Hacking News All articles
Investigation

Selling Holes in the Internet: The Shadowy Marketplace Where Zero-Days Go to the Highest Bidder

Hacking News
Selling Holes in the Internet: The Shadowy Marketplace Where Zero-Days Go to the Highest Bidder

Photo: File:Hacker-Pschorr Oktoberfest Girl.jpg by Markburger83 Derivative work: Lauro Sirgado (talk · contribs), CC BY-SA 3.0, via Wikimedia Commons

Imagine stumbling across a flaw in iOS that lets someone silently take over any iPhone on the planet. You've got two choices: report it to Apple and pocket a bug bounty, or take it somewhere else entirely — somewhere that pays orders of magnitude more and doesn't ask a lot of follow-up questions. For a growing number of security researchers, that second option is looking more attractive every year.

Welcome to the zero-day black market, where undisclosed software vulnerabilities are bought, sold, auctioned, and weaponized before most vendors even know there's a problem.

What Exactly Is a Zero-Day, and Why Does It Matter?

A zero-day is a software vulnerability that the vendor hasn't patched — or in many cases, hasn't even discovered yet. The name comes from the idea that defenders have had "zero days" to fix it. Once a flaw is disclosed and patched, it loses most of its value. But in that window between discovery and patch, it's potentially worth millions.

These aren't theoretical curiosities. Zero-days are the ammunition behind some of the most consequential cyberattacks in recent memory. The Stuxnet worm that targeted Iranian nuclear centrifuges used four zero-days simultaneously — an almost unheard-of combination at the time. More recently, zero-days in Microsoft Exchange and Pulse Secure VPN were used to breach federal agencies and critical infrastructure operators across the US.

The Pricing Tiers: From Five Figures to Eight

The market for these vulnerabilities isn't a single entity — it's a layered ecosystem with wildly different price points depending on the target, reliability, and exclusivity of the exploit.

At the low end, you've got browser exploits and local privilege escalation bugs that might move for anywhere from $5,000 to $50,000 on forums and dark web markets. These are often sold to multiple buyers and have a shorter shelf life since they're more likely to be independently discovered.

Step up to remote code execution vulnerabilities in widely deployed enterprise software — think network edge devices, VPN appliances, or widely used productivity suites — and prices jump dramatically. We're talking $100,000 to $500,000 or more for a reliable, weaponized exploit chain.

At the very top of the pyramid sit mobile operating system zero-days, particularly full-chain exploits targeting iOS and Android that allow remote takeover with zero user interaction. Firms like Zerodium — one of the few brokers operating in something resembling the open — have publicly listed acquisition prices for these at up to $2.5 million. And that's the advertised ceiling. Industry insiders suggest nation-state buyers routinely pay more through private channels.

Who's Actually Buying?

This is where things get genuinely complicated. The buyers aren't exclusively criminal organizations. In fact, a significant chunk of the market is made up of government agencies — including US ones.

Law enforcement and intelligence agencies have long purchased zero-days to support surveillance operations and offensive cyber capabilities. The NSA, FBI, and various defense contractors have all been tied to zero-day acquisitions, either directly or through intermediary brokers. This creates an uncomfortable reality: your tax dollars may have funded the purchase of a vulnerability sitting in software you use every day.

Criminal groups occupy another tier. Ransomware operators and financially motivated threat actors increasingly seek out zero-days to punch through enterprise defenses that have gotten better at catching commodity malware. When your target has next-gen endpoint detection and a competent security team, a patched CVE just won't cut it.

Then there are the nation-state actors — China's APT groups, Russia's Sandworm, North Korea's Lazarus Group — who either develop zero-days in-house or acquire them through brokers. For these groups, a single high-value exploit can be the difference between a failed intrusion and a multi-year espionage campaign.

Legitimate Researchers Getting Squeezed Out

Here's the uncomfortable truth that doesn't get discussed enough: the underground market is actively competing with legitimate bug bounty programs — and winning.

Major tech companies have expanded their bounty programs significantly over the last decade. Google, Microsoft, and Apple all offer payouts that can reach into the hundreds of thousands for critical vulnerabilities. But compare that to what Zerodium or a private broker will offer, and the math gets awkward fast. A researcher who finds a critical iOS exploit could report it to Apple for a maximum of $1 million — or sell it to a broker for potentially more, with fewer strings attached and no waiting period.

This creates a real talent drain from the defensive side of the ecosystem. Skilled independent researchers who might otherwise contribute to making software safer are instead being drawn toward buyers whose intentions aren't exactly public-facing. The security community has debated this tension for years without arriving at any clean resolution.

What This Means for Enterprise Security Teams

If you're running security for a mid-to-large US enterprise right now, the zero-day market should be keeping you up at night — and not because you need to buy anything.

The proliferation of commercial spyware vendors and exploit brokers means that capabilities once reserved for nation-states are increasingly accessible to well-funded criminal organizations. The barrier to acquiring a weaponized zero-day has dropped. Not to commodity levels, but enough that a successful ransomware crew with a few big payouts under their belt can realistically fund an exploit acquisition.

Practically speaking, this means a few things for your defensive posture. Patch velocity matters more than ever — the window between a zero-day being discovered and a patch being available is exactly when you're most exposed, but so is the window between patch release and your team actually deploying it. Threat intelligence subscriptions that track exploit market activity can give early warning signals. And network segmentation remains one of the most underrated controls for limiting what an attacker can do even after they've used a zero-day to get a foothold.

Attack surface reduction is the other big lever. Every internet-exposed service, every legacy VPN appliance, every unmanaged device is a potential target. Zero-days are expensive — attackers want to use them against targets where the payoff justifies the investment. Making your environment a harder, less lucrative target pushes threat actors toward cheaper, noisier methods that your defenses are better equipped to catch.

The Market Isn't Going Anywhere

There's no realistic scenario where the zero-day market disappears. As long as software has bugs — which is forever — and as long as some parties are willing to pay more for silence than for disclosure, this ecosystem will persist. Regulatory efforts have had limited impact, and international coordination on restricting exploit sales has been slow and incomplete.

What the security community can do is keep pressure on vendors to pay competitive bounties, advocate for policies that disincentivize government stockpiling of vulnerabilities, and build defenses that assume a zero-day will eventually be used against them.

The market exists. The buyers exist. The only question is how long it takes before that expensive zero-day lands in your network.

All Articles

Related Articles

Poison in the Pipeline: How Compromised Open-Source Packages Are Quietly Owning Your Codebase

Poison in the Pipeline: How Compromised Open-Source Packages Are Quietly Owning Your Codebase

Your Code Is Leaking: The Silent API Key Crisis Hiding in Plain Sight on GitHub

Your Code Is Leaking: The Silent API Key Crisis Hiding in Plain Sight on GitHub

Your Inbox Is Being Targeted by a Machine That Knows You Better Than Your Coworkers Do

Your Inbox Is Being Targeted by a Machine That Knows You Better Than Your Coworkers Do