Exploit Brokers: The Wholesale Market for Zero-Days
Firms like Zerodium and Crowdfense pay millions for zero-day exploits, channelling offensive capabilities to governments and spyware vendors. Exploit brokers are the supply chain behind much mercenary surveillance.
Last updated October 9, 2026
Overview
Exploit brokers are intermediary firms that purchase exclusive rights to zero-day vulnerabilities from independent researchers and resell that capability — usually to government intelligence agencies and mercenary spyware vendors. They sit at the wholesale layer of the offensive market, professionalising the trade in exploitability and effectively setting the market price for unpached flaws.
Public-facing brokers like Zerodium and Crowdfense publish price charts: a remote-code-execution zero-day in iOS or Android can fetch several million dollars; full-chain zero-click exploits considerably more. These prices signal both the rarity of the capability and the defensive value of timely patching — every patched vulnerability is a broker's lost inventory.
The existence of a lucrative, legitimate grey market shapes the vulnerability ecosystem. Researchers who might responsibly disclose a flaw for a vendor bounty can instead sell exclusive rights to a broker for orders of magnitude more. This drains the defensive supply of vulnerability knowledge toward offensive use, intensifying the arms race between patch cadence and exploit deployment.
Key Points
Published exploit price charts (iOS/Android/Windows RCE) effectively set the commercial value of an unpatched vulnerability, guiding researcher behaviour.
Brokers typically buy exclusive rights, meaning the flaw is not reported to the vendor and remains exploitable until independently rediscovered and patched.
End buyers are predominantly intelligence agencies and mercenary spyware vendors, linking the broker market directly to state and commercial surveillance.
The spread between vendor bug bounties and broker payouts can exceed 10–50x, structurally incentivising researchers toward offensive sale.
Because brokered flaws are not disclosed, defenders depend on vendor's own research and rediscovery — making rapid patch adoption the primary defensive lever.
Latest Intelligence

Citrix Confirms Active Exploitation of NetScaler Zero-Day CVE-2026-88779

Critical Zero-Day Exploitation Surge: Fortinet and Citrix NetScaler Under Active Attack

Pwn2Own Ireland 2026 Uncovers 32 Zero-Day Vulnerabilities Amidst Surge in Critical Infrastructure Exploits

Pwn2Own 2026: 32 Zero-Day Vulnerabilities Disclosed as Global Exploitation Surge Continues

Critical FortiMail and Cisco SD-WAN Zero-Days Under Active Exploitation

Critical Zero-Day Vulnerabilities Surge: FortiMail and Citrix NetScaler Under Active Exploitation
Frequently Asked Questions
Encrygma produces defensive intelligence only. This analysis is derived from public reporting, government advisories, and OSINT — no exploit code or attack instructions.
Sovereign Defense SolutionsGet the Weekly Cyberwarfare Briefing
State cyber operations, AI-powered attack campaigns, and offensive cyber industry developments — delivered to your inbox every week.