Intel Might End Bug Bounty Premiums: $100,000 Rewards at Risk
Intel may be shifting its strategy regarding hardware security. Reports indicate that the company's existing Bug Bounty program, which previously offered rewards of up to $100,000, has been suspended. A new "Vulnerability Disclosure Program" has appeared on the Intigriti platform, but its description explicitly states it operates "without bounties."
The End of Financial Incentives?
Under the previous system, the scale of rewards depended on the severity of the flaw and the affected product category. Researchers could earn up to $100,000 for critical hardware vulnerabilities. Firmware issues were valued at up to $30,000, while software-related bugs carried a maximum payout of $10,000.
As reported by Phoronix, the original program is now listed as suspended on Intigriti. The new program, which reportedly launched on September 17, makes it clear that financial compensation is no longer part of the deal. Intel has not yet provided a reason for this sudden change in policy.
Conflicting Official Statements
The situation is currently complicated by conflicting information on Intel's own websites. The company continues to promote its Bug Bounty program, citing potential rewards between $500 and $100,000 and directing researchers to Intigriti. Furthermore, corporate communications still highlight that over 350 researchers have participated in the program, resulting in millions of dollars in total payouts.
The Bug Bounty program has historically been a vital part of Intel's security ecosystem; for instance, in 2020, 105 out of 231 handled CVEs were traced back to reports from the program. It remains unclear whether this is a permanent shift or a temporary restructuring. This move is particularly unexpected given that earlier in 2026, Intel had announced plans to expand its bounty criteria and introduce additional bonuses for high-quality reports.