AMD Denies Researcher $10,000 Bug Bounty Reward – Despite Discovering Critically Serious Issue


  • Researcher Paul found RCE via MITM in AMD’s automatic update, but bounty denied
  • AMD introduced extended embargo, later changed disclosure rules after criticism
  • The security community pushed back, saying the new policy discourages transparency and undervalues ​​researchers

A security researcher discovered a Remote Code Execution (RCE) vulnerability in an AMD product, but the company reportedly denied him the bug payout it promised for such findings.

In February 2026, a researcher named Paul discovered a potential RCE flaw via a man-in-the-middle (MITM) attack in AMD’s automatically updated software. He reported it to AMD and published a blog post about his findings.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top