P PatchhoundWe hunt · we patch · you sleep

Proof, published.

Every bug we find in open source becomes a public case file: the diff, the test numbers, what we got wrong. It's how you judge us before paying. Client work stays confidential unless a client says otherwise.

Run your own scan first, free

Case files
PATCHED No.002
FILE No.002

The bounty was already claimed. We found two bugs anyway.

An idempotency race with a merged fix still had two real gaps: a lost-race error surfacing as a raw 500, and responses outliving their claims. Reading acceptance criteria against shipped code pays.

race conditions · payment integrity · postgres · Aug 2026
PATCHED No.001
FILE No.001

We found a repo farming AI agents with prompt injections

A "$780 bounty program" with no way to get paid and README instructions written at AI agents. How we spotted it in thirty seconds, plus the one-line fix for the real bug inside.

auth bypass · bounty programs · prompt injection · Aug 2026
Field notes

Maintaining an open source project? A free security pass from us costs you nothing but an email. We publish what we find only with your sign-off. hello@patchhound.dev.

RSS: /feed.xml · GitHub: iamwhitehat