AMD denied a security researcher a $10,000 payout for a critical-severity vulnerability — then retroactively updated its bug bounty program rules to justify the refusal.
A researcher identified a critical-severity flaw in AMD products and submitted it through the company's bug bounty program, which listed $10,000 as a potential reward at that severity level. AMD declined to pay. The company then updated its program's disclosure rules after the fact, a move that recast the finding as ineligible under the new terms. AMD did not dispute the vulnerability's critical-severity classification.
The credibility of any bug bounty program depends on researchers trusting that the rules are fixed at submission. Retroactive rewrites break that compact — not just for AMD but for the broader responsible disclosure ecosystem that keeps critical vulnerabilities out of attackers' hands first. A researcher who cannot trust the payout terms has strong incentive to take findings to a broker instead.
AMD joins a long list of vendors who have found responsible disclosure more appealing as a marketing commitment than a financial one.
