AI

Zero-Days Aren’t Getting Cheap. They’re Getting More Expensive.

Cybersecurity price tags showing zero-day exploit costs in the millions, dark atmospheric editorial image
Cybersecurity price tags showing zero-day exploit costs in the millions, dark atmospheric editorial image

Substack/Medium draft — v3
Status: v3 — date corrected (mid-2026), double-hyphens replaced throughout, report periods cited explicitly

There’s a story that gets told about zero-day exploits: that they’re democratizing, that the market is flooding, that sophisticated attacks are becoming accessible to smaller players. It’s a compelling narrative. It’s also backwards.

The data points in one direction. The zero-day market isn’t softening. It’s escalating.

The Actual Price Trend

iOS exploit prices have hit all-time highs: $5 to $7 million per exploit, according to Crowdfense’s published acquisition pricing (source: securityweek.com/company-offering-30-million-for-android-ios-browser-zero-day-exploits/). That’s not a temporary spike. Deepstrike’s 2025 zero-day statistics analysis estimates annual price inflation for top-tier exploits at roughly 44% per year (source: deepstrike.io/blog/zero-day-exploit-statistics-2025).

The organizations paying these prices aren’t shopping a buyer’s market. They’re running structured acquisition programs with long-term budgets. Crowdfense alone has committed $30 million to a single vulnerability acquisition program: one broker, one program, one budget cycle.

The Market Structure Problem

The bug bounty economy (the civilian alternative where researchers disclose vulnerabilities to vendors in exchange for payment) is larger than commonly assumed. HackerOne paid out $81 million to researchers in the year ending mid-2025 (source: bleepingcomputer.com/news/security/hackerone-paid-81-million-in-bug-bounties-over-the-past-year/). Google’s own bug bounty program paid approximately $12 million in 2024.

That’s a real market. It’s also a market that can’t compete on the individual transaction that matters most.

When a single iOS exploit is worth $5 to $7 million to an acquisition program, no bug bounty table (Google’s or anyone else’s) can match that number for the specific researcher who found it. The $81 million HackerOne total represents thousands of researchers and thousands of disclosures across hundreds of companies. The exploit acquisition market represents a handful of researchers, a handful of findings, and per-transaction prices that dwarf anything the disclosure economy offers.

The result is structural, not conspiratorial. Researchers with the most valuable and novel findings have a financial incentive to go straight to acquisition programs rather than disclose. The concentration of demand at the premium end pulls supply away from the disclosure market, not toward it.

The Volume Picture

Google’s Threat Intelligence Group (GTIG) documented 90 confirmed zero-day exploits used in active attacks in their 2025 review, published March 2026 (source: cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review). That figure is meaningful but not a record: the 2023 count was 100, the highest on record; 2024 came in at 78. The 2025 figure of 90 represents a recovery toward elevated levels after the prior year’s dip.

What the volume data does support: zero-days in active use are a sustained, high-frequency phenomenon, not rare emergency events. 90 confirmed exploits in 12 months is roughly 7 to 8 per month, across the threat landscape, every month.

What the Narrative Gets Wrong

The “zero-days are getting cheap” story points to real signals: more security researchers, better tooling, exploit broker networks with broader reach. These things are true, and they’ve expanded the supply of lower-tier vulnerabilities.

They’ve done nothing to reduce demand for high-value targets. More connected devices means more attack surface, which means more operational value for a reliable exploit against a hardened system. The supply expansion in the mid-market hasn’t touched the pricing dynamics at the top.

The market isn’t democratizing. It’s bifurcating: a growing mid-market of commodity vulnerabilities, and a premium tier with sustained price appreciation that the disclosure economy can’t compete with.

The Security Implication

If you’re doing threat modeling under the assumption that sophisticated exploits are out of reach for most threat actors, the price data suggests you should be more specific about which threat actors you mean.

$5 to $7 million for a single iOS exploit is out of reach for most actors. It’s not out of reach for nation-states, intelligence agencies, or well-capitalized criminal organizations with specific, high-value targeting requirements. The organizations paying acquisition-program prices are selecting for impact against hardened targets. They’re paying precisely because those targets are worth it to them.

The threat isn’t that zero-days are affordable. It’s that the actors who can afford the best ones have very specific uses in mind.

Sources

– Crowdfense $30M acquisition program and iOS $5 to $7M pricing: securityweek.com/company-offering-30-million-for-android-ios-browser-zero-day-exploits/
– HackerOne $81M payout (year ending mid-2025): bleepingcomputer.com/news/security/hackerone-paid-81-million-in-bug-bounties-over-the-past-year/
– GTIG 2025 zero-day count (90), report published March 2026: cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review
– 44% annual price inflation estimate: deepstrike.io/blog/zero-day-exploit-statistics-2025
– Prices and figures current as of mid-2026. Verify current pricing through published broker disclosures before citing in formal risk assessments.

Chris Meredith writes about AI, technology, and what it actually means for real people. Follow along on Substack: monkeyattack.substack.com

Leave a Reply

Your email address will not be published. Required fields are marked *