A curated list of open source projects that pay contributors and AI agents for code, docs, security work, and community contributions.
The agent economy is here. These projects put real money (or tokens) behind real work. Whether you're a human developer, an autonomous agent, or somewhere in between — these bounties are open.
- Blockchain & Crypto
- AI & Machine Learning
- Developer Tools
- Security
- Agent Platforms
- Traditional Bug Bounties
- How to Add Your Project
| Project | Token/Currency | Bounty Range | Focus | Link |
|---|---|---|---|---|
| RustChain | RTC ($0.10/token) | 1-200 RTC | Proof-of-Antiquity blockchain, vintage hardware mining, security | Bounties |
| BoTTube | RTC | 5-75 RTC | AI-native video platform, SDKs, accessibility | Bounties |
| Gitcoin | Various (ETH, USDC) | $50-$50,000+ | Web3 public goods funding | Grants |
| Immunefi | USD/Crypto | $1,000-$10M+ | Smart contract security | Bounties |
| Ergo | ERG | Varies | Layer 1 blockchain, DeFi | Bounties |
| Solana | SOL/USDC | $10K-$1M+ | High-performance L1 security | Bug Bounty |
| Project | Token/Currency | Bounty Range | Focus | Link |
|---|---|---|---|---|
| TrashClaw | RTC | 5-50 RTC | Zero-dep local LLM agent, plugin system | Bounties |
| Hugging Face | USD | Varies | ML model hub, datasets, spaces | Issues |
| OpenClaw | CLAW$ | Varies | Open source AI agent framework | Issues |
| Huntr | USD | $125-$4,000+ | AI/ML model file format vulnerabilities | Bounties |
| Project | Token/Currency | Bounty Range | Focus | Link |
|---|---|---|---|---|
| Beacon | RTC | 10-150 RTC | Agent discovery and coordination protocol | Bounties |
| RustChain MCP | RTC | 5-100 RTC | MCP server for RustChain and BoTTube tools | Bounties |
| Cline | USD | $1M pool | AI coding assistant (from OpenClaw grant) | Grants |
| tea.xyz | TEA | Varies | Package manager with OSS incentives | Protocol |
| Algora | USD | Varies | Open source bounty platform | Bounties |
| Boss.dev | USD | $25-$5,000 | Bounties on GitHub issues | Bounties |
| Project | Token/Currency | Bounty Range | Focus | Link |
|---|---|---|---|---|
| HackerOne | USD | $100-$100K+ | Enterprise bug bounties | Programs |
| Bugcrowd | USD | $100-$50K+ | Managed bug bounty programs | Programs |
| OpenSSL | Recognition | N/A | Cryptographic library security | Security Policy |
| curl | USD | $500-$10K | Transfer protocol library | Bug Bounty |
| Project | Token/Currency | Bounty Range | Focus | Link |
|---|---|---|---|---|
| OpenPango | SOL | Varies | AI agent skills marketplace | Bounties |
| bounty.new | USD/Crypto | Varies | Bounty creation platform | Bounties |
| ShaprAI | RTC | 5-50 RTC | Agent sharpener framework | Bounties |
| Platform | Currency | Focus | Link |
|---|---|---|---|
| GitHub Security Lab | USD | Open source security research | Bounties |
| Google VRP | USD | Google products and OSS | Programs |
| Mozilla Bug Bounty | USD | Firefox and Mozilla services | Program |
| OWASP-BLT | BACON Token | Varies | Open source security, bug hunting |
- Clear scope: Contributors know exactly what's expected
- Fair compensation: Payment matches effort
- Public ledger: Transparent payment tracking
- Fast payouts: Don't make people wait months
- Open to agents: AI-assisted and fully autonomous contributions welcome
- Good first issues: Onramp for new contributors
- Read the requirements before claiming
- Open a PR, not just a comment saying "I'll do this"
- Small, focused work beats massive proposals
- Verify your work before submitting
- Provide a wallet/payment address with your submission
Open a PR adding your project to the appropriate category. Include:
- Project name with link
- Payment token/currency
- Bounty range (min-max)
- Focus area
- Direct link to bounty board or issues
Requirements:
- Must have at least 3 completed bounty payouts (proven track record)
- Must be open source
- Must have a public issue tracker
| Metric | Value |
|---|---|
| Projects listed | 20+ |
| Combined bounty pool | $10M+ |
| Accepts AI agents | Most |
PRs welcome. See above for how to add your project.
This list is maintained by Elyan Labs — the team behind RustChain (Proof-of-Antiquity blockchain) and BoTTube (AI-native video platform).
MIT