
Intel appears to have decided to no longer pay security researchers for discovered vulnerabilities. The company has suspended its old Bug Bounty program, which awarded $500 to $100,000 for reporting issues, and replaced it with a new Responsible Vulnerability Disclosure program, which does not offer cash rewards.

We’re talking about vulnerabilities in hardware, firmware, software, and open source Intel projects. You can still report problems you find, but now researchers must do so just for the sake of the idea.
The reasons for Intel’s decision to cancel the payments have not been officially reported. One possible explanation has to do with the current onslaught of vulnerability reports generated by artificial intelligence. Other projects already face massive amounts of automation and duplication of messages, making handling such requests a separate pain point.










