Skip to content

Report: Suspicious bounty on onlybugs05/angular ($1,686) - repo deleted after receiving PR #6

@boluo965

Description

@boluo965

Report: Suspicious/Fraudulent Bounty

GitHub user: onlybugs05 (SkyZeroZx)
Opire bounty URL: https://app.opire.dev/issues/01KTG6191Q4J7JJAZ1QM5TGZFC
GitHub repo: onlybugs05/angular (https://github.com/onlybugs05/angular)
Bounty amount: $1,686

What happened

  1. This user created a bounty on their fork of angular/angular
  2. The Opire issue claims a $1,686 reward for finding security bugs in the code
  3. A solver submitted a PR (#7) with a verified security fix and tests
  4. Within hours, the GitHub repository was completely DELETED (404)
  5. The Opire bounty page still shows the reward, but there is no repo to merge PRs into

Evidence

The solver (boluo965) has proof of:

Why this is suspicious

  • The repo was a 0-star fork of angular/angular with minimal custom changes
  • The bounty amount ($1,686) is unusually high for a fork
  • The repo was deleted shortly after receiving a valid PR, preventing any review or merge
  • The same user (chaunceyturcot2te) has created similar bounties on other fork repos (Authentik, SeaweedFS) but never funded them (failed /reward 10 attempts)

Request

Please investigate this user and consider:

  • Removing the bounty listing to prevent others from being defrauded
  • Banning the GitHub user account if this is a pattern of fraud
  • Adding scam/fraud reporting features to the platform

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions