Vulnerability Disclosure Exploit Markets Systemic Risk

When "Lost" Exploits Don't Stay Lost

What happens when pressure builds and the system has fewer release valves
AIMF Security Blog • April 2026 • 18 min read

The Pressure System

Following up on my last post about vulnerabilities that quietly disappear into triage limbo—we're now seeing what happens when pressure builds and the system has fewer release valves.

A recent report highlights leaked Windows Defender zero-days affecting potentially over 1 billion users after a breakdown between a researcher and the vendor. At the same time, there's been a noticeable shift in the background:

  • Zerodium—once one of the largest buyers of zero-days—has significantly reduced or paused purchases of certain high-end exploits on the U.S. front
  • Fewer legal gray-market outlets for researchers to offload findings
  • Increasing legal and policy pressure around exploit sales and disclosure

So now we have a tightening funnel:

On one side: Researchers finding real, impactful vulnerabilities sitting in long or opaque triage cycles.

On the other: Fewer alternative paths (legal or otherwise) to monetize or escalate those findings.

That middle ground—the "gray zone"—is getting squeezed. And when that happens, outcomes start to shift:

  • More tension in disclosure timelines
  • Higher likelihood of frustration-driven exposure
  • Greater systemic risk if vulnerabilities surface without coordination
40-70%
Exploit market contraction
$2-3.5M
Current Safari exploit price
1B+
Users exposed (BlueHammer)
87 Months
Prison for exploit sale

The Stable System Myth

We like to think of responsible disclosure as stable infrastructure:

Researcher → Vendor → Patch → Safety 🔐

But what we're actually dealing with is a pressure system.

And right now:

  • Incentives are changing
  • Outlets are narrowing
  • Timelines are still inconsistent

That combination matters. Because if:

  • Researchers feel stuck with no resolution path
  • Vendors don't provide transparent, timely engagement
  • And external markets for exploits contract

Then "lost exploits" don't just sit quietly anymore. They build pressure until something gives.

Case Study: When Frustration Goes Public

The Windows Defender Zero-Day Leak (April 2026)

The clearest recent example is the Windows Defender zero-day cluster publicly released in April 2026 by a researcher using the alias Chaotic Eclipse.

Before April 2, 2026
Researcher privately reports vulnerability to Microsoft
April 2, 2026
Public disclosure: "I was not bluffing Microsoft and I'm doing it again" — BlueHammer exploit published
April 6, 2026
BleepingComputer reports the unpatched zero-day
April 10, 2026
BlueHammer weaponized in the wild (Huntress reporting)
April 14, 2026
Microsoft patches BlueHammer (CVE-2026-33825)
April 16-17, 2026
RedSun and UnDefend exploits published; all three actively exploited

The Pattern

Private disclosure → MSRC frustration → Public leak → Weaponization → Patch (but only for the first one)

This is not just "researcher irresponsibility." It's a pipeline failure where trust between researcher and vendor collapses, and the time between private report and public weaponization becomes dangerously short.

The Shrinking Exploit Market

Zerodium's Quiet Retreat

Zerodium, historically one of the largest exploit brokers, began significantly restricting purchases starting in 2023:

YearEventImpact
2021NSO Group sanctionsBuyer fear increases
2023iOS exploit purchasing limited"We already have enough"
2024Public acknowledgment of oversupplyDemand-side contraction
2025-2026Selective purchasing onlyImplicit pause phase

Market Contraction by the Numbers

Peak Market (2018-2022)

  • Zerodium: $30M-$50M annually
  • Crowdfense: $20M-$40M annually
  • Exodus Intelligence: $10M-$25M annually
  • Others: $20M-$50M annually

Total: ~$150M-$300M per year

Current Market (2024-2026)

  • Zerodium: $15M-$30M annually (reduced)
  • Crowdfense: $15M-$30M (quieter)
  • Exodus Intelligence: $10M-$20M (stable)
  • Others: $10M-$40M (shrinking/underground)

Total: ~$50M-$120M per year

Key Insight: The exploit market didn't collapse because vulnerabilities disappeared—it collapsed because the legitimate buyer layer broke. Legal pressure, sanctions, and reputation risk made overt exploit brokerage too dangerous.

The Price Divergence

While the market contracted, prices for premium exploits exploded—but only in the gray market. Legitimate channels couldn't keep up.

Browser Exploit Pricing (2020 vs 2026)

Channel2020-20212024-2026Change
Pwn2Own Contest$100K$75K-$150K+50%
Chrome VRP~$50KUp to $250K+400%
Apple Bounty$250K max$2M+ (with bonuses)+700%
Gray Market (Crowdfense)~$500K-$1M$2M-$3.5M+300%
The Gap: Even after Apple and Google raised their bounties dramatically, the spread between a $60K-$250K legitimate payout and a $2M-$3.5M broker valuation is too large to ignore. That gap is where the pressure builds.

The Frustration → Alternative Path Pipeline

While direct "vendor dismissed me, so I sold it to Zerodium" cases are rare in public (exploit sales are private), the broader pipeline is well-documented:

Documented Pattern

  1. Researcher privately reports issue
  2. Vendor dismisses, delays, or mishandles the report
  3. Researcher loses trust in coordinated disclosure
  4. Researcher moves to alternative path:
    • Public disclosure / PoC release (BlueHammer)
    • Private sale / broker inquiry (rarely documented)
    • Non-vendor monetization (contests, direct contracts)

Why Direct Sales Are Invisible

The scarcity of public "dismissal → sale" cases is explainable:

  • Exploit sales are confidential — Brokers advertise buying "original and previously unreported zero-day research," but transactions are private
  • Public admission creates legal risk — Openly saying you sold an unpatched exploit invites scrutiny from vendors, law enforcement, and future employers
  • Public disclosure is better leverage — If the goal is to pressure the vendor or maintain reputation, a blog post is more visible than a private sale
The Inference: The public record likely understates how often vendor dismissal leads to private sales. The most dangerous outcomes may be the least documented.

Project Zero: Pressure Without Resolution

Google Project Zero's 90-day disclosure deadline has been one of the most important forcing functions in vulnerability disclosure. It improved vendor response times dramatically—but it also created new failure modes.

What Improved

  • Median patch times decreased from ~120-200 days (pre-2014) to ~30-60 days (2020s) for top vendors
  • Industry-wide accountability and transparency
  • Forced prioritization of high-severity bugs

What Didn't Improve

  • Vendor triage quality
  • Researcher trust
  • Handling of disputed findings

New Risks Introduced

  • Public disclosure before safe patch — If vendor fails to fix in 90 days, vulnerability becomes public while users are still unprotected
  • Rushed patches — Some vulnerabilities require architectural changes; 90 days may be too short for safe remediation
  • Increased adversarial dynamics — Vendors may stall until deadline, then rush patch at last minute
Critical Insight: Project Zero solved the "vendor ignoring bugs forever" problem—but replaced it with a "deadline pressure system" that can still fail under complexity, disagreement, or friction. It ensures issues don't stay hidden forever, but it doesn't guarantee fair vendor treatment or researcher satisfaction.

Where the Exploits Actually Go

When vendors fail and legitimate markets shrink, who is actually acquiring exploits?

Nation-states remain the dominant high-end buyers—but the acquisition pipeline has evolved from broker-centric to more fragmented, opaque, and sometimes direct channels.

The Pipeline Evolution

PhaseModelCharacteristics
Pre-2021Broker-heavyZerodium, NSO pipeline; semi-legitimate gray market
2021-2023Sanctions disruptNSO blacklisted; Pegasus revelations; legal scrutiny spikes
2023-2026Fragmented, hybridDirect contractors, private firms, underground markets, more covert

Evidence of Ongoing Acquisition

1. Active Exploitation Reports

Google TAG, Apple, and Microsoft regularly report zero-days used in targeted attacks—often patched after exploitation. Someone is acquiring these exploits before vendors fix them.

2. Continued High Pricing

Crowdfense still lists Chrome/Safari chains at $2M-$3.5M. Demand is strong; buyers are willing to pay.

3. Criminal Case: L3Harris / Russian Broker (2025-2026)

Former executive Peter Williams pleaded guilty and was sentenced to 87 months in prison for selling stolen cyber-exploit components to a Russian broker for $1.3M in cryptocurrency. Exploit acquisition pipelines are still active—even under legal scrutiny.

The Hidden Market Problem: The visible market shrinks, but the invisible market may grow. We can observe vendor patch reports and public leaks, but we cannot observe most exploit sales, direct government contracts, or private researcher deals. The decline of the visible exploit market does not reduce risk—it hides it.

The Legal Squeeze

The legal landscape shifted in two opposite directions between 2020-2026:

CFAA Got Narrower (Good for Researchers)

After Van Buren v. United States (2021), the Supreme Court rejected expansive CFAA interpretations. DOJ later updated charging policy, limiting aggressive theories around terms-of-service violations.

Export Controls Got Broader (Bad for Exploit Sales)

Cases like Project Raven (2021) and Peter Williams (2025-2026) show that selling exploit capabilities—especially when tied to stolen IP, foreign governments, or restricted brokers—can lead to:

  • Deferred prosecution agreements
  • Multi-million-dollar penalties
  • Asset forfeiture (cryptocurrency, house, luxury goods)
  • Prison (87 months in Williams case)
The Modern Rule: Exploit sales become legally dangerous when they involve stolen IP, unauthorized access, foreign-government/offensive cyber services, export-controlled activity, sanctioned parties, or deceptive conduct. The paths outside coordinated disclosure are now less predictable and more dangerous.

The Fragmented Ecosystem

As structured markets shrink and vendor trust declines, disclosure becomes more fragmented, less transparent, and more strategic.

Emerging Alternative Paths

1. Direct-to-Government / Contractor Relationships

Instead of Researcher → Broker → Government, we now see Researcher → Private firm → Government. More money still exists, but access is closed, relationship-driven, and less visible.

2. Underground / Invite-Only Markets

As visible brokers shrink, underground markets have become more selective with invite-only structures, crypto payments, and escrow systems. The market didn't disappear—it became harder to observe.

3. Public Disclosure as Leverage

Researchers increasingly use partial details, PoCs, or blog posts to create pressure on vendors, establish credibility, and signal to buyers/recruiters. Publication is no longer just disclosure—it's also marketing and leverage.

4. Subscription Intelligence Platforms

Instead of selling a single exploit, researchers contribute vulnerabilities to platforms that sell intelligence feeds and early warnings. Lower legal risk, recurring revenue, broader customer base—but lower payout per vulnerability.

5. Crypto-Based Transactions

Cryptocurrency enables pseudonymous transactions and cross-border payments, reducing banking visibility and compliance friction. The L3Harris case involved crypto payments; underground markets are often crypto-based.

PathTransparencyPayoutRisk
Bug bountyHighLow–MediumLow
BrokerMediumHighMedium
Direct gov/contractorLowHighHigh
Underground marketVery lowHighVery high
Public disclosureHighIndirectMedium
Subscription intelMediumMediumLow–Medium
Structural Change: The vulnerability disclosure ecosystem is no longer a pipeline—it's a network of competing pathways, each with different incentives, risks, and visibility. When traditional disclosure fails, vulnerabilities don't disappear—they migrate across a fragmented ecosystem of alternative paths.

The Transparency Gap

Most major vendors do not publish meaningful public transparency about their vulnerability triage queues. We can see outputs (payouts, valid bugs, advisories) but not the queue dynamics that determine whether researchers feel heard, delayed, dismissed, or pushed elsewhere.

What Vendors Publish

  • Total payouts
  • Number of rewarded researchers
  • Sometimes counts of valid findings
  • Public CVE/advisory feeds after resolution

What Vendors Don't Publish

  • Average or median time to first human response
  • Average or median time to triage decision
  • Backlog size
  • Share of reports marked: valid, invalid, duplicate, informational/won't fix
  • Percentage of valid reports that led to patch vs. accepted risk
Why This Matters: In an opaque system, frustration is more likely because reporters lack context for delay, dismissal, or silence. Low triage transparency likely increases researcher frustration and distrust, which can in turn increase the appeal of public disclosure, third-party escalation, or alternative monetization paths.

HackerOne and Bugcrowd expose the richest queue metrics, but primarily to customers inside their platforms rather than to the public. Google, Microsoft, and Apple publish stronger data on payouts and valid bugs than on queue health or rejection-path breakdowns.

The public can see that vulnerabilities are found and sometimes fixed, but cannot clearly see how many reports are delayed, deprioritized, marked informational, or left to age in the queue.

The Real Question

This isn't about defending leaks or unsafe disclosure. It's about recognizing the ecosystem dynamics that make them more likely.

We're dealing with a pressure system where:

  • Researchers find valid vulnerabilities
  • Vendors provide inconsistent, opaque triage
  • Exploit brokers have contracted 40-70%
  • Legal risks have increased for alternative paths
  • Nation-state demand remains constant but less visible
  • Transparency about queue health is minimal

When researchers end up with:

  • Valid findings
  • No response or dismissive response
  • No legal outlet
  • And no good options

...the exploits don't stay lost. They build pressure until something gives.

So the real question is: How do we redesign the system so researchers don't end up in that position? How do we create enough release valves—transparent triage, fair payouts, timely responses, clear communication—that the pressure doesn't build to the point where leaks, sales, or weaponization become the rational choice?

Because right now, the system is optimized for outputs (patches, advisories, bounty totals) but not for trust (queue transparency, researcher experience, coordination quality).

And when trust breaks, exploits don't disappear. They migrate to the highest bidder with the least visibility.

The disappearance of brokers like Zerodium from public visibility does not mean exploits stopped being sold—it means they stopped being sold where we can see them.