CASE FILES OPEN

We find the hole, patch it, and publish the diff.

Patchhound is a one-hound security studio. Every fix we ship goes through a five-level verification gate and gets written up in the hunt log below: bug, diff, test numbers, mistakes included. Businesses hire us for the same treatment at a flat fee.

Get a €490 tune-up  Read the hunt log

Hunt log
FILE No.002PATCHED

The bounty was already claimed. We found two bugs anyway.

An idempotency race with a merged fix still had two real gaps: a lost-race error surfacing as a raw 500, and responses outliving their claims. Reading acceptance criteria against shipped code pays.

race conditions · payment integrity · postgres · Aug 2026
FILE No.001PATCHED

We found a repo farming AI agents with prompt injections

A "$780 bounty program" with no way to get paid and README instructions written at AI agents. How we spotted it in thirty seconds, plus the one-line fix for the real bug inside.

auth bypass · bounty programs · prompt injection · Aug 2026
The short version

Most security work asks you to trust a logo. We'd rather show you the receipts: every claim on this site traces to a public diff, a test run you can repeat, or a live request against a real server.

If your site takes form submissions, logs people in, or touches a database, it has the same class of bug we find in open source every week. The tune-up is how you find out before someone else does.

What a tune-up covers

Field notes

Maintaining an open source project? A free security pass from us costs you nothing but an email. We publish what we find only with your sign-off. hello@patchhound.dev.

RSS: /feed.xml · GitHub: iamwhitehat