Exploit
Acquisition

We acquire zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms. Payouts range from $10,000 to $7 million depending on target, reliability, and operational value.

Submit Research

What We Buy

We buy individual primitives, not just finished chains. A sandbox escape, kernel info leak, or type confusion primitive is valuable on its own. Full chains pay the most, but we acquire at every stage of development.

All submissions require exclusivity — we do not acquire exploits that have been sold elsewhere or previously disclosed. Current versions of target software only. No theoretical vulnerabilities, no DoS-only, no phishing.

We Accept

  • Individual primitives — info leaks, type confusions, UAFs
  • Partial chains and sandbox escapes
  • Full exploit chains (highest payouts)
  • Zero-days with no prior disclosure
  • Current versions of target software

We Don’t Accept

  • Theoretical or unproven vulnerabilities
  • Previously disclosed or patched bugs
  • Non-exclusive or previously sold exploits
  • Denial-of-service only
  • Exploits requiring physical access

Platforms & Payouts

Prices are indicative maximums. Actual payouts depend on exploit quality, reliability, stealth characteristics, and current demand. Partial chains and individual components are also considered.

Mobile

up to $7M
High demandiOS Zero-Click Full Chain
$5M – 7M
High demandiOS One-Click Full Chain
$3M – 5M
High demandAndroid Zero-Click Full Chain
$3M – 5M
Android One-Click Full Chain
$1M – 3M
iOS/Android Persistence Module
$500k – 1M
Baseband RCE
$500k – 1M

Desktop OS

up to $1.5M
High demandWindows RCE + LPE Chain
$500k – 1.5M
High demandmacOS RCE + Sandbox Escape
$500k – 1.5M
Windows LPE / Kernel Code Execution
$200k – 500k
macOS LPE / Kernel Code Execution
$200k – 500k
Linux Kernel LPE (recent mainline)
$100k – 300k

Browsers

up to $1.5M
High demandChrome RCE + Sandbox Escape
$500k – 1.5M
High demandSafari/WebKit RCE + Sandbox Escape
$500k – 1.5M
Chrome/V8 RCE (renderer only)
$200k – 500k
Safari/WebKit RCE (renderer only)
$200k – 500k

Network & Infrastructure

up to $500k
High demandCisco IOS/IOS-XE RCE
$200k – 500k
Firewall/VPN Appliance RCE
$150k – 500k
Enterprise Email Server RCE
$150k – 400k
Virtualization / Hypervisor Escape
$200k – 500k

How It Works

01

Initial Contact

Send a brief technical summary — target, vulnerability class, and proof of exploitability. No full exploit code at this stage.

02

Evaluation

Our research team assesses impact, reliability, and operational value. We respond within 72 hours with a preliminary offer or follow-up questions.

03

Agreement

We negotiate final terms and execute a formal acquisition agreement covering exclusivity, payment, and confidentiality.

04

Delivery & Payment

You provide the full exploit package — source, writeup, root cause, and methodology. Payment releases upon validation via wire or crypto.

Submit Research

Send a brief technical summary — target platform, exploit type, and constraints. Do not include full technical details in initial contact.

PGP keys available upon request.

info@irisc2.com