Intel Has Ended Its Paid Bug Bounty Program
The company has transitioned to a disclosure-only model, removing financial incentives for security researchers.
Updated on Sept. 19, 2026 in Cybersecurity

Live Poll
Should companies continue to provide financial rewards to researchers who discover security vulnerabilities?
Intel has officially ended its long-running bug bounty program, replacing it with a vulnerability disclosure initiative hosted on the Intigriti platform that provides no financial compensation. The shift marks a complete departure from the previous system that rewarded security researchers for reporting flaws in hardware, software, and firmware.
Why it matters
The removal of financial incentives for vulnerability reports risks reducing the flow of security intelligence to one of the world's largest semiconductor manufacturers. This transition follows a broader trend of instability in the bug bounty ecosystem, including the pause of the HackerOne-hosted Internet Bug Bounty program earlier this year.
The former program provided payouts ranging from $500 to $100,000 to independent researchers. In 2020, this incentive structure helped identify 105 of the 231 total CVEs addressed by the company that year.
The players
Intel
A global semiconductor manufacturer focused on central processing units, server architecture, and integrated circuits.
Intigriti
A European-based bug bounty and vulnerability disclosure platform that facilitates connections between companies and security researchers.
AMD
A semiconductor company and Intel's primary competitor in the x86 processor market that has also suspended its program on Intigriti.
The details
The transition moves Intel's vulnerability reporting process to the Intigriti platform, which now operates as a disclosure-only portal. In a traditional bounty system, researchers receive monetary compensation for reporting valid security vulnerabilities, often classified as CVEs (Common Vulnerabilities and Exposures), before they are exploited. By shifting to a disclosure-only model, Intel now receives these reports without providing the previous financial rewards that once incentivized the discovery of complex exploits.
Timeline
2017: Intel launched its original bug bounty program as an invite-only initiative.
2018: The program opened to all security researchers.
2020: The bounty program received 105 of the 231 CVEs addressed by Intel.
January 6, 2026: Intel announced it was evaluating enhanced bounty criteria.
March 27, 2026: HackerOne's Internet Bug Bounty program paused submissions.
The Tech Race
Intel's decision aligns with recent structural shifts in the security research landscape, following the March 2026 pause of the HackerOne Internet Bug Bounty program. The field is currently experiencing a contraction, as major industry players re-evaluate the economics of maintaining active bounty systems.
For security researchers, the immediate effect is the loss of a key revenue stream for identifying and reporting vulnerabilities in Intel hardware and software. The industry will now monitor whether the lack of financial incentive impacts the discovery rate of future critical security flaws.
The takeaway
The move from a paid bounty system to a disclosure-only model represents a significant shift in how semiconductor firms source security intelligence. Researchers should watch for changes in vulnerability submission rates or public disclosure latency in the coming months as a test of this new model.
Further reading
For more background on how companies manage external security research, visit the Cybersecurity section.
Live Poll
Should companies continue to provide financial rewards to researchers who discover security vulnerabilities?








