Vulnerability Markets

Exploit Brokers: The Wholesale Market for Zero-Days

Firms like Zerodium and Crowdfense pay millions for zero-day exploits, channelling offensive capabilities to governments and spyware vendors. Exploit brokers are the supply chain behind much mercenary surveillance.

Last updated October 9, 2026

Overview

Exploit brokers are intermediary firms that purchase exclusive rights to zero-day vulnerabilities from independent researchers and resell that capability — usually to government intelligence agencies and mercenary spyware vendors. They sit at the wholesale layer of the offensive market, professionalising the trade in exploitability and effectively setting the market price for unpached flaws.

Public-facing brokers like Zerodium and Crowdfense publish price charts: a remote-code-execution zero-day in iOS or Android can fetch several million dollars; full-chain zero-click exploits considerably more. These prices signal both the rarity of the capability and the defensive value of timely patching — every patched vulnerability is a broker's lost inventory.

The existence of a lucrative, legitimate grey market shapes the vulnerability ecosystem. Researchers who might responsibly disclose a flaw for a vendor bounty can instead sell exclusive rights to a broker for orders of magnitude more. This drains the defensive supply of vulnerability knowledge toward offensive use, intensifying the arms race between patch cadence and exploit deployment.

Key Points

Price-led market

Published exploit price charts (iOS/Android/Windows RCE) effectively set the commercial value of an unpatched vulnerability, guiding researcher behaviour.

Exclusive sale

Brokers typically buy exclusive rights, meaning the flaw is not reported to the vendor and remains exploitable until independently rediscovered and patched.

Government demand

End buyers are predominantly intelligence agencies and mercenary spyware vendors, linking the broker market directly to state and commercial surveillance.

Bounty gap

The spread between vendor bug bounties and broker payouts can exceed 10–50x, structurally incentivising researchers toward offensive sale.

Patch race

Because brokered flaws are not disclosed, defenders depend on vendor's own research and rediscovery — making rapid patch adoption the primary defensive lever.

Latest Intelligence

Frequently Asked Questions

Defensive Intelligence

Encrygma produces defensive intelligence only. This analysis is derived from public reporting, government advisories, and OSINT — no exploit code or attack instructions.

Sovereign Defense Solutions
Weekly Briefing

Get the Weekly Cyberwarfare Briefing

State cyber operations, AI-powered attack campaigns, and offensive cyber industry developments — delivered to your inbox every week.

Defensive intelligence only. No spam — unsubscribe anytime.