DEF CON 4 All articles
Security Research

Show Me the Money: How Bug Bounties Are Eating the Zero-Day Black Market

DEF CON 4
Show Me the Money: How Bug Bounties Are Eating the Zero-Day Black Market

Photo: hacker cryptocurrency dark web money trading computer screen, via cdn.memes.com

There's a moment every security researcher knows well. You've been grinding for weeks — maybe months — and suddenly there it is: a clean, reliable remote code execution vulnerability in a widely deployed piece of software. Your pulse spikes. Your brain immediately starts running the math.

Do you report it? Do you sell it? And if you sell it — to whom?

That calculation used to be a lot simpler. Bug bounty programs either didn't exist or paid embarrassingly little. The gray and black markets, meanwhile, were throwing around numbers that made responsible disclosure feel almost financially irresponsible. But that math is changing, and the shift is reshaping the entire vulnerability economy in ways nobody fully predicted.

The Old Equation: Why the Underground Paid Better

Let's be blunt about how things worked — and to some extent still work. Exploit brokers like Zerodium built a business model around paying top dollar for weaponizable zero-days, with public payout tables that read like a Silicon Valley salary guide. A full iOS remote jailbreak chain? Up to $2.5 million at peak pricing. Android RCE with sandbox escape? $2.5 million as well. Chrome renderer exploits were sitting at $500K.

Compare that to what major tech companies were offering through their own programs even five years ago, and the gap was laughable. Microsoft's bounty cap for many critical categories sat at $100,000. Google's Project Zero-adjacent reward structures were generous by industry standards but still couldn't touch broker pricing for the really exotic stuff.

The incentive structure practically wrote itself. High-skill researchers with elite zero-day capability were leaving enormous money on the table by going the responsible disclosure route. The underground wasn't some shadowy myth — it was a rational economic choice for a certain class of researcher.

How HackerOne, Bugcrowd, and Friends Changed the Game

The bug bounty platform model — where companies outsource vulnerability discovery to a crowd of independent researchers under structured payout terms — has been around since the mid-2010s in its modern form. But the real inflection point came when enterprise payouts started scaling aggressively.

HackerOne now reports over $300 million paid out to researchers across its platform lifetime, with single-vulnerability payouts occasionally cracking the seven-figure mark for critical infrastructure bugs. Bugcrowd, Intigriti, and Synack have all pushed payout ceilings higher as competition for top-tier talent intensified.

More importantly, the volume of mid-range payouts has exploded. A solid web application logic flaw that might have fetched $5,000 in 2016 is now routinely paying $15,000 to $40,000 depending on scope and impact. For researchers working across multiple programs simultaneously, the math starts competing seriously with riskier alternatives.

"The platforms created a middle class of security research," said one researcher who asked to remain identified only by their handle, Vex_Null. "Before, you were either grinding CVEs for pennies or you were operating at a level where the underground was your only real option. Now there's a sustainable income tier in between."

The Vulnerability Pricing Tier List

Not all bugs are created equal, and the market — both legitimate and underground — prices them accordingly. Here's a rough breakdown of where the two markets currently compete:

Web application vulnerabilities (XSS, SQLi, SSRF, IDOR): Bug bounty programs dominate here. The underground has minimal appetite for garden-variety web bugs. Bounties range from $500 to $50,000+ depending on severity and target.

Mobile OS exploits (iOS/Android): This is where the underground still commands enormous premiums. A reliable iOS zero-click RCE chain is worth so much to nation-state buyers that no bounty program can realistically compete. Apple's Security Research Device Program and expanded payouts help at the margins, but the gap remains wide.

Enterprise software (VPNs, firewalls, EDR tools): A fascinating middle ground. Legitimate programs for vendors like Palo Alto, Fortinet, and CrowdStrike have gotten serious about payouts, but these vulns also carry massive underground value for ransomware operators and APT groups. Researchers operating here face real temptation.

Cloud infrastructure bugs: Increasingly lucrative in legitimate programs. AWS, Google Cloud, and Azure all run aggressive bounty structures, and the reputational upside of a high-profile cloud disclosure has its own career value.

The Moral Hazard Nobody Talks About

Here's the uncomfortable conversation that happens in private Discords and Signal groups but rarely makes it into polished conference talks: bug bounty programs create their own weird incentive distortions.

When a researcher discovers a critical vulnerability, the current system asks them to essentially trust that the vendor will pay fairly, won't lowball the severity rating, and won't drag out the disclosure process for months while the researcher sits on a non-disclosed finding they can't sell elsewhere. Triaging disputes — where companies downgrade severity to reduce payouts — are a persistent complaint across every major platform.

"I've had companies accept a critical finding, sit on it for four months, then come back and say it was actually medium severity," said another researcher, who goes by the handle Crucible_8. "At that point, the responsible thing and the financially rational thing are pointing in very different directions."

This tension is a known problem. HackerOne and Bugcrowd both have mediation processes, but researchers consistently describe them as slow and vendor-favorable.

What's Actually Disrupting the Underground

Interestingly, the biggest pressure on the black market might not be coming from bounty payouts at all — it's coming from legal risk and operational security failures.

The 2021 FinFisher takedowns, the Hacking Team breach that exposed customer lists, and multiple FBI operations targeting exploit brokers have made the underground riskier to participate in. Cryptocurrency tracing has complicated payments. And the expanding scope of the Computer Fraud and Abuse Act (CFAA), despite recent Supreme Court narrowing, still creates real legal exposure for researchers who wander into gray-market territory.

Combined with improving bounty economics, the risk-adjusted return of underground participation is declining — at least for researchers operating below the nation-state tier.

The Bottom Line

Bug bounties haven't killed the zero-day market. For the most exotic, weaponizable exploit chains — the kind that end up in nation-state toolkits — legitimate programs simply can't compete. That market will persist as long as governments are willing to spend intelligence budgets on offensive capability.

But for the enormous middle tier of the vulnerability economy? The calculus has genuinely shifted. Legitimate platforms have created a sustainable, lower-risk income stream that's pulling talent away from riskier channels. The underground isn't dead — but it's under real competitive pressure for the first time in its history.

For the security community, that's meaningful progress. Not a solved problem. But progress.

All Articles

Related Articles

When the Alarms Go Off: Incident Response Lessons Written in Blood (and Breach Notifications)

When the Alarms Go Off: Incident Response Lessons Written in Blood (and Breach Notifications)

Poison at the Source: A Technical Deep Dive Into How Supply Chain Attacks Are Evolving

Poison at the Source: A Technical Deep Dive Into How Supply Chain Attacks Are Evolving

Poison in the Pipeline: How Foreign Adversaries Are Turning Open Source Into a Weapon

Poison in the Pipeline: How Foreign Adversaries Are Turning Open Source Into a Weapon