
Omarchy bug bounty on HackerOne: up to $1,500
Omarchy pays up to $1,500 on HackerOne for bugs in its Linux distribution repository. The public program launched on 1 October 2026.
The Omarchy bug bounty is a public program on HackerOne for the Omarchy Linux distribution. It launched on 1 October 2026 and submissions are open. The bounty table lists $250 for medium, $750 for high, and $1,500 for critical. The policy does not list a low payout. There is no closing date.
The in scope code is the repository at https://github.com/omacom/omarchy. Findings should be checked against the default branch, which the policy names quattro. Upstream vulnerabilities are out of scope for payment. Omarchy says it will still help report those to the upstream project and will give credit, but it will not pay a bounty. Third party services, documentation, social engineering, denial of service, and brute force are also out of scope. A bug in a dependency qualifies only when the issue is in how Omarchy uses or integrates that dependency.
A paid report needs clear reproduction steps, a working proof of concept, the affected version, and an impact description. One vulnerability per report, unless a chain is needed to show impact. Only the first valid reproducible report is paid when duplicates arrive. Scanner output, or an AI generated finding without a manual check and a working proof of concept, is not eligible. Do not damage systems or take personal data.
Submit the report on the HackerOne program page. The policy asks for a typical 90 days after confirmation before public disclosure. Omarchy aims to send an initial response within 5 business days, a triage decision within 10 business days, and a bounty decision within 15 business days of triage.