Intel Ends Bug Bounty Payouts While Keeping The Reporting Channel Open

By Indie Kings | October 3, 2026

Updated October 3, 2026: Intel appears to have ended paid rewards for vulnerability reports according to VideoCardz by WhyCry. The money catch is that a formerly reported range of $500 to $100,000 now reads zero under a new disclosure program that explicitly states no bounties are available.

Historical Intel Inside logo

Image: Historical Intel Inside logo, 2002 to 2006 era. Credit: Wikimedia Commons, public domain.

A housekeeping note on the image above is needed before the substance begins. The image shows a historical Intel Inside logo from the 2002 to 2006 era. It is not the current Intel brand mark. It is also not a screenshot of the Intigriti program page. It is used here only as a visual identifier for the company named in the report.

The Money Stopped, The Mailbox Did Not

Intel appears to have ended paid rewards for vulnerability reports. That hedged sentence is the finding as reported by VideoCardz by WhyCry. The hedge matters. The source does not present this as a confirmed Intel announcement.

VideoCardz published the report on Sep 19, 2026 at 15:48 GMT. The headline uses reportedly. The body uses appears. This article keeps both qualifiers for the same reason. Intel has made no public statement in the source material.

The precise shape of what ended is narrower than a shutdown of reporting. The reporting channel still exists. It still accepts reports. What stopped, according to the source, is the money.

VideoCardz describes the change in one compact line. It states that Intel appears to have ended paid rewards for vulnerability reports. It adds that the new disclosure program explicitly states that no bounties are available. Those two clauses carry the whole story.

The distinction between a bounty program and a disclosure program is central here. A bounty program pairs a reporting channel with financial rewards. A disclosure program provides a reporting channel without a promise of payment. According to VideoCardz, Intel has moved from the first model to the second.

That move leaves researchers with an open mailbox and no stated price list. The company still accepts vulnerability reports. Researchers should no longer expect a monetary reward under the new program. Both points come directly from the reported description of the new program.

This section exists to prevent the most likely misreading. Intel did not reportedly close its doors to outside reports. It reportedly removed payment from the process. The channel remains. The compensation does not.

The table below states the reported old versus new arrangement in the exact terms supplied for this article. It is not expanded with outside material. It is not filled in with assumptions about products or dates. It reflects only what the source establishes.

ItemPrevious Intel program on IntigritiNew Intel program on Intigriti
Statuslisted as suspendedlaunched, accepting reports
Financial rewards$500 to $100,000 depending on vulnerabilityexplicitly none, operates without bounties
Scope previously coveredhardware, software, firmware, open sourcescope of the new program not detailed in source
PlatformIntigritiIntigriti, same platform
Public explanationnonenone

Read the status row first. The previous program is listed as suspended. The new program is described as launched and accepting reports. Suspension on one listing plus a new listing on the same platform is the reported evidence for a replacement rather than a simple pause.

Read the rewards row second. The old range is stated as $500 to $100,000 depending on the vulnerability. The new position is stated as explicitly none. The word explicitly is doing important work. It indicates that the absence of payment is written into the program terms, not merely inferred from silence.

Read the scope row third. The old scope covered hardware, software, firmware and open source projects. The new scope is not detailed in the source. That gap is preserved in the table rather than filled. Anything beyond that entry would need separate verification.

Read the platform row fourth. Both the old and new programs are placed on Intigriti. The continuity of platform is part of why this reads as a program replacement. The venue stayed the same while the payment terms changed.

Read the explanation row last. No public explanation is reported on either side. Intel has not publicly explained the change in the source. That silence is itself a reported fact and it constrains everything that follows.

Five Hundred To One Hundred Thousand To Zero

The reported old range was $500 to $100,000 depending on the vulnerability. That range comes to this article through Phoronix as relayed by VideoCardz. It is a wide band. It suggests that different classes of findings carried very different values under the prior program.

The new figure is simpler to state. It is zero. The new program explicitly states that it operates without bounties. There is no reported lower tier. There is no reported upper tier. There is an explicit statement of no payment.

A change from a range to zero is easy to misstate, so precision helps. The source does not say that rewards were reduced. It does not say that rewards were paused pending review. It says that the replacement program operates without bounties. Reduction and removal are different claims and only the second matches the source.

For a researcher reading the new program page, the practical meaning is direct. A report can still be submitted. Payment should not be expected. That is the full extent of what the source establishes about incentives. It does not address motivation, persistence, or redirection of effort, because the source makes no claim on those points.

The range itself deserves careful handling. Rewards reportedly ranged from $500 to $100,000 depending on the vulnerability. The word reportedly is retained here because VideoCardz attributes the program history to Phoronix. This article did not independently verify the historical price table. It reports the range as reported.

The dependence on vulnerability type is also worth stating plainly. The source ties the old amount to the vulnerability. It does not supply a schedule of which finding earned which amount. It does not name any specific vulnerability. It does not name any affected product. Those details are absent and are left absent here.

What a range to zero change means for a reader is therefore limited to the transaction terms. Under the previous program as described, a qualifying report could reportedly earn payment within a stated band. Under the new program as described, a report earns no monetary reward. The reporting act continues. The paid incentive does not.

This article does not convert that observation into a prediction. It does not claim that researchers will stop reporting. It does not claim that report volume will fall. It does not claim that users are more or less safe. The source makes none of those claims, so this article makes none of them.

The honesty of a short report matters more than its length. The primary reporting here is deliberately brief. VideoCardz metadata gives a wordCount of 145 words. That thinness is not a flaw to hide. It is a limit to respect. The money finding is clear, and most surrounding questions are simply unanswered.

One more precision point closes this section. The zero in question is a policy zero, not a measured zero. It means the program terms state that no bounties are available. It does not mean that a particular researcher received zero for a particular report. Whether past rewards were paid out is not stated in the source.

Suspended On The Same Platform

According to Phoronix as relayed by VideoCardz, Intel previously operated its bug bounty through Intigriti. That platform attribution is explicit. It places both the history and the present on one named venue.

The previous Intel program is now listed as suspended on Intigriti. Suspended is a listing status. It signals that the old entry is not active. It does not by itself explain why the status changed. No reason is supplied in the source.

Intel has since launched a new vulnerability disclosure program on the same platform. The continuity matters for interpretation. A move from one Intigriti listing to another Intigriti listing looks like a replacement. It does not look like a departure from the platform.

That new program explicitly states that it operates without bounties. The explicit no bounty language is the clearest reported difference between the two listings. The venue is constant. The payment term is not.

The old scope is described in broad categories. That program covered hardware, software, firmware and open source projects. Those four categories are the full extent of the scope detail available to this article. No product name is attached to any of them in the source.

The new scope is not detailed in the source. The required table records that gap directly. Readers looking for a product list for the new program will not find one here, because the source does not supply one. Any product list added from outside would require separate verification.

Platform continuity also clarifies what did not reportedly happen. There is no report here of a move to a different provider. There is no report of an in house portal replacing Intigriti. There is no report of a new crowdsourced venue. The reported facts keep both programs on Intigriti.

The suspended label deserves one more careful sentence. A suspended listing indicates that the prior program is not currently operating as a bounty. It does not state when the suspension took effect. It does not state whether the suspension is permanent. The source dates its own report to Sep 19, 2026, but it does not date the underlying change.

For readers who track disclosure infrastructure, the takeaway is narrow and stable. The venue is Intigriti before and after. The old entry is suspended. The new entry accepts reports without pay. Everything beyond those three sentences would go past the source.

No Public Explanation

Intel has not publicly explained the change in the source material. That silence is reported as a fact about the record, not as an accusation. No statement, memo, post, or filing is cited by VideoCardz or by the underlying Phoronix item as relayed.

The absence of an explanation limits what can be written about motive. No reason for the change is stated. No cost rationale is offered. No strategy shift is described. No executive is quoted. This article therefore offers no theory of why Intel acted.

The underlying source chain is short and should be stated plainly. VideoCardz by WhyCry reported the change. VideoCardz names Phoronix as the underlying source. Phoronix is credited with the Intigriti history, the scope categories, and the reward range. This article relies on that chain and does not add a third link.

The thinness of the primary report is itself worth documenting. VideoCardz metadata gives a wordCount of 145 words. That count signals a brief item, not an investigation. Readers should understand that the public record on this change, at least as captured here, consists of a compact report rather than a detailed dossier.

Thin reporting can still be precise. The brief item establishes several discrete points. It establishes the apparent end of paid rewards. It establishes the replacement disclosure program. It establishes the explicit no bounty term. It establishes continued acceptance of reports. Brevity does not erase those points, but it does confine them.

Thin reporting also leaves wide margins. It does not establish timing beyond the report date. It does not establish product scope for the new program. It does not establish payment history. It does not establish future intent. Each of those margins is preserved later in this article in a dedicated gaps section.

Hedged language is the correct register for this record. Intel appears to have ended its paid bug bounty program. Rewards reportedly ranged from $500 to $100,000. The hedges appear and reportedly are not decorative. They mark the distance between a platform listing observation and a confirmed company announcement.

This article does not upgrade the finding to a confirmed Intel announcement. No public Intel statement is present in the source. To drop the hedge would be to claim more than the evidence supports. The hedge stays.

The practical effect of silence is that researchers and readers share the same limited view. Both can see the reported listing statuses. Both can read the reported no bounty language. Neither is given a rationale, a timeline, or a scope document. That symmetry is worth stating so that no reader mistakes brevity for completeness.

What This Does And Does Not Mean

What this reportedly means is straightforward. Intel still accepts vulnerability reports. Researchers should no longer expect a monetary reward under the new program. Those two sentences can be held at the same time without contradiction.

An open channel without pay is a coherent arrangement. Many disclosure programs operate on that basis across the industry in general terms, but this article makes no comparative claim about peers. The point here is local. The reported Intel channel takes reports and states no bounties.

What this does not mean must be stated with equal care. It does not mean that Intel stopped receiving reports. The source says the opposite. It does not mean that past valid reports went unpaid. Payment history is not stated. It does not mean that any specific flaw is unpatched. No specific vulnerability is named.

It also does not mean that users face a new or quantified risk. The source makes no claim about exploit risk. It makes no claim about patch timelines. It makes no claim about product safety. This article repeats that boundary so that the money finding is not stretched into a safety finding.

The second required table follows. It separates established points from open questions in the exact terms supplied. It is the companion to the old versus new table above. Together the two tables carry the factual load of this article.

QuestionStatus
Did Intel announce this publiclyno public explanation in the source
Does Intel still take reportsyes, the channel accepts reports
Should researchers expect payno, no monetary reward under the new program
Why did Intel do thisnot stated
When exactly did it changenot dated beyond the Sep 19, 2026 report
Which products are in scope nownot detailed
Whether past rewards were paid outnot stated

Read the first three rows as the settled core. No public explanation is present. Report intake continues. Payment expectation is now zero. Each of those rows is directly supported by the source description.

Read the remaining four rows as explicit limits. Why the change occurred is not stated. The exact date of the change is not dated beyond the report itself. Current product scope is not detailed. Past payout history is not stated. Those limits prevent overreading.

The table format is deliberate. A short hedged report is easy to inflate in prose. A table forces each claim into a separate cell with a separate status. That structure keeps the established and the unknown visually apart.

For researchers, the actionable reading is minimal but complete. Submit through the new disclosure program if the goal is to inform the vendor. Do not submit with an expectation of payment under the stated terms. Seek no further instruction here about where else to report, because the source supplies none.

For general readers, the actionable reading is even shorter. A vendor incentive changed. A reporting channel remains. Nothing in the source quantifies a change in personal risk. Nothing in the source names an action for device owners to take.

What Is Not Established

A short report stretched honestly requires a full accounting of what it does not contain. This section provides that accounting. Every item below is either marked as unstated or left out entirely where the fact block requires omission.

The date the program ended is not established [NEEDS VERIFICATION]. The source report is dated Sep 19, 2026. That is the date of the reporting, not the date of the underlying change. No effective date for the suspension or the launch is supplied.

The number of researchers affected is not established [NEEDS VERIFICATION]. The source gives no headcount. It gives no measure of active participants. It gives no measure of past submitters. This article therefore states no figure for the affected population.

The total paid out historically is not established [NEEDS VERIFICATION]. The source supplies a reported range for individual rewards. It does not supply an aggregate total. It does not supply an annual figure. It does not supply a lifetime figure. No total appears here.

The number of reports is not established [NEEDS VERIFICATION]. No submission count is given for the old program. No submission count is given for the new program. No trend is described. No comparison across periods is possible from the source.

Any specific vulnerability is not established [NEEDS VERIFICATION]. No flaw is named. No severity score is cited. No patch is referenced. No timeline from report to fix is described. The article stays at the program level throughout.

Any Intel product name is not established in this context. The old scope uses category words such as hardware, software, firmware and open source projects. Those categories are repeated here because they are in the source. No model, family, or codename is added, because none is supplied.

Any executive statement is not established [NEEDS VERIFICATION]. No quote appears in the source chain. No named spokesperson is cited. No blog post or press release is referenced. The record as given contains platform listings plus secondary reporting, and nothing more.

Any reason for the change is not established [NEEDS VERIFICATION]. Cost, strategy, reorganization, fraud, low signal volume, duplication with internal testing, or any other motive would each be speculation. The source states no reason, so this article states no reason.

Whether peer programs changed is not established [NEEDS VERIFICATION]. The source makes no claim about other vendors. This article therefore makes no claim about whether any other company kept, cut, or changed a bounty. A comparative angle would need separate verified sourcing.

Any claim about future exploit risk is not established [NEEDS VERIFICATION]. The source does not forecast attacker behavior. It does not forecast fix rates. It does not forecast disclosure volume. This article does not fill that gap with a forecast of its own.

Two claims are affirmatively excluded rather than merely unstated. This article does not claim that researchers will stop reporting. The source makes neither that claim nor any claim about researcher intent. This article does not claim that users are less safe. The source makes neither that claim nor any claim about user outcomes.

The discipline throughout is to keep unknown items unknown. Where a fact would be useful but is absent, the article says so. Where a fact would be interesting but is barred by the fact block, the article omits it. The result is longer than the source but not broader than the source.

FAQ

Did Intel reportedly end paid bug bounty rewards?
Yes. Intel appears to have ended paid rewards for vulnerability reports according to VideoCardz by WhyCry, with the replacement program explicitly stating that no bounties are available.

Does Intel still accept vulnerability reports?
Yes. The company still accepts vulnerability reports through the new disclosure program on Intigriti, even though no monetary reward is offered.

What was the reported old reward range?
Rewards reportedly ranged from $500 to $100,000 depending on the vulnerability under the previous program, as relayed from Phoronix by VideoCardz.

Where were the old and new programs hosted?
Both are placed on Intigriti. The previous program is listed as suspended there and the new disclosure program was launched on the same platform.

Did Intel publicly explain the change?
No. Intel has not publicly explained the change in the source, and no reason, date, or statement beyond the reported listing change is established.

What remains unknown about the new program?
The new scope, the exact timing, past payout history, and the reason for the change are not detailed, and no specific vulnerability or product name is established.

Bottom Line

The reported change is narrow. The mailbox remains open and the money is gone. Intel appears to have replaced a paid bounty with an unpaid disclosure channel on the same platform.

The numbers state the shift without embellishment. A reported $500 to $100,000 range now reads as an explicit zero. Reports are still accepted. Payment should no longer be expected.

The record is thin and hedged. A 145 word primary report plus an underlying Phoronix item is the full chain supplied here. No public Intel explanation accompanies it. The hedges appear and reportedly are retained for that reason.

Sources: VideoCardz by WhyCry, Intel reportedly ends bug bounty rewards for security researchers, https://videocardz.com/newz/intel-reportedly-ends-bug-bounty-rewards-for-security-researchers and Phoronix, https://www.phoronix.com/news/Intel-Bug-Bounty-Program-Ends.

Share