Priced Out of Their Own Defense: The Global Race to Corner the Zero-Day Market
For decades, the United States operated under a quiet assumption: that its intelligence community and defense establishment would, by default, be the most capable buyers in any market for offensive cyber tools. That assumption is no longer operationally valid. A maturing, increasingly sophisticated global marketplace for undisclosed software vulnerabilities — commonly known as zero-days — has inverted the traditional power dynamic, placing state adversaries and organized criminal syndicates in direct competition with American agencies for the same finite pool of exploitable flaws.
The consequences for national security are difficult to overstate. When a foreign buyer acquires exclusive access to a critical vulnerability in widely deployed enterprise software, every American organization running that software becomes a potential target — without any awareness that the threat exists.
The Market Structure No One Officially Acknowledges
The zero-day ecosystem operates across several distinct tiers. At the highest end sits a small number of commercial brokers — firms that serve as intermediaries between independent vulnerability researchers and government clients. These entities operate legally in many jurisdictions, marketing their services under the banner of "offensive security solutions" or "sovereign intelligence capabilities." Their client lists are not published. Their contracts are not disclosed. But their pricing structures have become increasingly legible to analysts tracking procurement signals and researcher compensation trends.
Premium zero-days targeting mobile operating systems — particularly those enabling remote code execution without user interaction — have commanded prices ranging from $1.5 million to over $2.5 million in recent years, according to published broker rate cards and researcher community disclosures. Vulnerabilities affecting enterprise network infrastructure, industrial control systems, and satellite communications platforms occupy a similarly elevated tier. Below that sits a broader secondary market of partially weaponized exploits, proof-of-concept code, and vulnerability intelligence subscriptions accessible to a wider range of buyers.
The critical variable is exclusivity. Unlike traditional defense procurement, the zero-day market allows buyers to pay a premium specifically to prevent rivals from acquiring the same capability. A foreign intelligence service that secures exclusive rights to a critical vulnerability effectively removes that weapon from the American arsenal — not by stealing it, but by purchasing it first.
Who Is Buying, and at What Price
Open-source intelligence, court filings, and researcher testimony have collectively illuminated a buyer landscape far more diverse than the U.S. government's own procurement activity. Russia's Federal Security Service and its military intelligence directorate have demonstrated sustained investment in commercial vulnerability acquisition, supplementing their domestic offensive research programs with externally sourced capabilities. Chinese state-affiliated actors have pursued a parallel but structurally distinct approach: cultivating long-term relationships with domestic and diaspora researchers while simultaneously engaging commercial brokers operating in jurisdictions beyond American regulatory reach.
Gulf state purchasers present a different profile. Several have made well-documented investments in commercial spyware platforms — most notably the NSO Group's Pegasus system — that are themselves built on proprietary zero-day stockpiles. These acquisitions effectively transfer offensive cyber capability to governments with limited indigenous technical capacity, extending the reach of the zero-day market into geopolitical contexts that U.S. counterintelligence frameworks were not designed to anticipate.
Criminal organizations occupy the lower tiers of this market but should not be dismissed. Ransomware syndicates operating out of Russia and Eastern Europe have demonstrated the financial capacity to acquire or independently develop zero-days targeting enterprise environments. The line between state-tolerated criminal actors and intelligence proxies in this space is frequently indistinct by design.
Where America's Disclosure Framework Falls Short
The United States government manages its relationship with the zero-day market through a policy mechanism known as the Vulnerabilities Equities Process, or VEP. Established during the Obama administration and formalized under executive policy in 2017, the VEP is designed to ensure that when government agencies discover or acquire zero-day vulnerabilities, a structured interagency review determines whether those vulnerabilities should be disclosed to vendors for patching or retained for offensive use.
The framework has genuine merits. It imposes institutional discipline on a process that, left unmanaged, could result in government agencies indefinitely stockpiling vulnerabilities that leave American networks exposed. But the VEP was architected around a specific assumption: that the government is the primary acquirer of significant zero-days and therefore the primary decision-maker about their fate.
That assumption has eroded. When a foreign intelligence service purchases a vulnerability exclusively through a commercial broker, the VEP has no mechanism to compel disclosure. The vulnerability exists in an adversary's arsenal — unknown to the vendor, unknown to American defenders, and entirely outside the reach of domestic policy frameworks. The patch is never written. The exposure persists indefinitely.
Furthermore, the federal government's own acquisition budgets have not kept pace with market inflation. Agencies operating under congressional appropriations cycles and procurement regulations cannot move with the speed or financial flexibility of a foreign sovereign wealth fund or a well-capitalized intelligence service operating outside public accountability structures.
The Strategic Calculus of Stockpiling
For adversary states, the acquisition of zero-days serves purposes beyond immediate operational deployment. A stockpile of undisclosed vulnerabilities represents a form of strategic reserve — a latent offensive capability that can be held in readiness for escalatory scenarios, deployed against specific high-value targets during geopolitical crises, or used as leverage in coercive diplomacy. The 2017 leak of NSA-developed exploits, which were subsequently weaponized in the WannaCry and NotPetya attacks, demonstrated that stockpiled vulnerabilities carry their own risk of catastrophic exposure. But that lesson has not deterred accumulation — it has merely incentivized more rigorous operational security around stockpile management.
From a threat mapping perspective, the zero-day market functions as an early warning indicator for adversary offensive cyber intent. Shifts in purchasing patterns, new entrants to the broker ecosystem, and changes in the vulnerability categories commanding premium prices all carry intelligence value for analysts tracking the evolution of state-sponsored cyber programs.
Recalibrating the American Response
Addressing the structural disadvantage the United States faces in this market requires action on multiple fronts simultaneously. Legislative frameworks governing commercial vulnerability brokers operating within U.S. jurisdiction require modernization. Export control regimes — including the Wassenaar Arrangement's provisions on intrusion software — need enforcement mechanisms capable of keeping pace with a market that transacts across jurisdictions in days.
Equally important is investment in the domestic researcher community. Independent security researchers who discover significant vulnerabilities represent a strategic asset. When federal bug bounty programs and coordinated disclosure incentives fail to compete with commercial broker payouts, those researchers — and the vulnerabilities they find — migrate toward the open market. Closing that gap is not merely a procurement question. It is a national security priority that belongs on the same strategic map as any kinetic capability competition.
The zero-day market will not disappear. But the United States can choose whether it enters that market as a competitive, strategically coherent participant — or continues to cede ground to adversaries who recognized its importance long before Washington's policy frameworks caught up.