Intel Has Ended Its Paid Bug Bounty Program

The technology firm transitioned to a disclosure-only platform that offers researchers no financial rewards.

Updated on Sept. 19, 2026 in Cybersecurity

Isometric editorial illustration of a single silicon processor chip resting on a gray metallic surface.
Intel has discontinued its paid bug bounty program, shifting to a disclosure-only platform that eliminates financial rewards for independent security researchers. AI Illustration. Upload story photo >

Live Poll

Should companies continue to provide financial rewards to researchers who discover security vulnerabilities?

Intel has officially discontinued its bug bounty program, moving its vulnerability reporting to a new system hosted on the Intigriti platform. This change marks the end of financial incentives for security researchers who identify software, hardware, and firmware flaws.

Why it matters

The removal of monetary rewards alters the incentive structure for independent researchers who previously helped the company secure its products. While the new program facilitates vulnerability reporting, the absence of payments may impact participation rates for critical security discoveries.

The former program provided payouts ranging from $500 to $100,000 per reported flaw. Intel has now shifted its reporting process to the Intigriti platform, which does not offer financial compensation for submissions.

The players

Intel

This multinational technology corporation designs and manufactures computer processors and related hardware.

Intigriti

This organization operates a bug bounty and vulnerability disclosure platform for companies to manage security reports.

AMD

This semiconductor company designs computer processors and graphics technologies and currently has a suspended program on Intigriti.

The details

Intel previously maintained an open initiative that rewarded researchers for uncovering bugs across its software, hardware, firmware, and open-source projects. Other industry entities are facing similar shifts, as the HackerOne Internet Bug Bounty program paused its submission process earlier this year.

Timeline

  1. Intel launched an invite-only bug bounty program in 2017.

  2. The program expanded to all researchers in 2018.

  3. Researchers submitted 105 CVEs through the bounty program in 2020.

  4. Intel announced it was evaluating enhanced bounty criteria on January 6, 2026.

  5. HackerOne's Internet Bug Bounty program paused submissions on March 27, 2026.

The Tech Race

This transition reflects a broader shift in how major semiconductor and software companies manage security contributions from external researchers. Intel's move aligns with recent industry trends as organizations move away from traditional paid bounty models toward disclosure-only frameworks.

The policy change primarily affects independent security researchers who previously earned income through Intel's bounty system. Users and enterprise clients should continue to monitor official security updates, as researchers may alter how they prioritize finding and reporting future vulnerabilities.

The takeaway

The move to a non-monetary disclosure model reflects a changing strategy in how tech giants handle independent security research. Developers and researchers should prepare for a potential shift in reporting workflows across the semiconductor industry.

Further reading

For more information on industry trends, visit Cybersecurity.

Live Poll

Should companies continue to provide financial rewards to researchers who discover security vulnerabilities?