← Field Notes · Industry
Zero-Days and the Market Nobody Talks About
Software flaws nobody has patched yet are worth real money, and there is a functioning market to prove it.
A zero-day is a software vulnerability the vendor does not yet know about, named for the number of days the developer has had to fix it. Until it is discovered, reported, and patched, it works against every unpatched machine running the affected software, which makes it valuable in a very literal sense: there is a real, if largely unregulated, market that prices zero-day vulnerabilities based on the software they affect, the difficulty of exploiting them reliably, and how quietly they can be used before detection.
Some of that market is entirely legitimate. Every major technology company runs a bug bounty program, paying independent researchers to find and report vulnerabilities before anyone else does, and specialized firms broker responsible disclosure between researchers and vendors as a business. These programs exist because the alternative, a researcher with no legal outlet for a serious finding, has historically pushed vulnerabilities toward buyers with fewer scruples about how they get used.
The other side of that market is less publicly documented but not exactly hidden. Firms such as Zerodium have operated publicly for years, buying working exploits for major operating systems and applications and reselling access to them, by their own public statements, to government and law enforcement clients rather than publishing them or reporting them to the affected vendor. Published price lists for exploits affecting fully updated mobile operating systems have run into the millions of dollars, a figure that says more about the value of a working zero-day than any amount of industry commentary could.
Governments are buyers in this market too, and not only as customers of commercial brokers. Intelligence and law enforcement agencies in multiple countries maintain their own vulnerability research capabilities, and the decision of whether to disclose a discovered flaw to the vendor, so it can be patched, or retain it for future use is a genuine and recurring policy debate, one the United States formalized through a process called the Vulnerabilities Equities Process. The tension is direct: every unpatched zero-day protects a capability and simultaneously endangers every other user of the affected software.
For an ordinary user, none of this market activity is directly visible, and none of it is something an antivirus product can neutralize before the fact, by definition, a zero-day exploit has no existing signature and often no established behavioral pattern to flag. It is one honest limit of the entire industry, not a specific product's failure, and it is a large part of the reason security researchers consistently argue that patching promptly, not any single detection tool, remains the single highest-leverage defense most organizations have.