In September 2015, a company called Zerodium published a bounty offer that shocked the security research community: $1 million for a working remote jailbreak of iOS 9, delivered via Safari or Chrome. This was roughly ten times what Apple's bug bounty program paid for its highest-severity findings, and Apple did not yet have a public bug bounty program at all. Within three months, Zerodium announced a team had claimed the prize. The winning exploit was never disclosed. It went directly to Zerodium's clients, who were described only as "government agencies in need of specific and tailored cybersecurity capabilities."

The zero-day market - the ecosystem through which vulnerability research is bought and sold - had existed for decades before Zerodium made it this visible. What Zerodium's founder Chaouki Bekrar had done was not create the market but formalize and publicize it: published price lists, professional marketing, explicit acknowledgment that the buyers were government intelligence and law enforcement agencies. In doing so, he made concrete a debate that the security community had been having abstractly for years: who benefits from the existence of undisclosed vulnerabilities, what is their appropriate price, and what are the consequences of a market in which governments are the most significant buyers?

The Structure of the Market

The zero-day market operates across several distinct tiers, differing primarily in the directness of the government relationship and the price points involved.

At the top tier are companies like Zerodium - operating legally, publicly visible, explicitly intermediating between independent researchers and government buyers. Zerodium's published price list in 2019 offered up to $2.5 million for "full chain with persistence" iOS exploits, $2 million for Android, $1 million for Chrome or Safari remote code execution, $500,000 for Microsoft Edge or Firefox, $250,000 for Apache or IIS remote code execution, and smaller amounts down through dozens of categories. These prices reflect market clearing rates - what government buyers will pay. The prices themselves are intelligence about what the NSA, CIA, and their foreign equivalents value most.

[INFO]
Zerodium's published price hierarchy reveals a consistent logic: mobility and ubiquity command premium prices. iOS commands more than Android partly because it is the platform of choice for high-value targets (executives, government officials, journalists), partly because its security architecture makes exploitation more difficult. Browser exploits are valued because they provide the most common initial access vector. The price differential between "no persistence" and "full chain with persistence" (typically 2-3x) reflects the significant additional work required to survive device reboots.

Below the top tier are brokers operating in grayer territory - companies that buy from researchers and resell to governments without quite the same public profile. Vupen, a French company founded by Bekrar before Zerodium, operated similarly but more quietly before it was dissolved when Bekrar moved to the US to found Zerodium. Crowdfense, based in the UAE, operates on a similar model. These companies occupy a legally permissible space in most jurisdictions - buying and selling information is not inherently illegal, and vulnerability research is protected speech in most free societies - but operate with varying degrees of transparency about who their customers are.

Below that are individual researchers selling directly to government agencies through defense contractor intermediaries. Agencies like the NSA conduct direct procurement of zero-days through cleared defense contractors who serve as cut-outs. A researcher with a high-value exploit might approach Raytheon or Northrop Grumman's cybersecurity divisions rather than a public broker, receiving a single upfront payment in exchange for a non-disclosure commitment. The terms of such arrangements are almost never made public.

The NSA as Buyer: Tailored Access Operations

The NSA's Tailored Access Operations (TAO) division - renamed Computer Network Operations in recent years - was the primary US government buyer of offensive cyber capabilities including zero-days. The Snowden disclosures provided some visibility into the scale of this market from the government side: classified budget documents showed the NSA spending hundreds of millions of dollars annually on "covert purchases of software vulnerabilities" from private vendors.

The logic of government zero-day procurement is straightforward: offensive cyber operations require exploitation of vulnerabilities in target systems. Custom-developed vulnerabilities are expensive and time-consuming to develop internally. Purchasing from a market of independent researchers is economically efficient. The question the market creates is whether purchasing a vulnerability and keeping it secret is in the national interest, and for whom.

The Obama administration developed the Vulnerabilities Equities Process (VEP) in 2010, refined in 2014 after the Heartbleed disclosure made the "should we have disclosed this?" question politically salient, and formalized in a 2017 charter. The VEP was supposed to be the interagency process through which the US government decided whether to disclose vulnerabilities it knew about or retain them for offensive use. The charter established criteria: the number of people at risk from the vulnerability, the severity of the risk, the likelihood that adversaries already knew about it, the intelligence value of the exploit, and the availability of mitigations.

In practice, the VEP was criticized by security researchers and policy advocates as systemically biased toward retention. The agencies with the most to gain from retaining vulnerabilities - NSA, CIA, military cyber commands - were the primary participants in the process. The agencies most focused on defensive security - CISA (then DHS-NPPD) - had fewer resources and less institutional weight in the deliberations. The criteria for disclosure were vague enough to support retention in most cases where offensive value existed.

[WARNING]
The EternalBlue vulnerability - the SMB exploit stolen from the NSA and deployed by WannaCry and NotPetya - was a direct product of the retain/disclose decision made through the Vulnerabilities Equities Process. The NSA had known about MS17-010 (the vulnerability EternalBlue exploited) for years before the ShadowBrokers stole and published it. The VEP process had determined the intelligence value exceeded the disclosure benefit. When EternalBlue was published, Microsoft was given only weeks to patch it before the ShadowBrokers release - and when WannaCry deployed it against patched and unpatched systems alike, the cost was measured in billions of dollars and NHS hospital shutdowns. The decision to retain had catastrophic consequences for people with no voice in the process.

Pricing Signals and the Economics of Secrecy

The zero-day market's prices carry information beyond what they reveal about government procurement preferences. They also reveal the approximate cost of vulnerability research - the floor below which researchers would rather sell elsewhere - and the approximate value the market assigns to security versus exploitability.

A $2.5 million iOS full-chain exploit represents years of specialized research. A skilled iOS security researcher might spend 12 to 24 months developing such a capability, with no guarantee of success. At market rates for that researcher's time ($200-400K per year in legitimate security work), the research investment might be $400K to $800K. The $2.5 million price represents a 3-6x multiple over research cost, which is a reasonable return for a high-risk research project but not extraordinary. The prices are high in absolute terms because the research is genuinely difficult.

The market also contains significant information asymmetries. A researcher selling an exploit to Zerodium does not know whether the same vulnerability has already been sold to another broker or discovered internally by another government's intelligence service. They do not know the operational context in which it will be used. They cannot know how much value the buyer extracts from the exploit relative to what they paid. The market is opaque in ways that systematically disadvantage sellers relative to institutional buyers.

The concept of "N-day" versus "0-day" matters here. A zero-day is a vulnerability unknown to the vendor and therefore unpatched. An N-day is a known vulnerability for which a patch exists but which many systems have not yet applied. N-days are worth less than zero-days to intelligence agencies conducting targeted operations against hardened targets who patch quickly, but N-days retain significant value for mass exploitation against enterprises and consumers who patch slowly. The half-life of a zero-day - the period before it is independently discovered, disclosed, or burned by operational use - is another dimension of its value.

The Wassenaar Arrangement and Export Controls

The sale of offensive cyber tools, including zero-days, to foreign governments is subject in principle to export control regulations under the Wassenaar Arrangement - a multilateral export control regime covering dual-use technologies. In 2013, the participating states agreed to add "intrusion software" and "IP network surveillance systems" to the Wassenaar control lists, intending to prevent the sale of surveillance tools to authoritarian regimes that would use them to suppress dissent.

The implementation of Wassenaar's cybersecurity provisions has been controversial and largely ineffective. The definitions in the initial proposal were so broad that they potentially captured legitimate security research tools - penetration testing frameworks, vulnerability scanners - creating compliance burdens for legitimate security companies without meaningfully impeding government procurement of offensive capabilities. The United States delayed implementation for years while the security industry lobbied for definition changes. The EU implemented versions that varied significantly by member state.

The fundamental tension in export-controlling offensive cyber tools is that the same capability can be legitimate security research, legitimate law enforcement tool, or an instrument of authoritarian suppression, depending entirely on who uses it and against whom. The Hacking Team breach (2015) demonstrated this concretely: their Remote Control System malware was sold to Sudan despite UN arms embargo, to Bahrain which used it against Arab Spring activists, and to Ethiopia, Morocco, and Egypt which used it against journalists and political dissidents. The tools were not clearly dual-use in any innocent sense - they were explicitly designed for covert surveillance of specific individuals.

Bug Bounties as Market Competition

The emergence of large corporate bug bounty programs represents a partial but incomplete counter to the government-dominated zero-day market. Apple launched its private bug bounty program in 2016 (now public) and increased maximum payouts to $1 million for kernel zero-click exploits in 2019. Google's Project Zero and Android Security Rewards have paid out tens of millions cumulatively. Microsoft's bounty programs now offer up to $250,000 for Azure and Hyper-V vulnerabilities.

These amounts are competitive with mid-tier broker payouts for some vulnerability classes but remain substantially below what Zerodium and government direct procurement offer for high-value targets. A researcher with a full-chain iOS browser-to-kernel exploit can expect $1 million from Apple's bug bounty, $2.5 million from Zerodium, and an unknowable but potentially higher amount from direct government procurement. The financial calculation, for a researcher with no ethical constraints, systematically favors non-disclosure.

There are non-financial factors that move researchers toward disclosure: legal risk from dealing with government buyers, moral discomfort with not knowing how exploits will be used, reputational value in the security community from published research and CVEs, and the simply practical consideration that maintaining secrecy about having sold a capability to a government is difficult and carries risks. Many researchers do choose the bug bounty path. But the market structure does not make it the default economically rational choice.

The Gray Market and Criminal Intersection

Below the legitimate tier of the zero-day market lies a gray-to-black market in which vulnerabilities and exploit code circulate among criminal organizations, ransomware operators, and cybercriminals. This market is less organized and less transparent than the government side but is substantial in volume if not in price per transaction. Criminal buyers typically pay less than government buyers for the same capability because they have lower requirements for reliability and stealth - ransomware that causes detectable damage is still profitable, whereas intelligence operations require zero visible footprint.

The criminal market also intersects with the government market in ways that are not always clean. Government contractors are sometimes the same individuals who have relationships with gray-market brokers. Exploits developed for government use sometimes leak into the criminal market when the government loses control of them - EternalBlue being the most expensive example. Criminal groups with state patronage (certain Russian ransomware operators, North Korean Lazarus Group affiliates) operate with capabilities and resources that blur the distinction between criminal and state-sponsored exploitation markets.

[IOC]
Zerodium price list (2019) for reference: Full iOS chain, no persistence: $1.5M / with persistence: $2.5M. Full Android chain: $2M. Chrome or Safari, full chain: $1M. Windows zero-click: $1M. VMware ESXi guest-to-host: $250K. Apache/IIS/Nginx RCE: $250K. OpenSSL RCE: $100K. Microsoft Outlook/Teams: $100-250K. SMB RCE (Windows): $150K. These prices vary significantly over time as vendors patch and attack surface changes.

The Market's Unsolvable Problem

The zero-day market presents a genuine policy dilemma that has no clean solution. Governments need offensive cyber capabilities to conduct intelligence operations and, increasingly, offensive cyber operations that serve strategic deterrence. Those capabilities require exploiting real vulnerabilities in real systems. Buying from a market of independent researchers is more economically efficient than building all capabilities internally. All of this is true.

Also true: every vulnerability retained for offensive use is a vulnerability that millions of people remain exposed to. The government cannot control who else has found the vulnerability. They cannot guarantee their own exploits will not be stolen. They cannot ensure the capabilities they purchase will only be used in ways consistent with the values they claim to hold. And once an exploit is used, it has a non-trivial probability of being discovered by the target, shared with researchers, reverse-engineered, and ultimately published - at which point the defensive window between the original discovery and public knowledge is compressed to days rather than the months a coordinated disclosure process would provide.

The people who live and work on the vulnerable systems do not get a vote in this calculation. The VEP process does not have a seat reserved for the hospital network administrator trying to defend against the next WannaCry. The market will continue to function as long as governments need offensive capabilities and researchers need income. The question is not whether to have the market but whether to govern it - and if so, how to govern it in a way that does not simply tilt the playing field further toward well-resourced institutional buyers at the expense of everyone using the systems they exploit.