Omarchy, the Linux distribution built by Ruby on Rails creator David Heinemeier Hansson, now pays people to find its security holes. The project opened a public bug bounty on HackerOne this week, and the Omacom Foundation has put US$100,000 into the pot.
It's got a head of security now, too. Hansson, better known as DHH, announced on Friday 2 October that Mehmet İnce is joining Omarchy Core to run the program and set the project's security direction.
What Omarchy announced
DHH set it out in a post on Omarchy's news page. "The Omacom Foundation has funded it with $100,000 for bounties," he wrote, "so researchers who find a real vulnerability and report it privately can now get paid for their work."
HackerOne's public data for the Omarchy program shows it opened to everyone at 17:46 UTC on 1 October. That was 3:16am Friday in Adelaide. Submissions are open.
DHH said HackerOne gives researchers "a familiar place to submit their findings, follow along as we work on a fix, and collect their bounty." It also gives the Omarchy Security Team a proper way to sort through what comes in. Researchers who don't want a HackerOne account can still email security@omarchy.org, and the project's security page explains what counts.
About İnce, DHH wrote that he "has been a key member of the Omarchy Security Team, and now he'll be setting the direction for how we keep Omarchy safe, from running the bounty program to making sure security is built into everything we ship."
The money comes from Omarchy's patrons. "Thanks to our patrons, we can put real money behind making Omarchy secure," DHH wrote.
How much it pays and for what
The payouts are modest per bug, but they're real. Here's the bounty table on HackerOne:
- Medium-severity bugs pay US$250.
- High-severity bugs pay US$750.
- Critical bugs pay US$1,500.
There's no payout listed for low-severity finds. At those rates, US$100,000 covers more than 60 critical reports, so the fund won't run dry in a hurry.
The scope is tight. Only one asset is in scope for bounties, and that's the project's own code repository on GitHub, omacom/omarchy. The program asks researchers to check their findings against the latest version of Quattro, the default branch. That way they don't report bugs that are already fixed but not yet released.
That matters because Omarchy is built on other people's software. Its manual calls it an "omakase Linux distribution based on Arch," with the Hyprland tiling window manager and the Quickshell desktop toolkit on top. Bugs in those upstream projects don't earn a bounty. The policy says Omarchy will help researchers report them to the right project and will give credit, but it won't pay. A bug in a dependency only qualifies if the problem is in how Omarchy itself uses or wires up that dependency.
Also out of scope: third-party websites and services, documentation, social engineering, phishing, denial-of-service attacks and brute-force attacks.
What counts as a real bug
Omarchy's security page sets a clear bar. "We consider a bug a security vulnerability when it can be exploited to cross a meaningful security boundary: an untrusted or lower-privileged party gains access, permissions, or control they didn't already have."
Code that could be sturdier but doesn't cross that line is an improvement, not a vulnerability. The project says it may still merge a fix and credit the reporter in its release notes. It just won't pay a bounty for it.
There's also a rule plenty of maintainers will recognize. Reports that are nothing but scanner output, or "AI-generated findings without manual verification," don't qualify. Maintainers of well-known open-source projects, including curl's, have complained publicly about floods of machine-written bug reports that turn out to be wrong. This rule puts the work back on the person reporting. A paying report needs clear steps to reproduce the problem, a working proof of concept, the affected version and a description of the impact.
That's a fair ask, and serious programs use the same standard. It's also a reminder that this is a program for people who can show their work. It isn't a lottery.
The program promises a first response within five business days, a triage decision within 10 business days, and a bounty decision within 15 business days of triage. It asks researchers to allow a typical 90 days from confirmation before going public. Only the first valid report of a given bug gets paid.
Why it's good news
Omarchy isn't a hobby project anymore. It's got a foundation, a core team with titles, and corporate money. The Omarchy homepage currently leads with news that Alibaba Cloud has joined as a founding corporate patron with US$3 million. The project is incubated at 37signals, the company DHH co-owns. When people install an operating system, they're trusting every script it runs as root. A paid bounty with a named security lead is how a project that size shows it takes that trust seriously.
The project already credits researchers who've reported bugs privately. Its security credits page lists 12 names and teams under the line "They found it, told us privately, and waited for the patch." Now the next ones get paid as well as thanked.
It fits a bigger shift we've been following. Security work that used to be done for free, or not done at all, is getting funded. HD Moore's free OOBscan tool, which we covered in Lights Out got an auditor, comes from the same instinct. Give defenders the tools and the incentives, and fewer holes make it to users.
Linux security news usually shows up as bad news, like the four kernel flaws we wrote up in Four Linux kernel root flaws, including DirtyAH6, go public. This is the other kind.
If you're thinking of taking part
Read the full policy on the program page first. Only test systems you own or have permission to test, and don't touch anyone's personal data. The policy rules out destructive testing outright.
I won't suggest where to look. That's the researchers' job, and the program is set up so they do it privately and get paid for it. If you're an Omarchy user rather than a researcher, the advice is simpler. Keep your system updated, because that's where the fixes from this program will land.






The paper
Comments
No notes on this story yet.
Sign in to comment