Intel quietly shut down its paid bug bounty program — the one that's been running since 2017. Researchers are still submitting reports. The checks just aren't coming anymore.
This wasn't some niche side project. The program covered hardware, firmware, software, and Intel-managed open source. Payouts ranged from $500 to $100,000 depending on severity. In 2020, roughly 45% of Intel's fixed bugs came through that bounty. In 2024, all 21 hardware vulnerabilities Intel disclosed that year were found internally through the program.
So what changed?
Intel hasn't made an official statement, but Phoronix suggests the culprit is the flood of AI-generated vulnerability reports now hitting Linux and other open-source projects. Linus Torvalds himself has complained about the volume of low-quality, duplicate reports clogging the kernel security list — many of them machine-generated noise.
Intel hasn't said whether paid bounties will return. But the shift is stark: a $100,000 cap used to buy outside scrutiny on CPU-level silicon. Now it's an unpaid inbox getting hammered by LLM spam. That's a very different filter — and probably not the one you want guarding your supply chain.
$INTC
This wasn't some niche side project. The program covered hardware, firmware, software, and Intel-managed open source. Payouts ranged from $500 to $100,000 depending on severity. In 2020, roughly 45% of Intel's fixed bugs came through that bounty. In 2024, all 21 hardware vulnerabilities Intel disclosed that year were found internally through the program.
So what changed?
Intel hasn't made an official statement, but Phoronix suggests the culprit is the flood of AI-generated vulnerability reports now hitting Linux and other open-source projects. Linus Torvalds himself has complained about the volume of low-quality, duplicate reports clogging the kernel security list — many of them machine-generated noise.
Intel hasn't said whether paid bounties will return. But the shift is stark: a $100,000 cap used to buy outside scrutiny on CPU-level silicon. Now it's an unpaid inbox getting hammered by LLM spam. That's a very different filter — and probably not the one you want guarding your supply chain.
$INTC