← Blog · published Oct 3, 2026

How to spot fake or farmed GitHub bounties before you waste time

Not every issue labelled with a dollar amount pays. Some are honeypots, some are self-funded by the project owner, and some are simply already solved. These are the checks worth doing in a couple of minutes before you commit hours. They are the same signals the BountyOS engine applies to every listing.

1. Who proposed the bounty?

If the repository owner opened the issue and attached the bounty on their own project, treat the amount as unverified. Real funding usually comes through a platform's bot or a clearly separate sponsor, with a visible confirmation from the platform on the issue.

2. Is the repository trustworthy?

A brand-new repository with almost no stars posting a large bounty is the classic farm pattern. Check the repo age, stars, recent activity and whether it is archived. An archived or abandoned repo cannot merge your pull request no matter what the issue says.

3. Is the issue already solved or taken?

Look for an assignee, linked pull requests, and especially a merged pull request that references the issue. If the work is already merged, there is nothing left to claim even if the issue is still open.

4. How many people are already on it?

Count open pull requests and recent comments claiming the issue. Several open attempts, or a stream of near-identical bot pull requests, mean your odds are low. A fresh issue with no competition is worth far more than the same amount on a crowded one.

5. Does the project have a track record?

Skim the repository's closed issues and merged pull requests. Projects that pay and merge external contributions leave visible history; projects with none are a gamble. Also read the contributing guide and any AI-code policy before you start.

6. Does the amount match reality?

Amounts get edited and bounties get withdrawn. Re-check the issue and the platform page just before you submit your work, not only when you start.

Automating the boring part

BountyOS runs these checks on every listing it finds and only promotes bounties that pass: confirmed payout, healthy repository, not assigned, limited competition, and no merged solution already referencing the issue. See what survives the filters on the live bounty board.

FAQ

What is a farmed or fake bounty? It is a listing that looks like a paid issue but is unlikely to pay out: a bounty the repository owner created on their own project, a new throwaway repository, an issue that is already solved or assigned, or a listing flooded with bot pull requests.

Does a large amount mean the bounty is real? No. Very large amounts on brand-new or low-trust repositories are a classic red flag. Judge the repository and the issue history, not only the number.

Can a bounty be real and still not worth it? Yes. A real bounty with many competing pull requests, a stale repository or an issue that is already assigned can still cost you hours for no payout, so competition and project health matter as much as legitimacy.

See also: GitHub bounty hunting guide · Open source bounties guide · Live bounty board

Versión en español · Versão em português

Start free with GitHub