For two decades, the trade in software vulnerabilities operated in a grey zone: legal in most jurisdictions, essential to intelligence agencies, lucrative for brokers, and largely invisible to the public except when an exploit leaked or a spyware scandal broke.
The grey zone is shrinking. Not because the market is disappearing — it is thriving — but because the political cost of ignoring it has finally exceeded the convenience of looking away.
Why it matters
Zero-days are the load-bearing input of both state cyber operations and the commercial spyware industry. How the market is governed determines whether vulnerabilities get patched or stockpiled, whether journalists and dissidents get targeted with impunity, and whether the software everyone runs gets safer or stays silently compromised.
It is also a rare policy area where the US government sits on both sides: the largest buyer of exploits and the regulator of their trade, which makes every rule a negotiation with itself.
How it works
The market has tiers. At the top, governments buy full exploit chains — often for iOS and Android — at prices reported in the millions of dollars, through brokers and boutique firms. Below that, commercial spyware vendors package exploits into products sold to state customers, which is where export controls now bite: the US Commerce Department's rules restrict trade in intrusion software and have put several spyware vendors on the Entity List.
On the defensive side, vulnerability equities processes — the US VEP and equivalents — require agencies to weigh disclosing a flaw to the vendor against keeping it for operations. Bug bounty programs and vendor vulnerability reward programs form the legal white-market alternative, and their rising payouts are the industry's quiet answer to the grey market's pull.
Evidence
Public price lists from brokers show premium mobile exploit chains priced in the millions and rising. The US has sanctioned or entity-listed multiple commercial spyware vendors, and the State Department has convened a coalition of governments committing to curb spyware misuse. Vendor reward programs, meanwhile, have raised top payouts into the hundreds of thousands — still below grey-market prices, but with legality and reputational safety attached.
The spyware scandals of the past several years — documented by Citizen Lab, Amnesty International and consortium journalism — supplied the political pressure that turned these measures from proposals into rules.
The competing read
Security researchers mostly argue the market should be pushed toward disclosure: every stockpiled zero-day is a hole in everyone's security, and state use normalizes the tooling that ends up aimed at civil society. Intelligence officials counter that lawful access to adversary communications depends on exactly these capabilities, and that unilateral disarmament just moves the market to less scrupulous sellers. The policy compromise emerging — regulate the commercial trade, constrain but preserve state programs — satisfies neither camp fully, which may mean it's durable.
What happens next
Watch whether the anti-spyware coalition's commitments get teeth — procurement bans and visa restrictions are the enforcement mechanism — and whether export-control enforcement produces its first major criminal cases. On the defensive side, watch mandatory vulnerability-reporting rules for software sold into government, which would shift the economics toward patching at scale.
