Skip to content
← Back to Briefings
cybersecurity

Zero-Day Market Dynamics: Broker Pricing, Government Procurement, and Disclosure Norms

Zero-day exploit prices have reached historic highs in 2026, driven by platform hardening at major vendors and intensifying demand from government intelligence buyers, reshaping the global security posture of widely-used software.

Asymmetry Lenses Applied

Capability-Intent
Coalition Mapping
Coordination-Defection Mapping

Alliances · Coalitions · Cartels

Counterfactual
Counterfactual Construction

Crisis Analysis · Causal Claims

Key Takeaway

Government stockpiling of zero-days creates a structural lag between vulnerability discovery and public disclosure that keeps widely-used software exposed for years, a dynamic that AI-assisted exploit development is now accelerating rather than resolving.

Executive Summary

Zero-day exploit prices have reached historic highs in 2026, driven by platform hardening at major vendors and intensifying demand from government intelligence buyers, reshaping the global security posture of widely-used software. Crowdfense now offers up to $9 million for zero-click full-chain smartphone exploits, a figure that was unthinkable five years ago, while the Russian firm Operation Zero offered up to $20 million for similar capabilities before US Treasury and State Department sanctions struck the firm in February 2026. The procurement process is almost entirely opaque: governments acquire exploits through subscription catalogs, per-exploit contracts, and access-as-a-service arrangements with no public tender or independent audit. That opacity translates directly into delayed disclosure, since stockpiled vulnerabilities cannot be patched, and into accelerated downstream risk when exploits eventually leak.

  • Security and risk officers at firms running Windows, iOS-dependent workflows, or enterprise chat platforms: Treat unpatched n-day vulnerabilities as functionally equivalent to zero-days, given documented government stockpiling lifecycles that routinely exceed six years.
  • Policy and regulatory stakeholders: The February 2026 US sanctions on Operation Zero establish a new enforcement model; tracking OFAC and State Department actions against additional brokers is now a leading indicator of Western governments' willingness to constrain the market.
  • Technology vendors (Apple, Google, Microsoft): Platform hardening is working as a price signal but not as a deterrent; rising prices confirm demand, not reduced capability.

Government stockpiling of zero-days creates a structural lag between vulnerability discovery and public disclosure that keeps widely-used software exposed for years, a dynamic that AI-assisted exploit development is now accelerating rather than resolving.

Key Findings

  • Zero-click full-chain exploit prices for mobile platforms have risen by a factor of three-to-six since 2019, driven by platform hardening rather than reduced demand.
  • AI-assisted vulnerability discovery is accelerating the rate at which zero-days are found, compressing the window between discovery and exploitation to negative territory on average.
  • The US government is the documented largest single procurer of offensive cyber capabilities, with China running a structurally different but equally active parallel acquisition model.
  • Government stockpiling norms delay public disclosure for an average of 6.9 years per vulnerability, materially extending enterprise exposure windows.
  • The February 2026 US sanctions on Operation Zero represent the first use of financial sanctions to directly target a gray-market exploit broker, establishing a new enforcement precedent that constrains but does not close the market.

The Price Escalation Mechanism And What It Signals

Broker price lists are not arbitrary; they are derived from resale margins, which in turn reflect what government clients will pay. Crowdfense, a UAE-based acquisition hub, anchors the visible Western gray market. Its 2024 program, documented by SecurityWeek, moved ceiling prices from $3 million (2019) to $9 million for zero-click full-chain exploits, a move that reflects three compounding factors: tightened sandboxing in iOS 17 and Android 14, Apple's Lockdown Mode reducing the attack surface for high-value targets, and sustained intelligence agency demand that has not diminished as targets hardened.

The white market, led by Trend Micro's Zero Day Initiative, offers a ceiling of roughly $150,000 per vulnerability, a fraction of gray-market rates. According to ForkLog's market review, ZDI's day-to-day catalogue pays $500 to $150,000. This price gap functions as a structural incentive: a researcher who can reliably produce iOS kernel exploits faces a financial choice between a six-figure bug bounty and a seven-figure broker payout. The gap guarantees that the most capable researchers are unlikely to route their most valuable work through vendor-disclosure channels.

What is not being reported: the gray-market broker price list is the visible surface of a deeper, fully classified tier. Both Zerodium and Crowdfense sell exclusively to government clients, and those clients resell or deploy on terms that are never publicly documented. The $20 million figure from Operation Zero may reflect what end-buyer governments in non-Western markets are prepared to pay, not what Western intelligence services offer through classified channels. Classified US government acquisition prices, referenced in the Atlantic Council's supply chain report through background interviews with former IC officials, are absent from any public record.

Government Procurement: Structure, Opacity, And Strategic Divergence

Governments acquire zero-day capabilities through three overlapping models. The Atlantic Council's 2025 analysis of the offensive cyber supply chain identifies the dominant US models as per-exploit contracts (typically for high-accuracy, exquisite capabilities), subscription catalog access (flat fees for year-long access to a firm's full inventory), and Access-as-a-Service arrangements for less sophisticated agency clients, where the contractor guarantees operational maintenance over a defined period.

None of these models requires public competitive tender, and none has a mandatory disclosure linkage to any national vulnerability disclosure framework. The NSA operates the Vulnerabilities Equities Process (VEP), established to weigh the intelligence value of a held vulnerability against the security cost of non-disclosure. However, the VEP's deliberations are classified, its outcomes are secret, and independent researchers including those at the Atlantic Council have noted that the process "overly indexes on high-cost, exquisite zero-day exploit procurements" rather than applying consistent disclosure standards.

China's model differs in a structurally significant way. According to the Atlantic Council, the Chinese Communist Party outsources operations to a decentralized network of contractors, shortens procurement cycles, and extends exploit operational life by supplementing original zero-days with n-day exploitation after the underlying vulnerability is patched but before enterprise deployment has caught up. This approach is less exquisite but more durable, and it benefits from China's National Intelligence Law, which compels all domestic entities to cooperate with state intelligence requirements. Bright Defense's 2026 statistics compilation attributes the 2025 BRICKSTORM campaign, a PRC-nexus operation, with targeting technology company source code directly, creating a self-reinforcing cycle: stolen source code enables faster vulnerability discovery, reducing the cost of finding the next zero-day.

Capability without confirmed intent: Russia's Operation Zero, before its February 2026 sanctioning, publicly advertised $20 million ceilings that exceeded any Western broker offer. This capability signal does not confirm that Russian intelligence agencies were actually paying those prices at scale. The offer may have functioned as a market-entry bid to attract researchers who would otherwise route work to Western buyers, rather than a reflection of sustained acquisition budgets.

The geopolitical and financial dimensions of this procurement market are mutually reinforcing. Government spending on zero-days translates directly into financial incentives that draw researchers away from vendor disclosure channels, which in turn constrains the speed of vendor patching, which in turn extends the exposure window for enterprises in every sector. The cybersecurity cost, measured as the delta between the date of government discovery and the date a vendor can ship a patch, is borne entirely by the private sector and by civilian users.

How Stockpiling Norms Extend Enterprise Exposure

The RAND Corporation's study found a 6.9-year average lifespan for stockpiled zero-day exploits from initial discovery to either public disclosure or natural obsolescence. That figure has not been meaningfully revised downward despite the proliferation of bug bounty programs. The EUHybNet consortium's 2024 review of RAND's methodology found that the low annual collision rate (5.7% per year) means an adversary holding a zero-day is unlikely to face the scenario where a vendor patches the vulnerability because a separate researcher found it independently. Stockpiling is therefore not irrational; it is a calculated bet that pays off in the majority of cases.

The structural consequence for enterprise security is direct: every day a government holds a zero-day in its stockpile without disclosure, the patch vendor cannot issue, and every enterprise running the affected software remains exposed. CrowdStrike's August 2026 Patch Tuesday coverage documented 415 CVEs addressed in a single monthly cycle, including one exploited zero-day, an indication of the volume of vulnerabilities flowing through the system. That monthly volume makes it harder, not easier, for enterprise patch teams to prioritize, and the subset that are government-held and undisclosed do not appear on the priority list at all.

The AI dimension tightens the timeline further. Anthropic's multiagent systems research, published in 2026, found that coordinated AI agent swarms were able to discover and cross-validate vulnerabilities in open-source software at a rate that exceeded single-agent approaches, with agents self-specializing in particular vulnerability classes. Google GTIG, as cited in Bright Defense's 2026 compilation, expects AI to accelerate both offensive discovery and defensive response in 2026. The net effect is that the discovery rate is rising, which increases the probability that any given stockpiled vulnerability will be independently rediscovered and exploited by a third party before the holding government chooses to disclose.

The broader systemic implications include a compounding risk for critical infrastructure operators. FortiGuard Labs documented in its 2025 Outbreak Alert annual report that exploitation attempts against industrial control systems and enterprise platforms are measured in trillions of attempts annually, with active campaigns targeting Siemens S7 PLCs, Cisco ASA/FTD firewalls, and Splunk Enterprise (including CVE-2026-20253, a critical authentication bypass confirmed in the US Known Exploited Vulnerabilities catalog as of June 2026). Each of these attack surfaces is a candidate for zero-day exploitation, and each may already be subject to classified stockpiling by one or more governments.

Key Assumptions

AssumptionSupporting EvidenceFalsifying EvidenceImpact if WrongMonitoring Metric
Published broker price lists reflect actual transaction prices, not marketing anchorsMultiple independent observers (SecurityWeek, TechCrunch, ForkLog) treat published lists as market signals; no researcher has publicly argued they are systematically inflatedEvidence that governments routinely pay far below list price or that list prices are rarely transactedAssessment of price escalation trend weakens; the market may be less valuable than characterizedZerodium or Crowdfense published pricelist updates (semi-annual)
Government stockpiling is the primary cause of delayed vendor disclosure, rather than simple researcher inactionRAND lifespan data and VEP opacity are consistent with systematic non-disclosure; Atlantic Council documents active procurement modelsIf most long-lived zero-days were held by non-government actors or reflected researcher inactivity rather than active suppression, the disclosure delay would have different remediation pathwaysThe policy lever shifts from VEP reform to researcher incentive reform; intervention design changes materiallyNSA Vulnerabilities Equities Process annual report (declassified summary)
AI-assisted exploit development is net-negative for defensive timelines on the current trajectoryGoogle GTIG assessment; Anthropic multiagent research; negative Mean Time to Exploit measurement (prior organizational finding)If defensive AI adoption outpaces offensive use and patch generation accelerates faster than discovery, the exposure window narrowsAssessment that AI compounds stockpiling risk would require revision; the urgency of policy intervention decreasesCISA Known Exploited Vulnerabilities catalog monthly growth rate (NVD/CISA)
Sanctions on Operation Zero will constrain but not eliminate Russian gray-market exploit brokerageFebruary 2026 OFAC and State Department action; ForkLog documentation of sanctions mechanismReconstitution of broker activity under new corporate structures or shift to fully cryptocurrency-denominated transactions within 12 monthsUS sanctions as enforcement model loses deterrence value; policy recommendation to replicate the model weakensOFAC Specially Designated Nationals list additions in the cyber broker category

Counterarguments

  1. The price escalation argument may conflate difficulty with danger. The case that rising broker prices signal worsening systemic risk assumes that expensive exploits are deployed more broadly or more recklessly than cheap ones. The opposite is plausible: a $9 million iOS exploit is a single-use asset that a government agency will deploy surgically against a very small number of high-value targets, not broadly against civilian infrastructure. If surgical use is the norm for high-price exploits, the systemic risk to average enterprise users may be overstated, and the policy priority should focus on cheaper commodity exploits that cascade to criminal use (as Bright Defense's 2026 data documents occurs within roughly two years of initial government use), not on the top tier of the market.

  2. The RAND 6.9-year lifespan figure may systematically undercount voluntary disclosures. The RAND methodology, acknowledged by EUHybNet in its 2024 review, can only observe zero-days that became public knowledge. Vulnerabilities disclosed through the VEP or equivalent national processes before exploitation became public would not appear in the dataset. If governments are disclosing a material share of held vulnerabilities quietly to vendors without public announcement, the actual exposure window could be shorter than 6.9 years. The evidence for or against this is, by definition, classified, and this assessment cannot resolve it.

  3. The Atlantic Council's characterization of US procurement as "overly indexed on exquisite zero-day exploits" may reflect a selection bias toward visible programs. Classified NSA and Cyber Command capabilities are not observable by Atlantic Council researchers, whose sourcing relies on background interviews with former officials. The visible procurement market may be the less sensitive, more commercially-oriented portion of actual government acquisition, meaning total US government zero-day investment is likely higher than what the supply chain report captures, and the market discipline assumptions may not hold for the classified tier.

Indicators To Watch

The table below identifies observable signals that would confirm or disconfirm the key assessments in this analysis. Readers tracking the offensive cyber market should monitor these against the warning thresholds quarterly.

IndicatorCurrent StateWarning ThresholdTime Horizon
Crowdfense or Zerodium published pricelist revisionCrowdfense ceiling: $9M (zero-click); Zerodium iOS ceiling: ~$2.5MAny broker ceiling exceeds $15M, or a new entrant publishes a list above current leaders6-12 months
CISA Known Exploited Vulnerabilities catalog growth rateApproximately 415 CVEs patched in August 2026 Patch Tuesday alone; one confirmed zero-day exploitedMore than 3 confirmed zero-days in a single monthly Patch Tuesday cycle, or a KEV entry for a 5+ year old vulnerability (indicating long-held stockpile release)30-90 days
OFAC / State Department sanctions actions against additional exploit brokersOne action completed (Operation Zero, February 2026)Second sanctioning of a non-Russian broker, or sanctioning of a broker registered in a Five Eyes-allied jurisdiction12-18 months
NSA Vulnerabilities Equities Process annual disclosure summaryClassified; no public figure availablePublication of any declassified summary showing disclosure rate below 50% of reviewed vulnerabilities12 months
Commercial surveillance vendor CVE attribution rateSpyware vendors responsible for 75% of zero-days targeting Google/Android per Google Project ZeroAttribution rate rises above 85% or drops below 50% (the latter would indicate a shift back to direct state actor exploitation)6-12 months
AI-generated exploit proof-of-concept emergence in public repositoriesIsolated academic demonstrations; no confirmed criminal deployment of AI-generated full-chain exploitsFirst confirmed criminal ransomware deployment traceable to AI-generated exploit code, per CrowdStrike or Mandiant attribution3-9 months

Near-term watch list: (1) CrowdStrike 2026 Technology Threat Landscape Report follow-on (Q3 2026), specifically its quantification of AI-assisted exploit development timelines, will be the first major industry benchmark for the offensive AI acceleration claim; (2) CISA's next joint cybersecurity advisory on Iranian-affiliated PLC targeting (expected Q4 2026), which will indicate whether OT/ICS zero-days are entering the documented KEV catalog at an accelerated pace; (3) Any OFAC action under the Protecting American framework against a non-Russian broker in Q4 2026 or Q1 2027 would confirm that the February 2026 Operation Zero sanctions represent a repeatable enforcement model rather than a one-off geopolitical response.

Decision Relevance

Scenario A (~55%): Gradual price escalation with no major reform, AI discovery rate increasing but offset by defensive tooling. The gray market continues to expand, broker prices reach $10-12 million ceilings for top-tier exploits by 2027, and governments maintain stockpiling norms with minimal VEP reform pressure. If your organization runs critical infrastructure or processes high-value intelligence-relevant data (financial, defense, health), assume that your most sensitive platforms have been or will be subject to government-held zero-day exposure. Prioritize network segmentation and behavioral detection over perimeter patching as your primary control; patching cannot address what vendors cannot yet disclose. If you lack direct critical-infrastructure exposure, treat the KEV catalog as your primary prioritization filter and maintain a 72-hour patching SLA for catalog entries.

Scenario B (~30%): A major stockpile leak event, comparable to Shadow Brokers, forces emergency policy response and accelerates VEP reform. Medium-sized state or non-state actor gains access to a government zero-day stockpile and releases weaponized exploits into the public domain. The Shadow Brokers 2017 precedent, which produced EternalBlue and contributed to WannaCry, establishes the damage pathway. If your infrastructure includes Windows Server, Cisco ASA, or widely deployed enterprise software, maintain off-network backup capability and ensure your incident response retainer explicitly covers nation-state tooling scenarios. If you are a technology vendor, accelerate threat modeling against leaked government offensive tooling, as Mandiant and CISA advisories will lag the exploit's actual market penetration by days to weeks.

Scenario C (~15%): Multilateral regulatory action (Wassenaar Arrangement update, EU NIS2 extension) constrains the broker market materially. The Wassenaar Arrangement, which already covers "intrusion software," is updated to require broker registration and government-client disclosure obligations, reducing the opacity of the acquisition pipeline. This is unlikely in the near term given the documented inconsistency in Wassenaar implementation across member states, as noted by ForkLog's review. If you have policy exposure and are tracking this scenario, the leading signal is a joint US-EU statement on commercial spyware regulation, which has not yet materialized as a binding framework. If this scenario materializes, vendor patch timelines should compress within 12-18 months of regulatory implementation as researcher incentives shift back toward responsible disclosure.

Expert Integration

Expert Consensus Assessment

Researchers at the RAND Corporation, the Atlantic Council, Google Project Zero, and the EUHybNet consortium agree that government stockpiling materially delays disclosure and that broker prices have risen substantially over the past five years. There is no expert disagreement on the directional trend.

Expert Disagreement Areas

  • Disclosure rate under VEP: The Atlantic Council and independent security researchers acknowledge that the VEP's classified nature makes it impossible to determine whether voluntary disclosure is occurring at a meaningful rate; RAND's methodology cannot capture quiet disclosures.
  • AI's net effect on the defender-attacker balance: Google GTIG and IBM Security disagree on whether AI defensive tooling can close the detection gap opened by AI-assisted exploitation. IBM's breach cost data (2026) shows organizations using AI in security operations experience materially lower breach costs, suggesting defense is gaining ground; Google's assessment emphasizes persistent offensive advantage.
  • Scope of Chinese acquisition: Atlantic Council researchers and US government officials have publicly documented China's decentralized n-day model; whether China's actual zero-day investment in absolute dollar terms equals or exceeds the US is not resolvable from open sources.

Systematic-Expert Alignment

Alignment: ALIGNED

This assessment's core findings align with expert consensus on price trajectory, government procurement opacity, and stockpiling-induced disclosure delay. The assessment diverges from the most pessimistic expert framing by acknowledging the counterargument that high-price exploits are likely deployed surgically, limiting their immediate systemic risk even as their long-term leak risk remains high.

Analytical Limitations

  • No public data exists on actual transaction prices between governments and exploit brokers; all figures in this assessment derive from broker acquisition programs (what brokers pay researchers), not resale prices (what governments pay brokers), which are likely higher and entirely classified.
  • The RAND 6.9-year lifespan figure was computed from observed public disclosures and cannot account for vulnerabilities that were disclosed quietly to vendors without public documentation; the true disclosure lag may be shorter or longer than the available data suggests.
  • Attribution of exploit-market demand to specific governments is inferential; no government other than through the Vulnerabilities Equities Process publicly acknowledges its zero-day acquisition portfolio, and the US VEP summary is itself classified.
  • The AI-exploit acceleration claim rests on academic demonstrations (Anthropic multiagent research) and industry projections (Google GTIG); confirmed criminal deployment of AI-generated full-chain exploits has not yet been publicly attributed, making the timeline uncertain.
  • Operation Zero's $20 million offer may have been a market-positioning signal rather than a transacted price; the sanctions disrupted the firm before independent verification of actual transaction volumes was possible.

Sources & Evidence Base

Methodology version: 2026-08-22

Get the next analysis when it's published

Free email alerts for new briefings. No spam, unsubscribe in one click.

Source-graded evidence. Competing hypotheses. Calibrated confidence. Delivered daily.

Want to bookmark and save analyses? Create a free account →

Apply this analytical approach to your priority topics.

Source-graded evidence, competing hypotheses, and calibrated confidence, with limitations stated, not hidden.

Request a Demo

Accountability

Every Mapshock forecast is published with its confidence assessment and resolution horizon, and resolved in public against subsequent evidence.

View the public forecast record
Share

Continue Reading

defense15 min read

ASEAN Institutional Cohesion Under Regional Fragmentation: Myanmar, South China Sea, and Alliance Architecture Implications

ASEAN's twin institutional failures on Myanmar and the South China Sea Code of Conduct are now mutually reinforcing, and together they are accelerating the bloc's displacement from the center of regional security architecture.

cybersecurityAug 22, 202613 sourcesHigh Confidence14 min read