Ways to earn / Bounties
Open-source issue bounties and bug bounties: why we say do not start
Do not start checked 2026-10-08
You (or an AI coding tool) fix a listed software issue or find a security bug for a payout; for non-programmers this mostly produces unpaid work and, with AI, can get you banned.
What the evidence says about money
Do not start unless you already write code. Payment happens only if the work is accepted. One estimate puts 35 to 45% of active bug hunters at 0 dollars a year; the same source says to expect nothing in the first three months. An AI-assisted bounty experiment found 14 viable bounties, 6 patches and 2 paid, about 420 dollars after fees over two weeks, a single developer's account. Maintainers are closing contribution routes because of AI-generated low-quality submissions.
How sure are we: Backed by a secondary source such as press or a review site.
What only you can do, once
- Not applicable: do not start unless you can read and review code yourself
A first week
| Day | What happens | Who | Minutes |
|---|---|---|---|
| 1 | Read why this path is not recommended; pick a different path | You | 10 |
The rules where it happens
- Algora: You do it by hand inside the platform. Contributors get 100% of the bounty; the organisation pays the platform fee; payout via Stripe Connect 1 to 3 business days after payment, with country coverage varying. Sample open bounties range 500 to 3,500 dollars and are mostly Rust and TypeScript. Source
- HackerOne / Bugcrowd (security bug bounties): You do it by hand inside the platform. Platforms are tightening rules because of AI-generated spam: Bugcrowd submissions quadrupled in 3 weeks in March 2026 and mostly were false positives; curl ended its bounty on 31 Jan 2026; Nextcloud paused in April 2026. Source
What can go wrong
- Most attempts are unpaid: one company's bounty round drew 19 claimed pull requests for 7 paid bounties.
- Projects ban or auto-close AI-generated contributions (Ghostty permanent bans, Gentoo bans, tldraw closes external PRs).
- Submitting low-quality or AI-generated security reports can get accounts penalised and wastes maintainers' time.
- Testing systems you do not have permission to test can be illegal; only test programmes that explicitly allow it.
- Payouts are lumpy and taxable.
How it hooks people
The payout looks large and the work looks like fun. One company's round drew 19 claimed pull requests for 7 paid bounties, and many projects ban AI contributions.
Age, region and other limits
Minimum age 18. Algora docs say some countries limit international payments to businesses.
Sources
- Algora docs: contributors always get 100% of the bounty, paid via Stripe Connect 1 to 3 business days after payment; the organisation pays the fee when the PR is merged; Stripe may refuse payouts if the contributor lacks credentials for international payments in their country. [P]
- Algora bounty list sample: open bounties of 500 to 3,500 dollars, most in Rust, TypeScript and MDX; page does not state who can claim or typical amounts. [P]
- Company report (Nov 2024): 14 issues with bounties drew 19 pull requests; 7 closed via Algora, total 1,430 dollars awarded; reports of copied PRs and suspected bot activity. [S]
- Register (21 Jan 2026): curl ended its bug bounty at the end of January 2026 to remove the incentive for AI-generated, poorly researched reports; the last week produced 7 submissions, none a real vulnerability. [S]
- Computing (18 May 2026): Bugcrowd submissions more than quadrupled in a 3-week period in March, mostly false positives or low-quality AI findings; HackerOne added agentic validation; Nextcloud paused its programme in April. [S]
- Blog (2 July 2026, not verified against originals): Ghostty moved to zero tolerance with permanent bans, Gentoo bans AI-generated contributions, tldraw auto-closes external PRs, Jazzband shut down; curl's confirmed-vulnerability rate fell from above 15% to about 1 in 20 to 30. [S]
- Bug bounty economics article (7 Apr 2026, tier estimates admitted as approximate): 35 to 45% of active hunters earn 0 dollars a year; about 40% of researchers who submit a report never get a bounty; top 1% earn more than the bottom 90% combined. A second article (24 Apr 2026) expects most beginners to earn 0 dollars in the first 3 months; author's own estimates. [S]
Get the Recipe Pack, USD 19 What is in the pack Try the Restmode app
Normal price USD 19. Code LAUNCH takes 40% off for the first 25 buyers.
Our method, written down, with sources. No income promise.