the volume of AI-generated security reports now landing on maintainers and vendors across the industry has made paid triage expensive in a way it was not two years ago.

That pressure is real and documented elsewhere. Greg Kroah-Hartman warned that the 7.3 kernel cycle would be rough specifically because of AI-generated reports and patches, and the 7.3-rc4 release still carries that volume four candidates later.

A bounty programme inverts the economics badly under those conditions. Every submission must be assessed by a human, because you cannot pay out on an unreviewed claim, and a monetary reward is a direct incentive to submit volume. When generating a plausible-looking report costs a researcher almost nothing, the number of reports rises faster than the number of real bugs does, and the triage bill lands entirely on the vendor.

Removing the reward removes the incentive to submit noise. It also removes the incentive to submit signal, which is the problem.

What this costs

Bounties do not exist to be generous. They exist because the alternative market pays considerably more.

A researcher who finds a serious Intel firmware vulnerability has options: report it to Intel, sell it to a broker, or keep it. Removing payment from the first option does not remove the other two. It shifts the balance, and not in Intel’s favour.

There is a second cost that is easy to miss. A paid programme is a commitment to respond. Unpaid disclosure programmes have a well-earned reputation for reports disappearing into a queue, and researchers learn quickly which vendors are worth the effort of a careful writeup.

Context

This sits within a two-year contraction at Intel that has already touched a long list of open-source efforts, including the font project that was archived and then reinstated this month.

Security disclosure is a different category from a developer font. If the reason is cost, this is a more consequential place to find savings than most, and the effect will be measured in what does not get reported rather than in anything visible now.

If you are researching Intel products, the route still exists. It simply no longer pays.

Background reading

Explainers for the concepts behind this story.