Intel has suspended its original bug bounty program and launched a new vulnerability disclosure project. The company will continue to accept vulnerability reports submitted by security researchers, but the new program explicitly does not offer rewards for discoveries.
Previously, Intel collaborated with security researchers through the Intigriti platform, offering rewards ranging from $500 to $100,000 based on the severity of the vulnerabilities. The original plan covered hardware, software, firmware, and open-source projects, giving researchers the opportunity to receive compensation after discovering and reporting related security issues.
Currently, the Intigriti page has marked Intel's original program as suspended. The replacement new project still focuses on vulnerability disclosure, but its description clearly states that no bounties will be provided for vulnerability discoveries. This means researchers can still report issues to Intel, but they can no longer receive cash rewards through this program.
Intel has not publicly explained the reasons for the adjustment, nor confirmed whether this move is related to cost control, changes in security strategy, or other factors. Therefore, it is currently impossible to determine the specific considerations behind the company's suspension of the bounty mechanism.
For independent security researchers, bounties serve as a direct incentive for the time invested in discovering and verifying vulnerabilities. With Intel canceling cash rewards, external researchers' motivation to find vulnerabilities in its products may decline, potentially affecting the speed at which some issues are discovered and fixed. Currently, the new program is still accepting vulnerability reports.

