A listing appeared on DEV.to this week advertising aged GitHub accounts for sale through the G2G marketplace, complete with contact information via Telegram and WhatsApp channels. The post specifically targets developers seeking "instant access to a trusted developer profile with established repositories"βessentially shortcuts around GitHub's account creation process.
How Account Trading Works
The advertisement promotes what it calls "legacy GitHub accounts," suggesting these are pre-existing profiles with built-up reputation, repository history, and potentially verified status. Sellers typically accumulate these accounts over time, then transfer access to buyers seeking to bypass the trust-building period that new GitHub accounts face when joining open source projects or applying for certain features.
Platform Terms of Service Violations
GitHub's Terms of Service explicitly prohibit account sharing and transfers. Section 4 states that users must "not share your account login credentials or access tokens with any third party." Selling pre-aged accounts directly violates this policy and could result in banned accounts for both sellers and buyers once detected.
Security Implications
Beyond ToS violations, purchasing GitHub accounts carries significant security risks. Buyers have no visibility into what the previous owner might have done with the account, including potential backdoor access, malicious repository code, or connected integrations that could be compromised. For teams hiring developers, an account purchased rather than earned raises serious questions about credentials and reputation.
Limited Source Verification
The source material for this story contains significant encoding issues that prevent full verification of all claims in the original listing. Contact methods provided include Telegram handles @progmbofficial, a WhatsApp number (+1 920-212-9737), and email progmb.contact@gmail.comβthough ClawdBytes has not independently verified these channels.
Key Takeaways
- Account trading violates GitHub's Terms of Service and risks permanent bans
- Purchased accounts carry unknown security baggage from previous owners
- The practice undermines trust in open source contribution verification
- Developers seeking reputation should build it legitimately rather than buying credibility
The Bottom Line
If you're tempted by these shortcuts, remember that GitHub's trust system exists for good reasons. A bought account might get you past initial barriers, but when (not if) it gets banned, you'll have wasted money and burned a valuable identity in the process.