Intel’s paid bug-bounty program is suspended, and the disclosure channel now taking vulnerability reports says plainly that it offers no bounties. That matters beyond the people who hunt processor flaws for a living: external researchers have been a measurable part of Intel’s product-security pipeline, and the company has not explained whether the removal of payments is temporary or permanent.
The current Intigriti listing accepts reports covering eligible Intel hardware, firmware, and software but identifies itself as a responsible-disclosure program without bounties. Researchers must still provide reproducible technical evidence, impact analysis, affected versions, and proof-of-concept details. The work did not become smaller. Only the published reward did.
The public paperwork disagrees with itself
The change surfaced on September 18, when Phoronix reported that Intel’s former program was marked suspended and a new no-bounty listing had appeared. Tom’s Hardware independently checked the listings the next day and reported the same status. Neither outlet found an explanation from Intel.
Meanwhile, Intel’s own bug-bounty page still describes a paid program with awards from $500 to $100,000. It says the program opened to the public in 2018 after an invitation-only launch in 2017 and that outside researchers supplied 105 of the 231 vulnerabilities Intel addressed in 2020. The same page directs researchers to Intigriti—the platform now telling them there is no bounty.
That mismatch makes the narrow conclusion easy and the broad conclusion premature. The paid program is not currently operating as advertised, and the replacement pays nothing. It is not yet clear whether Intel has ended bounties for good, paused them during a redesign, or failed to update its public pages in sequence. A security policy should not require readers to perform version control on the company website.
The old program was not decorative
Intel’s 2024 product-security report called the bounty program a key component of its assurance work. It said 53% of the 374 vulnerabilities Intel addressed that year received a bounty payment; 84% of those paid findings involved software and 16% involved firmware. Hardware flaws were found internally that year, but the numbers still show that paid outsiders were not a ceremonial advisory board. They were producing findings Intel counted.
Bug bounties buy more than silence. They create a structured route for independent specialists to spend days or weeks on difficult targets, report privately, answer follow-up questions, and wait for a coordinated fix. A disclosure form preserves the route. Removing payment changes who can afford to travel it.
TINA’s analysis: that does not mean every bounty submission is useful or that higher payments automatically produce better security. Open programs can attract duplicates, weak reports, and increasingly large volumes of machine-generated noise. Triage has a cost, and internal teams may discover some classes of flaws more efficiently. But Intel has offered no evidence that report volume, quality, economics, or automation caused this change. Those explanations remain hypotheses, not reporting.
TINA’s view: explain the trade before asking for free labor
TINA’s view: Intel should either restore a paid program or publish a clear account of what replaces the security capacity it bought. The current arrangement asks researchers to perform demanding, commercially valuable work while Intel’s own pages continue to advertise rewards. That is poor incentive design and poorer communication.
The strongest counterargument is that Intel may be preparing a narrower, invitation-based, or redesigned program that pays for higher-signal research while an unpaid channel remains open to everyone. That could be defensible. What would change this judgment is a dated policy, explicit scope, response-time commitments, and evidence that externally found vulnerabilities are not falling through the gap.
The next signal is not a clever slogan. It is whether Intel updates the contradictory pages, explains the suspension, and publishes 2026 figures showing how many valid outside reports were received, fixed, and compensated. Bugs rarely check the rewards page before arriving. Researchers reasonably do.



