by

Intel axes bug bounty 

Intel has suspended its long-running bug bounty programme, replacing cash rewards of up to $100,000 with a loud-sounding nothing.

According to Tom’s Hardware, Chipzilla’s programme on security platform Intigriti is now marked as suspended, while its replacement offers researchers no financial rewards for finding holes. The new scheme describes itself as “a responsible disclosure programme without bounties,” meaning researchers can still report flaws but should not expect beer money.

Intel has not explained why it stopped paying researchers. Awkwardly, its website still advertises rewards ranging from $500 to $100,000. The older programme started as invitation-only in 2017 before opening to all eligible researchers in 2018, covering vulnerabilities in software, hardware, firmware and open-source projects.

In 2020, 105 of the 231 Common Vulnerabilities and Exposures addressed by Chipzilla came through the bounty programme, making outside researchers a useful part of its security operation. Chipzilla expanded the scheme during 2025 to cover web services and said in January it was evaluating “enhanced bounty and bonus criteria.”

Instead, eight months later, researchers seeking those enhanced bonuses have discovered the bounty cupboard is bare.

It might have something to do with AI. The wider security industry has been struggling with floods of low-quality AI-generated vulnerability reports. Linux creator Linus Torvalds has described duplicate AI reports reaching the kernel security list as “almost entirely unmanageable.”

Curl closed its bounty programme after being swamped with poor AI-generated reports, while HackerOne paused submissions to its Internet Bug Bounty programme in March.

Intel has not said AI reports caused its decision, and the problem may be less relevant to Chipzilla’s hardware and firmware work. Researchers can still submit vulnerabilities through the replacement programme; they just will not be paid, which makes the whole thing pointless.  It might be better to flog the bug on the dark web, but we would never suggest such a course of action.

 

 

TOPICS:
ai security  ·  bug bounty  ·  Chipzilla  ·  CVE  ·  cybersecurity  ·  Intel  ·  Intigriti  ·  Linux  ·  vulnerabilities

Latest articles

Share

Featured articles

Hot topics

No results found.

Latest reviews