Report: Suspicious/Fraudulent Bounty
GitHub user: onlybugs05 (SkyZeroZx)
Opire bounty URL: https://app.opire.dev/issues/01KTG6191Q4J7JJAZ1QM5TGZFC
GitHub repo: onlybugs05/angular (https://github.com/onlybugs05/angular)
Bounty amount: $1,686
What happened
- This user created a bounty on their fork of angular/angular
- The Opire issue claims a $1,686 reward for finding security bugs in the code
- A solver submitted a PR (#7) with a verified security fix and tests
- Within hours, the GitHub repository was completely DELETED (404)
- The Opire bounty page still shows the reward, but there is no repo to merge PRs into
Evidence
The solver (boluo965) has proof of:
Why this is suspicious
- The repo was a 0-star fork of angular/angular with minimal custom changes
- The bounty amount ($1,686) is unusually high for a fork
- The repo was deleted shortly after receiving a valid PR, preventing any review or merge
- The same user (chaunceyturcot2te) has created similar bounties on other fork repos (Authentik, SeaweedFS) but never funded them (failed /reward 10 attempts)
Request
Please investigate this user and consider:
- Removing the bounty listing to prevent others from being defrauded
- Banning the GitHub user account if this is a pattern of fraud
- Adding scam/fraud reporting features to the platform
Report: Suspicious/Fraudulent Bounty
GitHub user: onlybugs05 (SkyZeroZx)
Opire bounty URL: https://app.opire.dev/issues/01KTG6191Q4J7JJAZ1QM5TGZFC
GitHub repo: onlybugs05/angular (https://github.com/onlybugs05/angular)
Bounty amount: $1,686
What happened
Evidence
The solver (boluo965) has proof of:
Why this is suspicious
Request
Please investigate this user and consider: