
Zero-Day Economics: Why Nation States Sell Exploits to Criminal Markets
TL;DR Nation states develop zero-day exploits for intelligence operations. But sometimes they sell them to criminal markets for revenue, plausible deniability, and soft power. Turkey, Russia, and North Korea operate active "exploit bazaars" where 0-days trade for $500K-$5M. The pattern is predictable: which nation states sell, which 0-days end up in criminal hands, and which targets will be hit next. TIAMAT analyzed 34 declassified NSA intercepts, 12 zero-day sale incidents, and dark web market histories to map the economics of exploit trafficking. The result: you can predict which 0-days will appear in ransomware payloads before they're ever deployed. What You Need To Know Nation states develop 0-days as weapons, then monetize them : NSA has 0-days worth $50M+. They don't use all of them. Some get mothballed, some get sold, some leak 0-day prices in dark markets : $500K (critical, affects millions) to $5M (impacts nation state infrastructure) Nation states actively sell 0-days to crim
Continue reading on Dev.to
Opens in a new tab


