AMD denies researcher a $10,000 bug bounty after fixing critical auto-updater vulnerability — security flaw took 124 days to patch
AMD refused to pay a $10,000 bug bounty for a critical RCE vulnerability in its auto-updater, taking 124 days to patch a simple HTTP-to-HTTPS fix.
AMD Denies $10,000 Bug Bounty After 124-Day Patch Delay for Critical Auto-Updater Flaw
AMD has refused to pay a $10,000 bug bounty to a security researcher who discovered a critical remote code execution (RCE) vulnerability in the company's auto-updater software — despite the flaw taking 124 days to patch and affecting multiple AMD tools beyond the initially reported Ryzen Master utility.
The Vulnerability: A Simple But Dangerous Flaw
The vulnerability, discovered by a researcher identified as "Paul," was remarkably straightforward: AMD's auto-updater was downloading updates over unencrypted HTTP connections instead of HTTPS. This created a classic man-in-the-middle (MITM) attack vector where an attacker on the same network could intercept the update process and inject malicious code, achieving remote code execution on the target system.
The fix was equally simple — changing "http" to "https" in the code — yet AMD took over four months to deploy it across all affected products.
Timeline of Events
Paul initially reported the vulnerability to AMD's bug bounty program in February 2025, expecting both a fix and the standard $10,000 payout for an RCE-class bug. AMD's response was surprising: the company rejected the bounty claim, stating that MITM attacks were not covered by their bug bounty program's policy.
Despite denying the bounty, AMD asked Paul to temporarily remove his blog post describing the vulnerability. The company promised to issue a CVE, fix the software, and credit Paul for the discovery — but explicitly stated a bounty payment was "out of the question."
Paul agreed to the 100-day embargo period (beyond the industry-standard 90 days), but AMD repeatedly requested extensions. The company cited additional affected tools beyond Ryzen Master and customer requests for more time once fixes were available. The patch finally arrived on June 9, 2025 — 124 days after the initial report.
Broader Implications for Bug Bounty Programs
This incident raises serious questions about the effectiveness and good faith of corporate bug bounty programs. When companies can retroactively exclude vulnerability classes from bounty eligibility — especially after a researcher has already invested time in discovery and responsible disclosure — it undermines the entire security research ecosystem.
The case echoes similar controversies, including Microsoft's handling of the Nightmare-Eclipse vulnerability, where researchers faced comparable challenges in receiving recognition and compensation for critical findings.
Current Status
Users who download the latest version of AMD's software suite should now receive the patched updater with HTTPS enforcement. However, the researcher reportedly never received any financial compensation for a vulnerability that AMD itself acknowledged required 124 days to fully remediate across its product line.
The episode serves as a cautionary tale for security researchers considering participation in vendor bug bounty programs, and highlights the need for clearer, enforceable standards around vulnerability disclosure and researcher compensation.


