← Home

IRIS C2 and the Zero-Day Market's Credibility Problem

By James Trappett · 13 July 2026

5 min read

The zero-day vulnerability market has always operated in a grey zone where legal ambiguity, asymmetric information, and enormous financial incentives create conditions ripe for exploitation. What the Krebs on Security report on IRIS C2 exposes, however, is something qualitatively different from the usual opacity of this market. It is a case study in how the structural weaknesses of the offensive security industry allow bad actors to position themselves credibly, at least superficially, as legitimate brokers of high-value security research.

IRIS C2, operating under the corporate shell Calvexa Group LLC and registered at an address associated with lobbying firm Burkman & Associates, has been publicly advertising payouts of up to $7 million for zero-day exploits across major platforms. The company is run by Jacob Wohl and Jack Burkman, two individuals with documented histories of securities fraud, telecommunications fraud, civil rights violations, and the fabrication of intelligence dossiers used to smear public figures. Both have felony convictions. The brazenness of this operation raises questions that go well beyond the individuals involved.

The Structural Opacity of the Zero-Day Brokerage Market

To understand why an operation like IRIS C2 can exist and attract attention from genuine researchers, it helps to understand the baseline conditions of the vulnerability acquisition market. Legitimate brokers such as Zerodium, Crowdfenders, and various government-adjacent contractors operate with varying degrees of transparency. Zerodium, for instance, publishes explicit payout tables. Government programmes like those run by defence contractors are almost entirely opaque by design. This creates a spectrum where opacity is normalised and even expected.

IRIS C2 positions itself at the high-payout, high-visibility end of this spectrum while simultaneously claiming operational secrecy about its actual clients and contracts. Wohl told Krebs that he could not discuss specific government contracts publicly. This is a standard claim in the industry, and its very ordinariness is part of what makes it an effective cover. Researchers accustomed to dealing with classified programme offices are primed to accept non-disclosure as a signal of legitimacy rather than a red flag.

The company's recruitment messaging compounds this problem. By explicitly targeting junior researchers with high raw ability and no formal credentials, IRIS C2 is fishing in a pool of individuals who may lack the professional networks needed to vet a potential employer. A seasoned vulnerability researcher at a major firm has colleagues who can perform due diligence. A self-taught 22-year-old who found a media decoder flaw on a mobile platform almost certainly does not.

What the Technical Claims Actually Reveal

Wohl's description of his company's technical work during the Krebs interview is worth examining carefully. He describes receiving exploit primitives, where a researcher has identified a flaw and demonstrated a proof-of-concept, and then developing those primitives into stable, reliable, operationally deployable exploits. This is a real and technically demanding workflow. The gap between a primitive and a weaponised exploit is significant. It requires deep knowledge of memory management, operating system internals, anti-exploitation mitigations such as ASLR, CFG, and PAC, and the specific deployment environment.

Wohl also claimed to know more about technology than anyone and described himself as capable of creating capabilities that would make your head spin. These are not the claims of someone with genuine technical depth. Researchers who actually do this work tend toward understatement, not hyperbole. The technical vocabulary Wohl deploys is accurate at a surface level, which suggests familiarity with the terminology rather than the practice. This is a meaningful distinction. Someone who has read extensively about exploit development can discuss exploit primitives coherently without being able to write a single line of shellcode.

Whether IRIS C2 has any genuine technical staff is unknown. Wohl claims approximately 40 employees, none of whom are permitted to list their employment on LinkedIn. This is not inherently implausible for a sensitive government contractor, but combined with the principals' documented history of fabricating entire organisations, it warrants serious scepticism.

Regulatory and Legal Gaps Enabling This Operation

The IRIS C2 case highlights several specific regulatory gaps that deserve attention from policymakers and the security research community.

The LobbyMatic Pattern and Systemic Risk

The prior LobbyMatic venture is instructive here. Burkman and Wohl operated an AI-based lobbying platform under assumed names, Jay Klein and Bill Sanders respectively, and employees only discovered the principals' true identities after the fact or upon resignation. This is not opportunistic deception. It is a repeatable operational pattern: create a company in a technically credible domain, recruit people who lack the context to perform due diligence, extract value, and exit.

The cybersecurity context makes this pattern considerably more dangerous than an AI lobbying platform. Vulnerability research has direct national security implications. An operation that acquires zero-day exploits under false pretences could potentially transfer those capabilities to foreign actors, criminal organisations, or use them for purposes entirely unrelated to the stated government contracting mission. The July 2026 update to the Krebs piece adds another dimension: Burkman and Wohl were reportedly paid a $300,000 retainer by a Canadian cryptocurrency fraudster wanted in multiple jurisdictions for allegedly stealing $65 million. The willingness to accept large payments from individuals facing serious criminal charges in exchange for influence-seeking services is consistent with a pattern of operating at the intersection of legal grey zones and outright criminality.

Implications for the Vulnerability Research Community

The security research community has long grappled with questions about the ethics of selling offensive capabilities. Those debates typically centre on whether selling to authoritarian governments or criminal actors is acceptable, and what due diligence researchers owe their buyers. The IRIS C2 case adds a dimension that receives less attention: what happens when the broker itself is the bad actor?

Several practical recommendations follow from this analysis. Researchers considering selling vulnerability research to any broker should treat the absence of verifiable employee histories as a significant warning sign. The claim that employees cannot list their employer on LinkedIn is not, by itself, disqualifying, but it removes the primary mechanism by which researchers could verify a company's legitimacy through professional networks. Researchers should also independently verify a company's registration, legal history of its principals, and export control compliance before engaging.

The broader market would benefit from more systematic vetting infrastructure. Organisations like the vulnerability coordination community, ISACs, and professional bodies such as the IEEE could provide researcher-facing resources for vetting brokers, analogous to the way financial regulators maintain public records of disciplinary actions against registered advisers.

What the IRIS C2 case ultimately demonstrates is that the offensive security market's tolerance for opacity, which exists for genuinely legitimate operational reasons in many contexts, creates attack surface that bad actors can exploit. The solution is not to force full transparency onto a market where classification and operational security are sometimes necessary. It is to build better vetting mechanisms at the edges, where researchers and brokers first make contact, before capabilities change hands and legal exposure crystallises. Wohl and Burkman are not sophisticated adversaries. If an operation this poorly concealed can attract thousands of followers and conference attendees willing to discuss selling their research, the structural problem is considerably larger than two convicted felons with a website.

CybersecurityZero-Day ExploitsOffensive SecurityFraudGovernment Contracting

Related Articles

Building Culturally Specific Stereotype Datasets with LLMsMesh LLM: Distributed Inference Over a P2P QUIC MeshSelf-Distillation for Web Search Agents Without Teacher Models