Troy Hunt says he will be open sourcing the Have I Been Pwned code base
Let me just cut straight to it: I'm going to open source the Have I Been Pwned code base. The decision has been a while coming and it took a failed M&A process to get here, but the code will be turned over to the public …
Context & Ripple Effects
Troy Hunt's announcement closes a loop that started when he put Have I Been Pwned up for sale in 2019 to keep pace with the breach archive's growth as its founder and sole employee. That process failed, and a month before this post he had discussed his reluctance to retain breached data and the site's unresolved revenue model — open sourcing is what he chose instead of a corporate owner.
The move builds on an existing pattern of opening the service's core: the Pwned Passwords API had already let password managers like 1Password check logins against leaked credentials, and the code handover extends that trust model from the data to the platform itself.
First-order effects
- Hunt, as sole employee, shifts from sole custodian to maintainer-in-chief: the code base's survival no longer depends on one person's availability or a successful exit.
- The failed M&A process becomes public context for the project's governance — buyers walked, and the community inherits the scaling problem instead.
Second-order effects
- Integrators such as password managers already consuming the Pwned Passwords API gain auditability of the code they depend on, lowering the trust barrier to deeper adoption.
- A public code base invites external contributors and forks, distributing maintenance load that a single-person operation could not carry as breach volumes grew.
Third-order effects
- The pattern — critical security infrastructure run by one person, exit attempt fails, code goes open source — points toward community-governed public-interest security services as an alternative to acquisition by platform vendors.
- If the open-sourcing holds, the boundary between a commercial API service and an open utility blurs: revenue shifts toward hosted data and integrations rather than proprietary software.
The trend: Independently operated breach-notification and credential-checking infrastructure is converging on open source plus public-sector data sharing as the sustainability model when private ownership stalls.