Intel suspends bug bounty program that paid $100k per flaw


Featured image Intel suspends bug bounty program that paid 100k per flaw

In a seismic shift felt across the technology landscape, major industry programs designed to reward vulnerability discovery are quietly winding down. Intel, a titan of computing, has suspended its highly lucrative bug bounty program, signaling a significant pivot in how the world finds and addresses security flaws.

This isn’t just about a change in corporate policy; it touches upon the very economics of cybersecurity. For years, Intel’s program, known as Intigriti, offered staggering rewards, with bug reports sometimes fetching up to $100,000 based on the quality and severity of the findings. The system operated on clear tiers, ranging from $2,000 for Tier 1 vulnerabilities up to $100,000 for the most critical flaws, inviting researchers to dedicate their talents to patching the world’s most complex systems.

But even established systems are evolving, and the recent changes suggest that the sheer volume of information, coupled with new technological forces, has reshaped the vulnerability landscape. The program was designed to be a pipeline for security, but the environment itself has become overwhelmingly saturated with reports.

As the flow of information accelerates, so too does the emergence of artificial intelligence in security research. It is no surprise that the bounty system has faced scrutiny, with many speculating that AI-assisted bug-seeking is playing an increasingly vital role in uncovering weaknesses. Linus Torvalds, the creator of the Linux kernel, has expressed frustration over the onslaught of AI-generated reports, noting that the process has made managing the security mailing list nearly impossible.

This trend is not unique to Intel. Other major players are also adjusting their security incentive structures. For example, HackerOne’s Internet Bug Bounty program paused submissions, recognizing the expanding reach of AI-assisted research across the ecosystem. Similarly, AMD’s Intigriti program has also undergone suspension, underscoring a broader industry recognition that the rules of engagement are changing.

Despite the pause in public bounties, the mechanism for responsible disclosure remains. The replacement programs emphasize that they are responsible disclosure initiatives without direct monetary rewards, focusing instead on the integrity of the reporting process. This allows security researchers to continue sharing critical information while the industry recalibrates its approach.

The dual reality of this transition is fascinating. While some reward structures are being suspended, the practical application of advanced tools like AI in security is proving highly effective. There are concrete examples of AI tools being utilized by researchers to map exploit chains, demonstrating a powerful, if sometimes controversial, new tool for discovery.

The story of vulnerability disclosure is clearly moving forward, propelled by both human ingenuity and machine learning. As developers and researchers navigate this evolving space, the focus remains on ensuring that the rapid advancement of technology does not outpace the safety of the systems we rely on.

You may also like: