VUPEN, Zerodium, and the Legal Market for Zero-Day Exploits
How VUPEN sold the NSA a hacking service on an invoice, and why the zero-day exploit market Zerodium inherited is legal, filtered, and hard to regulate.

VUPEN, Zerodium, and the Legal Market for Zero-Day Exploits
In September 2012, the NSA signed a 12-month contract with a small French security company for something called “binary analysis and exploits.” There was a purchase order, a scope of work, and an invoice. Nobody broke into anything to close that deal. The company, VUPEN Security, simply sold the American government a subscription, the same way a business sells access to a database or a piece of enterprise software. The contract itself surfaced years later through a public-records request and was reported by Threatpost, the clearest window into a market most people only hear about through headlines like “a million dollars to hack an iPhone.” VUPEN later gave rise to Zerodium, and together the two form the clearest case study of a legal, contract-based zero-day exploit market that most coverage still treats as an underworld curiosity. That is a different kind of trust problem than the one covered in DecodeStack’s explainer on zero trust architecture, where the question is who gets access to a network you already control. Here, the question is who gets to buy a way in before anyone else even knows the door exists. The VUPEN Zerodium zero-day exploit market is not a black-market curiosity. It is a legal, geopolitically filtered trade, and understanding why it works legally is the only way to understand why it is so hard to rein in.
A zero-day is a software flaw the vendor, Apple, Microsoft, whoever wrote the code, does not yet know about. Because there is no patch for it, an exploit built around it (a piece of code that actually uses the flaw to break in) works reliably against fully updated systems. That reliability is what buyers pay for.
What VUPEN actually sold, and to whom
VUPEN Security was founded in 2008 in Montpellier, France, by Chaouki Bekrar. Its researchers found vulnerabilities themselves, in-house, rather than buying bugs discovered by outside hackers and reselling them, which is how a broker like HP’s Zero Day Initiative operates. VUPEN built its own exploits and sold access to that catalog directly to government agencies.
The pricing, as described by Bekrar to Forbes journalist Andy Greenberg in a 2012 profile, followed a subscription model rather than a one-off sale. Government clients paid roughly $100,000 a year just to see the catalog of available exploits. Actually acquiring a specific exploit cost significantly more on top of that fee. In the same interview, Bekrar said Google had once offered him $1 million for a Chrome vulnerability, an offer he turned down, because a company patching the bug it just paid for defeats the entire point of buying it in the first place.
That detail matters more than the dollar figure. A software vendor and a government buyer want opposite outcomes from the same flaw. The vendor wants it dead. The buyer wants it alive, quiet, and reliable for as long as possible. VUPEN’s business existed entirely on the buyer’s side of that line, and it said so openly.

VUPEN Security — the French vulnerability-research firm whose exploit catalog the NSA bought under a services contract.
The company also drew an explicit boundary around its client list. VUPEN’s own marketing materials, reported by Privacy International, stated that a buyer had to be an intelligence or law-enforcement agency, sign a non-disclosure agreement, and belong to NATO (the US-Europe defense alliance), ANZUS (the Australia-New Zealand-US security pact), or ASEAN (the Southeast Asian regional bloc). This is the mechanism that separates the zero-day trade from a genuine black market: participation was voluntarily restricted along the lines of existing diplomatic alliances, not open to the highest bidder regardless of flag. The result is a market with a guest list.
The 2012 NSA contract, and why it was not a scandal
The document that made VUPEN’s business concrete rather than anecdotal surfaced through a Freedom of Information Act (FOIA) request, the US legal mechanism that lets citizens and journalists compel federal agencies to release records. It showed the National Security Agency signing a 12-month services contract with VUPEN dated September 14, 2012, covering exactly the kind of binary analysis and exploit access Bekrar had described to Forbes months earlier. Both Threatpost and Dark Reading covered the contract’s release in detail.
What is notable is what did not happen next. There was no indictment, no sanctions, no congressional hearing framing this as a breach of law. Buying knowledge of an unpatched flaw is not illegal in the United States, provided the seller obtained it through their own research rather than by breaking into a system without authorization. VUPEN’s researchers found the bugs themselves, in their own labs, on their own machines. Selling that knowledge to a government client is, legally, indistinguishable from a defense contractor selling radar technology. The exploit itself never touches a victim’s system until the buyer decides to deploy it, and by then the transaction is long closed and off VUPEN’s books.
This is the structural reason the market persists in plain sight rather than in hidden forums. A legal market does not need to hide its invoices, its contracts, or its client-screening policy. It can, and did, describe itself openly to a Forbes reporter. The absence of secrecy is itself the evidence that nothing about the transaction violated the law as written, whatever discomfort it raises about what the flaw is eventually used for.
From VUPEN to Zerodium: the model that replaced it
VUPEN dissolved, both its French parent company and its US subsidiary. Bekrar founded a new company, Zerodium, in July 2015. The two are legally and commercially distinct entities, not a rebrand, though the connective tissue is the same founder and the same underlying trade.
Zerodium’s business model diverged from VUPEN’s in one visible way: it went public with its pricing. Rather than a private catalog visible only to paying subscribers, Zerodium began publishing a bounty list, a standing offer of specific dollar amounts for specific categories of working exploit, updated periodically and available for anyone to read. In September 2015, Zerodium advertised a bounty of up to $1 million for a complete, remote jailbreak-style exploit against iOS 9, according to SecurityWeek. Two months later, in November 2015, the company confirmed it had actually paid out roughly that amount to a team that delivered a working exploit against iOS 9.1 and 9.2 beta, as reported by Forbes.
That payout is the detail that made headlines at the time, and the one most casual coverage stops at. But the more durable shift is structural, not the dollar amount. A published bounty list turns a private government contract into an open marketplace with visible, standing prices, functioning less like an intelligence procurement deal and more like a commodities board. Sellers, independent researchers anywhere in the world, can see exactly what a working exploit against a given target is worth before they even start looking for one. That transparency does not make the trade more regulated. It makes it more efficient, and Zerodium kept that public-bounty structure visible for nearly a decade. In January 2025 the company took its price list offline, replacing its public site with a single page carrying an email address and a PGP key, according to reporting on the shift — a move from a visible market-maker to an invitation-only channel, not a confirmed shutdown of the underlying trade.

Zerodium — the exploit-acquisition firm that replaced VUPEN, now reachable only through the single email address and PGP key on its site.
One policy carried over unchanged from VUPEN’s era: neither company has sold a vulnerability back to the vendor whose product it affects. Apple never gets first refusal on an exploit built against its own operating system. That standing refusal is what keeps the flaw alive long enough to be worth buying at all.
The disclosure debate this market forces on anyone who uses software
Step back from the corporate structure and the transaction itself raises a genuine question, one that touches anyone running an unpatched device, which is to say nearly everyone. When a government buys a zero-day rather than reporting it to the vendor, the flaw stays open. Anyone else who independently discovers the same bug, another government, a criminal group, a rival researcher, can use it too, against the exact same population of users the buying government is supposed to be protecting.
Security researcher Bruce Schneier wrote directly about this trade-off. In a 2014 post on Schneier on Security, he argued that security vulnerabilities are plentiful and unevenly discovered, meaning the odds that a given flaw will eventually be found by someone else, not just the agency that bought it first, are higher than intelligence agencies tend to admit. Schneier’s core point is that stockpiling a flaw instead of disclosing it for a patch weakens security broadly, including for the citizens of the country doing the stockpiling, because that country’s own institutions, companies, and infrastructure run the same vulnerable software as everyone else’s.
Schneier’s writing also names the internal justification agencies have used to defend keeping a flaw open: a principle sometimes referred to inside the intelligence community as NOBUS, shorthand for “Nobody But Us.” The idea is that some exploits require resources or expertise so specialized that an agency can be reasonably confident no other adversary will independently find and weaponize the same flaw, making the risk of retention low enough to justify keeping the door open for future use rather than reporting it. Schneier’s critique, as documented in that same post, is that this judgment is opaque, made unilaterally, and rarely revisited once the flaw ages or the assumption about exclusivity turns out to be wrong.
None of this requires believing any particular purchase was reckless or malicious. The point Schneier raises is structural: the same flaw that lets a government read a target’s messages also sits, unpatched, in the phone of every ordinary person who happens to run the same software. A reader who updates their phone the week a patch ships is, in effect, closing a door that a market like this one exists specifically to keep propped open a little longer, for a price. That mirrors a narrower version of a trust problem DecodeStack has covered elsewhere: software supply chain attacks exploit the same gap between what a vendor ships and what a vendor actually knows about its own code.
FAQ
Is buying or selling a zero-day exploit illegal?
Selling a zero-day exploit, a flaw a software vendor does not yet know about, is not illegal in the United States as long as the seller discovered it through their own research rather than unauthorized access to a victim’s system. VUPEN and Zerodium both operated openly, with signed contracts and public bounty lists, precisely because the underlying research and sale were lawful.
What is the difference between VUPEN and Zerodium?
VUPEN Security, founded in 2008 in France, sold a private subscription catalog of self-discovered exploits directly to government clients and dissolved after 2015. Zerodium, founded by the same person, Chaouki Bekrar, in July 2015, replaced it with a publicly advertised bounty list; it operated out of the United States until January 2025, when it took its public pricing offline.
Why did the NSA buying exploits from VUPEN not become a scandal?
The NSA’s 2012 contract with VUPEN, revealed through a Freedom of Information Act request, described a straightforward paid service, binary analysis and exploit access, that broke no law as written. Because the transaction was legal on its face, no agency faced sanctions or prosecution once the contract became public.
What is NOBUS and why does it matter?
NOBUS, short for “Nobody But Us,” is the internal justification some intelligence agencies use for keeping a vulnerability unpatched: the belief that only they possess the resources to exploit it. Security researcher Bruce Schneier has argued this judgment is often wrong and rarely revisited, leaving the same flaw exploitable by anyone else who eventually finds it.
Does a zero-day exploit market actually make software less secure for everyone?
A zero-day exploit market does not directly weaken software, but it changes the incentive around disclosure: a flaw sold to a buyer who wants it kept quiet stays unpatched, exploitable by any other party who independently discovers it. Bruce Schneier has framed stockpiling over disclosure as a trade-off that weakens security broadly, not a targeted risk to any single victim.
The one idea worth keeping
The VUPEN Zerodium zero-day exploit market is not a curiosity from the edges of the internet. It is a normal, contract-based business that happens to trade in the one thing software vendors want destroyed as fast as possible: the flaws in their own code. Every unpatched vulnerability in the software running on an ordinary phone or laptop has a real, transactable value to someone with the budget to buy it and a reason to keep it quiet. That is the fact worth carrying forward long after the specific dollar figures and company names from 2012 or 2015 have become historical footnotes.