Deep article

10 Red Flags When Someone Offers to Buy Your Code

The clearest warning signs are a buyer who asks you to install or run something, wants your code before a signed contract, or asks you to pay a fee. A fair buyer assesses fit from what you tell them, puts everything in writing and pays you, not the other way round.

5 min readPublished October 11, 2026By Alex Drew, Founder and CEO, Odys Global

The biggest red flags when someone offers to buy your code are requests to install or run software, demands for the code before a signed contract, and any fee you must pay first. A fair buyer works the other way round: it learns about your product from what you tell it, makes an offer, signs a written agreement, and only then receives cleaned code and pays you. Here are the ten warning signs, why each one matters and what a fair process looks like instead.

Why do code sellers get targeted?

Because old code often sits next to valuable things. A forgotten repository can hold live API keys, cloud credentials and database passwords. GitGuardian counted about 29 million secrets leaked in public GitHub commits in 2025, up 34% in a year, and found that nearly two thirds of valid secrets leaked in 2022 were still not revoked in 2026. Private repositories are worse: about six times more likely to contain hardcoded secrets than public ones.

Many owners also hear for the first time that their code has value, and may not know what a normal process looks like. That combination is what bad actors look for.

What are the 10 red flags to watch for?

1. They ask you to install or run something

A “valuation tool”, a scanner, a browser extension, a remote access app, a script to “check code quality”. Never run a stranger’s script on a machine that holds your code or credentials. It can read your files, keys and logged-in sessions. A fair buyer never needs you to install or run anything on your computer. If you want to size your code yourself, download a well-known free counter such as cloc or tokei from its official page.

2. They want the code before a signed contract

Read access to “take a quick look”, a zip “for due diligence”, an invite to a private repository. Once they have it, there is nothing left to sell. A fair buyer decides from what you tell it and receives code only after a written agreement is signed.

3. They ask you to pay first

Listing fees, verification fees, escrow setup fees, “legal costs”, a fee to release your payment. You are the seller; money should flow to you. Be clear about the difference with established marketplaces for running businesses, which publish their seller fees openly before you list. A private buyer asking you for money is something else.

4. They are vague about who is buying and why

“An investor group”, “a client of ours”, “a partner who prefers to stay anonymous”. You should know who signs the contract and what the code will be used for. Confidentiality about the seller is normal; secrecy about the buyer is not.

5. There is no written agreement, or it arrives at the last minute

A handshake, an email thread, a contract sent an hour before “the deadline”. In the US, a transfer of copyright is not valid without a signed written instrument. A real buyer wants a proper agreement and gives you time to have a lawyer read it. Our guide to what is in a source code purchase agreement shows what one should contain.

6. They apply pressure

“This offer expires tonight”, “we have three other sellers”, “decide on this call”. Old code does not go bad overnight. Pressure exists to stop you checking things. A fair offer gives you time and carries no obligation.

7. Payment depends on “approval by a partner”

An offer that will be paid only once an unnamed partner approves, after the code has been handed over. That turns a sale into a free sample. A fair agreement fixes the price and pays on transfer, with no condition that depends on someone you have never met.

8. They ask for your credentials or admin access

Your GitHub password, a cloud console login, an admin seat on your organization, your two-factor codes, or a request to “connect” or “authorize” their app on your GitHub account, which can quietly give it read access to your private repositories. None of that is needed to buy code. A repository can be transferred to another account through GitHub’s own transfer feature, without anyone logging in as you.

9. They want your databases or user data

A buyer who asks for the production database, user records, customer lists or chat logs is after something other than code, and you may have legal duties about that data. Under GDPR, breaking core principles such as data minimization can lead to fines of up to 20 million euros or 4% of global turnover, whichever is higher. We never take databases, user records, customer data or chat logs. This is not legal advice; ask a qualified lawyer about your own data protection duties.

10. They plan to use your brand or relaunch your product as yours

An offer that includes your name, your logo or a promise to “bring the product back” under its old brand can tie you to something you do not control. A buyer of code for research has no reason to use your brand at all. Read the use section of any agreement carefully.

What does a fair process look like instead?

Stage Fair buyer Red flag
First contact Asks what the product is, its size and who owns it Asks for code, access or credentials
Assessment Based on what you tell it Requires a script, tool or repository access
Money Pays you; no fees to the seller Asks you to pay first
Contract Written, signed before any code moves None, or rushed at the last minute
Payment Fixed price paid on transfer Depends on approval by someone you have never met
Data Leaves databases and user records out Wants the production database
Your name Never used Brand reused or product relaunched as yours

This is how we work. You fill in a short form with no code, we have a call, we review based on what you tell us and make a cash offer with no obligation. Both sides sign a written agreement, you remove secrets, keys and personal data with our help, and you are paid one agreed cash price on transfer. Odys AI Labs uses the code for AI training and R&D, and we may also work on it with research partners. Our guide on how selling your old code works explains every step.

How do you protect yourself before talking to any buyer?

  • Rotate keys now. Revoke or rotate every secret that was ever in the code; our guide on removing API keys and passwords from old code explains how, including git history.
  • Prepare a description, not a download. A one-page overview answers most questions without sharing code. Our guide on how to prepare a codebase for sale shows what to put in it.
  • Keep code on your own machine until there is a signed agreement.
  • Check the use clause and the payment clause before you sign.

What to do next

Frequently asked questions

Is it normal for a code buyer to ask for repository access before an offer?

No. A fair buyer can decide whether it is interested from what you tell it: the product, its size, languages, history, docs, tests and who owns the rights. Repository access before a signed agreement gives away the thing you are selling for nothing. Share a description, not the code, and hand over code only after both sides sign.

Someone sent me a script to scan my code for valuation. Should I run it?

No. Never run a stranger's script on a machine that holds your code or credentials. A script can read files, keys and browser sessions, or install something you cannot see. A fair buyer never needs you to install or run anything. If you want to size your code, use well-known free tools such as cloc or tokei that you download yourself.

What should I do if I already shared code or keys with a suspicious buyer?

Act on the keys first. Revoke or rotate every password, API key and token that was in the code or on the machine involved, then change account passwords and turn on two-factor authentication. Remove any access you granted: repository collaborators, deploy keys, SSH keys and apps you authorized on your GitHub account. Note what was shared and when. If you ran a script, have the machine checked. For the legal side, speak to a qualified lawyer.

Is it a red flag if the buyer will not name who uses the code?

Vagueness is a warning sign. A fair buyer should say plainly who buys and what the code is used for. With us, Odys AI Labs buys the code and uses it for AI training and R&D, and we may also work on it with research partners. We never use your brand or name and never relaunch the product as yours.

Your next move

Find out what your old code is worth right now.

Tell us about the product in about a minute. No code needed. We review the details and come back with a cash offer or a plain no.

Get my free code valuation →
About 60 secondsContract before any code100% confidential

Owner situations

Value my code →