Intel Has Ended Its Paid Bug Bounty Program
The technology firm transitioned to a disclosure-only platform that offers researchers no financial rewards.
Updated on Sept. 19, 2026 in Cybersecurity

Live Poll
Should companies continue to provide financial rewards to researchers who discover security vulnerabilities?
Intel has officially discontinued its bug bounty program, moving its vulnerability reporting to a new system hosted on the Intigriti platform. This change marks the end of financial incentives for security researchers who identify software, hardware, and firmware flaws.
Why it matters
The removal of monetary rewards alters the incentive structure for independent researchers who previously helped the company secure its products. While the new program facilitates vulnerability reporting, the absence of payments may impact participation rates for critical security discoveries.
The former program provided payouts ranging from $500 to $100,000 per reported flaw. Intel has now shifted its reporting process to the Intigriti platform, which does not offer financial compensation for submissions.
The players
Intel
This multinational technology corporation designs and manufactures computer processors and related hardware.
Intigriti
This organization operates a bug bounty and vulnerability disclosure platform for companies to manage security reports.
AMD
This semiconductor company designs computer processors and graphics technologies and currently has a suspended program on Intigriti.
The details
Intel previously maintained an open initiative that rewarded researchers for uncovering bugs across its software, hardware, firmware, and open-source projects. Other industry entities are facing similar shifts, as the HackerOne Internet Bug Bounty program paused its submission process earlier this year.
Timeline
Intel launched an invite-only bug bounty program in 2017.
The program expanded to all researchers in 2018.
Researchers submitted 105 CVEs through the bounty program in 2020.
Intel announced it was evaluating enhanced bounty criteria on January 6, 2026.
HackerOne's Internet Bug Bounty program paused submissions on March 27, 2026.
The Tech Race
This transition reflects a broader shift in how major semiconductor and software companies manage security contributions from external researchers. Intel's move aligns with recent industry trends as organizations move away from traditional paid bounty models toward disclosure-only frameworks.
The policy change primarily affects independent security researchers who previously earned income through Intel's bounty system. Users and enterprise clients should continue to monitor official security updates, as researchers may alter how they prioritize finding and reporting future vulnerabilities.
The takeaway
The move to a non-monetary disclosure model reflects a changing strategy in how tech giants handle independent security research. Developers and researchers should prepare for a potential shift in reporting workflows across the semiconductor industry.
Further reading
For more information on industry trends, visit Cybersecurity.
Live Poll
Should companies continue to provide financial rewards to researchers who discover security vulnerabilities?










