How a Late-Night iSpy.today Alert Turned Into a $1000 Bounty
About a month ago, I launched iSpy.today, a tool built for bug bounty hunters to monitor GitHub push events in real time and catch exposed…
How a Late-Night iSpy.today Alert Turned Into a $1000 Bounty
About a month ago, I launched iSpy.today, a tool built for bug bounty hunters to monitor GitHub push events in real time and catch exposed secrets. I had added several targets by configuring their GitHub org names and matching email domains.

iSpy.today
One night, while aimlessly scrolling on my phone around 2AM, an iSpy alert came in.

iSpy.today alert in discord

iSpy.today found secret
The alert flagged a commit with what looked like an API key. The email used in the commit matched the domain of one of my targets, but the repository wasn’t under their official GitHub org.
That got my attention.
I dug a bit deeper and found that the GitHub org owning the repo was also operated by the target — just not their main or public-facing one.
I confirmed it was in-scope and quickly submitted a report on HackerOne.
The next morning, another iSpy user messaged me saying they had received the same alert but held off reporting to avoid a duplicate. Looks like I got there first — and lucky.
The report was triaged and rewarded the same day with a $1,000 bounty.

H1 Report Summary
메타데이터
- post_id
- 4e111be6abbd
- slug
- how-a-late-night-ispy-today-alert-turned-into-a-1000-bounty-4e111be6abbd
- url
- https://infosecwriteups.com/how-a-late-night-ispy-today-alert-turned-into-a-1000-bounty-4e111be6abbd
- canonical_url
- https://infosecwriteups.com/how-a-late-night-ispy-today-alert-turned-into-a-1000-bounty-4e111be6abbd
- author_url
- https://medium.com/@arshadkazmi42
- status
- ok
- fetched_at
- 2026-08-02 00:12:56