Security/ bug-bounty · amd · security · vulnerability

AMD Changed Its Bug Bounty Rules to Avoid Paying for a Critical Flaw

A researcher found a critical-severity AMD vulnerability worth $10,000 under program terms — AMD responded by rewriting those terms retroactively.

AMD Changed Its Bug Bounty Rules to Avoid Paying for a Critical Flaw

AMD denied a security researcher a $10,000 payout for a critical-severity vulnerability — then retroactively updated its bug bounty program rules to justify the refusal.

A researcher identified a critical-severity flaw in AMD products and submitted it through the company's bug bounty program, which listed $10,000 as a potential reward at that severity level. AMD declined to pay. The company then updated its program's disclosure rules after the fact, a move that recast the finding as ineligible under the new terms. AMD did not dispute the vulnerability's critical-severity classification.

The credibility of any bug bounty program depends on researchers trusting that the rules are fixed at submission. Retroactive rewrites break that compact — not just for AMD but for the broader responsible disclosure ecosystem that keeps critical vulnerabilities out of attackers' hands first. A researcher who cannot trust the payout terms has strong incentive to take findings to a broker instead.

AMD joins a long list of vendors who have found responsible disclosure more appealing as a marketing commitment than a financial one.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →