On October 2, 2026, DHH announced that the Omacom Foundation put $100,000 behind an official Omarchy bug bounty on HackerOne — and that Mehmet İnce is joining Omarchy Core as head of security. That is real money and a named owner for the security queue. Good.
Bounty is a process, not a vibe
HackerOne gives researchers a familiar place to submit, track, and get paid. Omarchy still accepts email to security@omarchy.org if you do not want an account. The security page spells out scope. Paying for private reports beats hoping random GitHub issues catch critical paths.
Mehmet has already been around the Omarchy Security Team. Promoting him to set direction — bounty triage through how defaults ship — is the part I care about. Pretty desktops still run privileged helpers, themes, agents, and SSH forwards. Somebody has to own the boring checklist.
Same season, default-creds reminder
Pair that announcement with a quieter but sharper bug from the same stretch: Try Omarchy for Windows v0.6.2 closed a quick-start account that used omarchy / omarchy with passwordless sudo. If you had forwarded guest SSH — especially on a LAN — anyone who reached the port could log in and own the guest. The fix makes that account keys-only and authorizes your key when you set up the forward.
Omarchy’s last few point releases already showed the security team moving — Docker group opt-in, theme code blocked at install, USB device names stopped from becoming Hyprland Lua, signed packages, tighter sudo timers. A funded bounty with a named head of security is how you keep that pace when the desktop grows agent surfaces and community plugins by the thousand. Patrons funding $100K is not marketing fluff; it is triage capacity.
Default credentials are old news until they are your news. A public bounty and a patched trial image belong in the same mental folder: assume someone will try the obvious login, and pay people who find the less obvious ones. Update Try Omarchy if you still have a quick-start guest hanging around.
Happy hacking — and report responsibly.
References & Further Reading
- Omarchy News – $100K HackerOne bounty – DHH announcement; Mehmet İnce as head of security.
- HackerOne – Omarchy program – Submission portal for the bounty.
- Omarchy – Security page – Scope and reporting guidance.
- GitHub – try-omarchy-windows v0.6.2 – Quick-start SSH default-creds fix.
- 0xcc.io – Docker group root escalation – Earlier default-privilege writeup that pushed 4.0.1.
- Omarchy Linux – Is Omarchy safe? – Roundup of 4.0.x security defaults and fixes.