The zero-day vulnerability market has always operated in a grey zone where legal ambiguity, asymmetric information, and enormous financial incentives create conditions ripe for exploitation. What the Krebs on Security report on IRIS C2 exposes, however, is something qualitatively different from the usual opacity of this market. It is a case study in how the structural weaknesses of the offensive security industry allow bad actors to position themselves credibly, at least superficially, as legitimate brokers of high-value security research.
IRIS C2, operating under the corporate shell Calvexa Group LLC and registered at an address associated with lobbying firm Burkman & Associates, has been publicly advertising payouts of up to $7 million for zero-day exploits across major platforms. The company is run by Jacob Wohl and Jack Burkman, two individuals with documented histories of securities fraud, telecommunications fraud, civil rights violations, and the fabrication of intelligence dossiers used to smear public figures. Both have felony convictions. The brazenness of this operation raises questions that go well beyond the individuals involved.
The Structural Opacity of the Zero-Day Brokerage Market
To understand why an operation like IRIS C2 can exist and attract attention from genuine researchers, it helps to understand the baseline conditions of the vulnerability acquisition market. Legitimate brokers such as Zerodium, Crowdfenders, and various government-adjacent contractors operate with varying degrees of transparency. Zerodium, for instance, publishes explicit payout tables. Government programmes like those run by defence contractors are almost entirely opaque by design. This creates a spectrum where opacity is normalised and even expected.
IRIS C2 positions itself at the high-payout, high-visibility end of this spectrum while simultaneously claiming operational secrecy about its actual clients and contracts. Wohl told Krebs that he could not discuss specific government contracts publicly. This is a standard claim in the industry, and its very ordinariness is part of what makes it an effective cover. Researchers accustomed to dealing with classified programme offices are primed to accept non-disclosure as a signal of legitimacy rather than a red flag.
The company's recruitment messaging compounds this problem. By explicitly targeting junior researchers with high raw ability and no formal credentials, IRIS C2 is fishing in a pool of individuals who may lack the professional networks needed to vet a potential employer. A seasoned vulnerability researcher at a major firm has colleagues who can perform due diligence. A self-taught 22-year-old who found a media decoder flaw on a mobile platform almost certainly does not.
What the Technical Claims Actually Reveal
Wohl's description of his company's technical work during the Krebs interview is worth examining carefully. He describes receiving exploit primitives, where a researcher has identified a flaw and demonstrated a proof-of-concept, and then developing those primitives into stable, reliable, operationally deployable exploits. This is a real and technically demanding workflow. The gap between a primitive and a weaponised exploit is significant. It requires deep knowledge of memory management, operating system internals, anti-exploitation mitigations such as ASLR, CFG, and PAC, and the specific deployment environment.
Wohl also claimed to know more about technology than anyone and described himself as capable of creating capabilities that would make your head spin. These are not the claims of someone with genuine technical depth. Researchers who actually do this work tend toward understatement, not hyperbole. The technical vocabulary Wohl deploys is accurate at a surface level, which suggests familiarity with the terminology rather than the practice. This is a meaningful distinction. Someone who has read extensively about exploit development can discuss exploit primitives coherently without being able to write a single line of shellcode.
Whether IRIS C2 has any genuine technical staff is unknown. Wohl claims approximately 40 employees, none of whom are permitted to list their employment on LinkedIn. This is not inherently implausible for a sensitive government contractor, but combined with the principals' documented history of fabricating entire organisations, it warrants serious scepticism.
Regulatory and Legal Gaps Enabling This Operation
The IRIS C2 case highlights several specific regulatory gaps that deserve attention from policymakers and the security research community.
- Federal contractor vetting: Calvexa Group LLC appears in government contracting databases as a registered federal contractor despite having no documented active contracts. The process for obtaining contractor registration does not appear to screen for principals with felony convictions related to fraud and civil rights violations.
- Export control ambiguity: Zero-day exploits and offensive cyber capabilities are subject to export control regulations under the EAR and, in some cases, the ITAR. Whether IRIS C2 has applied for or received the necessary licences to broker such capabilities is entirely unclear from public information.
- Probation conditions: Both Wohl and Burkman were sentenced to probation in late 2025 for their robocall scheme. It is a reasonable question whether operating a company that brokers offensive cyber capabilities is consistent with the terms of that probation, particularly given that the scheme involved sophisticated technical infrastructure for voter suppression.
- Researcher liability: A vulnerability researcher who sells an exploit to IRIS C2 may be unknowingly participating in a transaction that violates export control law, computer fraud statutes, or both, depending on how the capability is ultimately deployed. The legal exposure falls disproportionately on the researcher, not the broker.
The LobbyMatic Pattern and Systemic Risk
The prior LobbyMatic venture is instructive here. Burkman and Wohl operated an AI-based lobbying platform under assumed names, Jay Klein and Bill Sanders respectively, and employees only discovered the principals' true identities after the fact or upon resignation. This is not opportunistic deception. It is a repeatable operational pattern: create a company in a technically credible domain, recruit people who lack the context to perform due diligence, extract value, and exit.
The cybersecurity context makes this pattern considerably more dangerous than an AI lobbying platform. Vulnerability research has direct national security implications. An operation that acquires zero-day exploits under false pretences could potentially transfer those capabilities to foreign actors, criminal organisations, or use them for purposes entirely unrelated to the stated government contracting mission. The July 2026 update to the Krebs piece adds another dimension: Burkman and Wohl were reportedly paid a $300,000 retainer by a Canadian cryptocurrency fraudster wanted in multiple jurisdictions for allegedly stealing $65 million. The willingness to accept large payments from individuals facing serious criminal charges in exchange for influence-seeking services is consistent with a pattern of operating at the intersection of legal grey zones and outright criminality.
Implications for the Vulnerability Research Community
The security research community has long grappled with questions about the ethics of selling offensive capabilities. Those debates typically centre on whether selling to authoritarian governments or criminal actors is acceptable, and what due diligence researchers owe their buyers. The IRIS C2 case adds a dimension that receives less attention: what happens when the broker itself is the bad actor?
Several practical recommendations follow from this analysis. Researchers considering selling vulnerability research to any broker should treat the absence of verifiable employee histories as a significant warning sign. The claim that employees cannot list their employer on LinkedIn is not, by itself, disqualifying, but it removes the primary mechanism by which researchers could verify a company's legitimacy through professional networks. Researchers should also independently verify a company's registration, legal history of its principals, and export control compliance before engaging.
The broader market would benefit from more systematic vetting infrastructure. Organisations like the vulnerability coordination community, ISACs, and professional bodies such as the IEEE could provide researcher-facing resources for vetting brokers, analogous to the way financial regulators maintain public records of disciplinary actions against registered advisers.
What the IRIS C2 case ultimately demonstrates is that the offensive security market's tolerance for opacity, which exists for genuinely legitimate operational reasons in many contexts, creates attack surface that bad actors can exploit. The solution is not to force full transparency onto a market where classification and operational security are sometimes necessary. It is to build better vetting mechanisms at the edges, where researchers and brokers first make contact, before capabilities change hands and legal exposure crystallises. Wohl and Burkman are not sophisticated adversaries. If an operation this poorly concealed can attract thousands of followers and conference attendees willing to discuss selling their research, the structural problem is considerably larger than two convicted felons with a website.