When "Lost" Exploits Don't Stay Lost
The Pressure System
Following up on my last post about vulnerabilities that quietly disappear into triage limbo—we're now seeing what happens when pressure builds and the system has fewer release valves.
A recent report highlights leaked Windows Defender zero-days affecting potentially over 1 billion users after a breakdown between a researcher and the vendor. At the same time, there's been a noticeable shift in the background:
- Zerodium—once one of the largest buyers of zero-days—has significantly reduced or paused purchases of certain high-end exploits on the U.S. front
- Fewer legal gray-market outlets for researchers to offload findings
- Increasing legal and policy pressure around exploit sales and disclosure
So now we have a tightening funnel:
On the other: Fewer alternative paths (legal or otherwise) to monetize or escalate those findings.
That middle ground—the "gray zone"—is getting squeezed. And when that happens, outcomes start to shift:
- More tension in disclosure timelines
- Higher likelihood of frustration-driven exposure
- Greater systemic risk if vulnerabilities surface without coordination
The Stable System Myth
We like to think of responsible disclosure as stable infrastructure:
Researcher → Vendor → Patch → Safety 🔐
But what we're actually dealing with is a pressure system.
And right now:
- Incentives are changing
- Outlets are narrowing
- Timelines are still inconsistent
That combination matters. Because if:
- Researchers feel stuck with no resolution path
- Vendors don't provide transparent, timely engagement
- And external markets for exploits contract
Then "lost exploits" don't just sit quietly anymore. They build pressure until something gives.
Case Study: When Frustration Goes Public
The Windows Defender Zero-Day Leak (April 2026)
The clearest recent example is the Windows Defender zero-day cluster publicly released in April 2026 by a researcher using the alias Chaotic Eclipse.
The Pattern
Private disclosure → MSRC frustration → Public leak → Weaponization → Patch (but only for the first one)
This is not just "researcher irresponsibility." It's a pipeline failure where trust between researcher and vendor collapses, and the time between private report and public weaponization becomes dangerously short.
The Shrinking Exploit Market
Zerodium's Quiet Retreat
Zerodium, historically one of the largest exploit brokers, began significantly restricting purchases starting in 2023:
| Year | Event | Impact |
|---|---|---|
| 2021 | NSO Group sanctions | Buyer fear increases |
| 2023 | iOS exploit purchasing limited | "We already have enough" |
| 2024 | Public acknowledgment of oversupply | Demand-side contraction |
| 2025-2026 | Selective purchasing only | Implicit pause phase |
Market Contraction by the Numbers
Peak Market (2018-2022)
- Zerodium: $30M-$50M annually
- Crowdfense: $20M-$40M annually
- Exodus Intelligence: $10M-$25M annually
- Others: $20M-$50M annually
Total: ~$150M-$300M per year
Current Market (2024-2026)
- Zerodium: $15M-$30M annually (reduced)
- Crowdfense: $15M-$30M (quieter)
- Exodus Intelligence: $10M-$20M (stable)
- Others: $10M-$40M (shrinking/underground)
Total: ~$50M-$120M per year
The Price Divergence
While the market contracted, prices for premium exploits exploded—but only in the gray market. Legitimate channels couldn't keep up.
Browser Exploit Pricing (2020 vs 2026)
| Channel | 2020-2021 | 2024-2026 | Change |
|---|---|---|---|
| Pwn2Own Contest | $100K | $75K-$150K | +50% |
| Chrome VRP | ~$50K | Up to $250K | +400% |
| Apple Bounty | $250K max | $2M+ (with bonuses) | +700% |
| Gray Market (Crowdfense) | ~$500K-$1M | $2M-$3.5M | +300% |
The Frustration → Alternative Path Pipeline
While direct "vendor dismissed me, so I sold it to Zerodium" cases are rare in public (exploit sales are private), the broader pipeline is well-documented:
Documented Pattern
- Researcher privately reports issue
- Vendor dismisses, delays, or mishandles the report
- Researcher loses trust in coordinated disclosure
- Researcher moves to alternative path:
- Public disclosure / PoC release (BlueHammer)
- Private sale / broker inquiry (rarely documented)
- Non-vendor monetization (contests, direct contracts)
Why Direct Sales Are Invisible
The scarcity of public "dismissal → sale" cases is explainable:
- Exploit sales are confidential — Brokers advertise buying "original and previously unreported zero-day research," but transactions are private
- Public admission creates legal risk — Openly saying you sold an unpatched exploit invites scrutiny from vendors, law enforcement, and future employers
- Public disclosure is better leverage — If the goal is to pressure the vendor or maintain reputation, a blog post is more visible than a private sale
Project Zero: Pressure Without Resolution
Google Project Zero's 90-day disclosure deadline has been one of the most important forcing functions in vulnerability disclosure. It improved vendor response times dramatically—but it also created new failure modes.
What Improved
- Median patch times decreased from ~120-200 days (pre-2014) to ~30-60 days (2020s) for top vendors
- Industry-wide accountability and transparency
- Forced prioritization of high-severity bugs
What Didn't Improve
- Vendor triage quality
- Researcher trust
- Handling of disputed findings
New Risks Introduced
- Public disclosure before safe patch — If vendor fails to fix in 90 days, vulnerability becomes public while users are still unprotected
- Rushed patches — Some vulnerabilities require architectural changes; 90 days may be too short for safe remediation
- Increased adversarial dynamics — Vendors may stall until deadline, then rush patch at last minute
Where the Exploits Actually Go
When vendors fail and legitimate markets shrink, who is actually acquiring exploits?
Nation-states remain the dominant high-end buyers—but the acquisition pipeline has evolved from broker-centric to more fragmented, opaque, and sometimes direct channels.
The Pipeline Evolution
| Phase | Model | Characteristics |
|---|---|---|
| Pre-2021 | Broker-heavy | Zerodium, NSO pipeline; semi-legitimate gray market |
| 2021-2023 | Sanctions disrupt | NSO blacklisted; Pegasus revelations; legal scrutiny spikes |
| 2023-2026 | Fragmented, hybrid | Direct contractors, private firms, underground markets, more covert |
Evidence of Ongoing Acquisition
1. Active Exploitation Reports
Google TAG, Apple, and Microsoft regularly report zero-days used in targeted attacks—often patched after exploitation. Someone is acquiring these exploits before vendors fix them.
2. Continued High Pricing
Crowdfense still lists Chrome/Safari chains at $2M-$3.5M. Demand is strong; buyers are willing to pay.
3. Criminal Case: L3Harris / Russian Broker (2025-2026)
Former executive Peter Williams pleaded guilty and was sentenced to 87 months in prison for selling stolen cyber-exploit components to a Russian broker for $1.3M in cryptocurrency. Exploit acquisition pipelines are still active—even under legal scrutiny.
The Legal Squeeze
The legal landscape shifted in two opposite directions between 2020-2026:
CFAA Got Narrower (Good for Researchers)
After Van Buren v. United States (2021), the Supreme Court rejected expansive CFAA interpretations. DOJ later updated charging policy, limiting aggressive theories around terms-of-service violations.
Export Controls Got Broader (Bad for Exploit Sales)
Cases like Project Raven (2021) and Peter Williams (2025-2026) show that selling exploit capabilities—especially when tied to stolen IP, foreign governments, or restricted brokers—can lead to:
- Deferred prosecution agreements
- Multi-million-dollar penalties
- Asset forfeiture (cryptocurrency, house, luxury goods)
- Prison (87 months in Williams case)
The Fragmented Ecosystem
As structured markets shrink and vendor trust declines, disclosure becomes more fragmented, less transparent, and more strategic.
Emerging Alternative Paths
1. Direct-to-Government / Contractor Relationships
Instead of Researcher → Broker → Government, we now see Researcher → Private firm → Government. More money still exists, but access is closed, relationship-driven, and less visible.
2. Underground / Invite-Only Markets
As visible brokers shrink, underground markets have become more selective with invite-only structures, crypto payments, and escrow systems. The market didn't disappear—it became harder to observe.
3. Public Disclosure as Leverage
Researchers increasingly use partial details, PoCs, or blog posts to create pressure on vendors, establish credibility, and signal to buyers/recruiters. Publication is no longer just disclosure—it's also marketing and leverage.
4. Subscription Intelligence Platforms
Instead of selling a single exploit, researchers contribute vulnerabilities to platforms that sell intelligence feeds and early warnings. Lower legal risk, recurring revenue, broader customer base—but lower payout per vulnerability.
5. Crypto-Based Transactions
Cryptocurrency enables pseudonymous transactions and cross-border payments, reducing banking visibility and compliance friction. The L3Harris case involved crypto payments; underground markets are often crypto-based.
| Path | Transparency | Payout | Risk |
|---|---|---|---|
| Bug bounty | High | Low–Medium | Low |
| Broker | Medium | High | Medium |
| Direct gov/contractor | Low | High | High |
| Underground market | Very low | High | Very high |
| Public disclosure | High | Indirect | Medium |
| Subscription intel | Medium | Medium | Low–Medium |
The Transparency Gap
Most major vendors do not publish meaningful public transparency about their vulnerability triage queues. We can see outputs (payouts, valid bugs, advisories) but not the queue dynamics that determine whether researchers feel heard, delayed, dismissed, or pushed elsewhere.
What Vendors Publish
- Total payouts
- Number of rewarded researchers
- Sometimes counts of valid findings
- Public CVE/advisory feeds after resolution
What Vendors Don't Publish
- Average or median time to first human response
- Average or median time to triage decision
- Backlog size
- Share of reports marked: valid, invalid, duplicate, informational/won't fix
- Percentage of valid reports that led to patch vs. accepted risk
HackerOne and Bugcrowd expose the richest queue metrics, but primarily to customers inside their platforms rather than to the public. Google, Microsoft, and Apple publish stronger data on payouts and valid bugs than on queue health or rejection-path breakdowns.
The public can see that vulnerabilities are found and sometimes fixed, but cannot clearly see how many reports are delayed, deprioritized, marked informational, or left to age in the queue.
The Real Question
This isn't about defending leaks or unsafe disclosure. It's about recognizing the ecosystem dynamics that make them more likely.
We're dealing with a pressure system where:
- Researchers find valid vulnerabilities
- Vendors provide inconsistent, opaque triage
- Exploit brokers have contracted 40-70%
- Legal risks have increased for alternative paths
- Nation-state demand remains constant but less visible
- Transparency about queue health is minimal
When researchers end up with:
- Valid findings
- No response or dismissive response
- No legal outlet
- And no good options
...the exploits don't stay lost. They build pressure until something gives.
Because right now, the system is optimized for outputs (patches, advisories, bounty totals) but not for trust (queue transparency, researcher experience, coordination quality).
And when trust breaks, exploits don't disappear. They migrate to the highest bidder with the least visibility.
The disappearance of brokers like Zerodium from public visibility does not mean exploits stopped being sold—it means they stopped being sold where we can see them.