Open source bounties
5 open open source bounties, each checked against the organizer's official page. 5 take applications on a rolling basis.
A bounty pays for one defined result: a security bug found and reported, a feature built, an issue closed. Bug bounty programs on HackerOne, Immunefi, Sherlock and similar platforms pay by severity, and many run all year.
Money for people who write and maintain open source: foundation grants, security funds, maintainer stipends and paid contribution programs.

Google Open Source Software Vulnerability Reward Program
Google pays up to $31,337 for supply chain compromises in its open source projects. Product vulnerability reports are paused since October 1, 2026.

Omarchy bug bounty on HackerOne: up to $1,500
Omarchy pays up to $1,500 on HackerOne for bugs in its Linux distribution repository. The public program launched on 1 October 2026.

Proximity Prize: Ethereum Foundation research rewards for SNARK soundness proofs
The Ethereum Foundation Proximity Prize rewards solvers who raise machine checked security bounds for hash based SNARKs. Proofs are checked in Lean.

Tenstorrent Bounty Program for open source contributors
Tenstorrent pays bounties for merged pull requests on GitHub issues tagged bounty. Tiers run from $1 to $3,000, and one open issue lists $35,000.

Vercel public bug bounty
Vercel pays up to $10,000 for critical reports in its public bug bounty, including open source projects. No deadline.
Questions
How many open source bounties are open right now?
5 as of 7 October 2026. 5 take applications on a rolling basis.
Can I apply from any country?
All of them accept applicants worldwide. Some still set conditions on age, residence or sanctions, and each entry lists them.
How is this list checked?
Every entry is written from the organizer's official page and links to it. Programs with a rolling deadline are checked again for closure, and an entry moves to the archive on the day it closes.