What Is a Bug Worth?

2026 Synthesis Edition — Twelve Core Ideas in Vulnerability Economics

A vulnerability has no intrinsic price. Its value is the expected payoff of converting a defect into durable access for a specific buyer, minus the costs of discovery, chaining, maintenance, exposure, time decay, and rediscovery. Twelve ideas explain everything else this paper says.

Casey Ellis — April 25, 2026. This edition synthesizes the framework into core ideas, weighting evidence equally across primary sources rather than privileging any single voice. Earlier editions: 2022 · 2022-revised · 2022-v2 · 2026 evidence edition.

Section 0Executive Summary

Eleven core ideas, each one falsifiable, none load-bearing on a single source.

  1. What is priced is not the bug. Defect, exploit primitive, chain, and access are four different objects with four different prices. Most market confusion comes from collapsing them.
  2. Six forces set value. Maintenance cost, time decay, detection risk, substitution availability, conversion machinery, and rediscovery rate. The formula is qualitative, not arithmetic.
  3. Seven buyer models pay differently. Boutique offensive, state-directed volume, initial-access broker, ransomware industrial, chaotic, commercial surveillance, defensive intelligence. Each prices substitutes differently.
  4. AI changes the time axis on both sides. Discovery costs fall for everyone; class-kill costs fall for vendors with a managed stack; the expected useful life of a non-provable exploit compresses.
  5. Mitigations cross the cost curve only on managed stacks. Apple, Google's first-party, Microsoft kernel: yes. Enterprise edge appliances and FOSS supply chain: no.
  6. Rediscovery is the load-bearing constraint. Empirical annualised rediscovery rates of 10-22 percent in 2017 are a floor; AI-assisted research is pushing them up.
  7. Buyers pay for effects, not exploits. Cloud abuse, identity theft, telecom interception, and shell-script-tier capability are first-class substitutes.
  8. The market is bifurcating. Premium-few full chains for sovereign customers, commodity-many "button" tools for municipal-tier buyers, middle thinning.
  9. FOSS supply chain follows different rules. Decentralised authority, single-maintainer choke points, transitive propagation measured in years. The defender tailwind does not reach this segment.
  10. Platforms are fragmenting geopolitically. HarmonyOS, Aurora OS, and the China-internal regulatory regime produce distinct threat models with distinct economics.
  11. Great-power competition is the exogenous variable. Sanctions, indictments, mandatory-disclosure regimes, and AI export controls now drive the same variables the model is trying to price.
  12. Equities regimes are diverging asymmetrically. The US-led centralised vulnerability infrastructure has been partially decommissioned at the same moment China's CNNVD funnel operates at full capacity. The asymmetry is structural and bears on every other claim above.

Section 1What Is Actually Being Priced

The pricing object — the thing the buyer pays for — is rarely the bug.

ObjectDefinitionBuyer
DefectLatent flaw in code or hardwareBug bounty programs (Apple Security Bounty raised full-chain payouts to $2M in 2025)
Exploit primitiveValidated way to convert a defect to capabilityBrokers and chain assemblers
ChainEnd-to-end composed capabilityGovernment direct buyers; Crowdfense's $30M acquisition program publicly listed $7M iOS, $5M Android, $9M zero-click SMS/MMS in 2024
AccessThe target's data, communications, or sessionEnd customers (intelligence services, surveillance vendors); DOJ's March 2025 i-Soon indictment documented PRC pricing of $10K-$75K per compromised email account

Disambiguating the four objects dissolves several long-running disputes. Bounty payouts and broker prices are not the price of an iOS bug; they price different objects with different liquidity, exclusivity, and obligations. A government contract is not paying for a chain; it is paying for maintained access through the chain's degradation curve. A ransomware affiliate is not buying a defect; the buyer is buying access and is indifferent between credentials, an n-day, or a 0-day if the operational outcome converges.

A second conflation cuts across all four objects: advertised offers versus realised sales. Ex-brokers Maor Shwartz (Black Hat 2019, Q-recon: 17% from companies, 15% from governments) and "the grugq" independently disclose a ~15–17% intermediary commission, and the Williams DOJ case shows an advertised $20M Operation Zero ceiling clearing at ~$162K per exploit. A published broker sheet is a bounding curve, not a transaction record.

Section 2The Six Forces That Set Value

Six forces shape what a buyer will pay for any of the four pricing objects. They interact, dominate one another at different points in the lifecycle, and respond to substitution pressure.

1. Maintenance cost

The hidden total-cost-of-ownership variable. Discovery and development are one-time costs; maintenance compounds with every patch cycle. On hardened tier-one targets, maintenance dominates the first two combined within 12-18 months of a chain reaching production. Most external valuations count only the first two.

2. Time decay

Vulnerabilities are wasting options. Their value declines as exposure, patching, and detection close in. RAND's Zero Days, Thousands of Nights (2017) reported a median latent life of 6.9 years on a small private dataset of held zero-days; the figure is widely cited and almost certainly overstates residual lifetime under 2026 conditions.

3. Detection risk

A burned exploit is worse than worthless. It exposes attribution chains, leaks technique, retires similar capabilities by signature, and creates diplomatic friction. Vendor claims that a specific mitigation prevented attacks must be read with care: operators select capability against observed defenses; if a target runs Lockdown Mode, the operator deploys something else, not the same payload.

4. Substitution

The 0-day is rarely the only path to the operational effect. Substitutes include n-days, stolen credentials, supply chain compromise, insider recruitment, telecom interception, cloud-account takeover, and social engineering at scale. Mandiant's M-Trends 2025 places stolen credentials as the second initial-access vector at 16 percent, behind only exploits at 33 percent. Verizon's 2025 DBIR reports credential abuse in 22 percent of 12,195 incidents.

5. Conversion

The gap between holding a defect and producing the operational outcome — chain assembly, OPSEC, deployment infrastructure, target reconnaissance, operator tradecraft. Two buyers holding the same defect may extract orders-of-magnitude different value because their conversion machinery differs. State-direct prices look high in the abstract and reasonable in the context of pipelines that cost tens of millions to maintain.

6. Rediscovery

The rate at which any privately-held capability faces the risk of becoming worthless because someone else independently found it. The empirical baseline (Section 6) is 10-22 percent annualized for public datasets; AI-assisted research is pushing the rate up. Rediscovery is the constraint that bounds every other force — an exploit you can't keep private cannot be priced for maintained access.

Section 3The Seven Buyer Models

The same technical artifact attracts seven different prices. The model depends on what the buyer values, what substitutes they have, and what obligations they accept.

ModelObject purchasedPricing logic
A. Boutique offensiveFull chain plus maintenance contractCost-plus; high obligations and exclusivity
B. State-directed volumeMany chains and access points; tolerant of brittle bugs against unpatched targetsAggregate access value; decentralized procurement (PRC model)
C. Initial-access brokerValidated accessPer-foothold; n-days and credentials beat 0-days when both work
D. Ransomware industrialAccess plus encryption tooling and leverageExpected ROI net of dwell-time risk and substitute access vectors
E. Chaotic / anti-economicWhatever is available; ideological or expressiveOutside rational pricing
F. Commercial surveillanceOne full chain amortised across many sovereign customersRecurring SaaS-style on top of chain investment (NSO, Paragon, Intellexa pattern)
G. Defensive intelligenceThe defect plus the option to discloseCost of class kill, not cost of exploit (ZDI, broker-funded VRPs)

Two structural notes. First, the top-tier offensive market is gated by trust networks rather than procurement; pricing is opaque and illiquid because customer vetting runs on word-of-mouth. Second, the market boundary is wider than exploit pricing: effect-based buyers (Section 7) route demand into cloud abuse, telecom interception, and sister-company services that produce the same operational outcome.

Section 4The AI Inflection

AI is the largest live variable. It changes the time axis on both sides simultaneously, but asymmetrically.

Idea I-1
AI compresses expected exploit lifetime — vendors find and patch faster, and the useful life of a non-provable exploit shortens.
Project Zero / DeepMind, 2024-2025
Big Sleep reported 20+ unknown bugs in widely-deployed open source. CVE-2025-6965 was found and pre-empted before in-the-wild deployment.
Project Zero, July 2025
The 2025 Disclosure Policy update targets the upstream patch gap directly: AI shortens discovery, but downstream deployment latency has barely moved.
Idea I-2
AI is asymmetric toward experts at the high end. Democratisation is real at the bottom of the market; at hardened tier-one, expert-plus-AI dominates AI alone.
DARPA AIxCC, August 2025
The AIxCC final ran seven systems against 54M lines of real code; the podium (Team Atlanta, Trail of Bits, Theori) was elite human security teams that built the AI.
arXiv 2509.07933, Sept 2025
Breaking Android with AI shows non-trivial autonomous progress on rooting and privesc without expert steering. Not a Pixel chain, but more than the asymmetry thesis allows.
Idea I-3
Vendor-side AI tailwind enables cheap re-architecture — in managed ecosystems where merged PR equals shipped patch.
Google Security Blog, Nov 2025
Rust in Android: memory-safety vulnerabilities fell from 223 (2019) to under 50 (2024); below 20 percent of total vulns in 2025 for the first time.
Mandiant M-Trends 2025
Time-to-exploit collapsed 32 days to 5 days in 2024. Three of four most-exploited 2024 CVEs were zero-days in security products themselves: PAN-OS, Ivanti, FortiClient.

The China-side picture cuts against the symmetric reading. Western AI vendors impose hard guardrails on offensive output; DeepSeek's V3 and R1 ship without comparable restrictions. NIST CAISI's September 2025 evaluation found DeepSeek agents roughly 12x more likely than US frontier models to be hijacked into malicious instruction-following. Cisco's red-team evaluation found DeepSeek failed to block any harmful prompt where GPT-4o blocked 86 percent. Huawei's HULK Robot has been credited with roughly 25 percent of bugs fixed in Linux 5.4 and 15 percent in 5.10 (per Margin Research), with the structural concern that Huawei tests fixes on its openEuler distribution before upstreaming. Whether the defender tailwind wins on net depends on which side's tailwind is structurally larger — and that is now an open question.

Section 5Mitigations and the Cost Curve

Class-killing mitigations work where they ship into managed stacks. They do not generalise to enterprise edge or FOSS.

Idea I-4
The cost curve has crossed for hardened tier-one targets — finding and developing a working chain on iOS, Pixel, or Chrome sandbox now costs more in time and capital than vendors spend shipping the next class kill.
Apple Security Research, Sept 2025
Memory Integrity Enforcement on A19 silicon: five-year hardware-OS co-design, internally tested against three years of mercenary spyware chains. Apple raised full-chain bounty ceilings to $2M.
GTIG, April 2026
2025 Zero-Days in Review counted 90 in-the-wild zero-days, up from 75 in 2024. Commercial surveillance vendors out-exploited nation-state groups for the first time. Demand absorbed the cost increase.

The cost curve thesis is not a 2026 narrative. The empirical baseline was documented at OffensiveCon 2019 in Mark Dowd's keynote What's in a Jailbreak? Hacking the iPhone 2014-2019. A 2015-era iOS 9 jailbreak required roughly five components: a Safari exploit, a sandbox escape, a kernel exploit, an optional KPP bypass, and persistence. By iOS 12 in 2019 the same operational outcome required all of the above plus a bulletproof JIT bypass, a user-mode PAC bypass, a kernel-mode PAC bypass, a PPL bypass, and an APFS remounting bug — roughly ten components. NSO's 2016 Pegasus chain relied on JIT writes, vtable overwrites, ROP backdoors, multi-kernel patches, file-system remounting, and user-mode backdoors; by 2019 every one of those primitives had been mitigated by some combination of GigaCage, fast permission switching, KTRR, PAC, APFS integrity, and PPL. Dowd's 2019 forward prediction — that further mitigations would push offensive operations toward "data-only attacks" and "weird machines" while Apple shipped data-structure integrity verification in response — is precisely the trajectory that produced MIE on the A19 six years later. The chain-complexity curve has been measured, not asserted, across more than a decade.

Idea I-5
Class-killing mitigations require a soak period. Year-one bypass headlines are not steady-state evidence.
Citizen Lab, 2022-2023
PWNYOURHOME analysis documented Apple Lockdown Mode blocking the 2022 NSO chain; no successful Lockdown Mode compromises observed in the cohort.
GitHub Security Lab + IEEE S&P 2025
CVE-2025-0072 bypasses MTE on Pixel 7/8/9 via Mali GPU memory mappings. TikTag leaks MTE tags via speculative execution in under four seconds.

The cost curve crosses unevenly. It crosses cleanly on hardened-mobile and browser surfaces where the West has spent the engineering capital. It has not crossed for enterprise edge devices, telecom infrastructure, or critical-infrastructure OT. The 2024-2025 PRC-attributed Salt Typhoon and Volt Typhoon campaigns exploited exactly the segments where Western vendors have not invested at the rate of Apple and Google. The cost curve is geographically and sectorally uneven.

Section 6Rediscovery: The Collision Constraint

Rediscovery is the rate at which a privately-held capability becomes worthless not because it was burned or patched but because someone else independently found it.

Two foundational empirical estimates anchor the discussion, and they disagree:

RAND, 2017
Zero Days, Thousands of Nights measured a small private dataset and found 5.76 percent annualised rediscovery; under 1 percent at 90 days; median latent life 6.9 years.
Belfer Center, 2017
Herr, Schneier & Morris measured public disclosure records and found 12.7 percent aggregate, 10.8 percent Chrome to 21.9 percent Android; 60+ percent of rediscovery within a year. Earlier work (Ozment 2005, Finifter 2013) sat between 4.6 and 9 percent.

The two papers measured different populations — held private bugs vs publicly-disclosed ones — but the gap is wide enough to matter for every economic claim downstream of it. Earlier estimates (Ozment 2005 at 9 percent for immature software; Finifter, Akhawe, Wagner 2013 at 4.6 percent for Chrome) sit between the two.

Idea I-6
Rediscovery rates are rising under AI. The 2017 baseline measured human-led research; AI-assisted discovery scales differently, and discovery cost is collapsing faster than disclosure incentive is changing.
NDSS 2026
FirmAgent: 140 zero-days in IoT firmware at 91 percent precision via LLM agents.
arXiv 2509.01835, 2025
CVE-Genie reproduces 2024-2025 CVEs at 51 percent success for $2.77/CVE.

Every economic claim about privately-held capability bends through rediscovery. Maintenance cost is rational only if the asset survives long enough to amortise the burden. Cascade strategies (Section 8) are bets that rediscovery is low enough to amortise the same bug across operators. The bifurcation thesis is partly a rediscovery story: premium chains have low rediscovery (novel logic, multiple obscure components); commodity bugs sit at or above the Herr rate. The middle thins because maintenance economics work only at the rediscovery extremes.

The policy consequence is the Vulnerabilities Equities Process. If rediscovery is closer to 1 percent, retention dominates; if closer to 22 percent, disclosure dominates. The Western VEP was built when 5.76 percent was a defensible upper bound. The empirical case for retention has been weakening since 2017, and AI is weakening it further.

Section 7Substitution and Effect-Based Buying

Buyers pay for outcomes, not for capability artifacts. The most under-priced shift in the 2026 marketplace.

Idea I-7
Effect-based buying is displacing capability-based buying for the broad market, but bounded at the very top.
Mandiant + Verizon, 2025
Stolen credentials at 16 percent of M-Trends 2025 initial access (up from 10 percent); 22 percent of DBIR 2025 breaches. Mandiant documents Azure Data Factory and AirByte cloud exfiltration without malware.
Crowdfense + Operation Zero, 2024-2025
Crowdfense $30M acquisition program, $9M zero-click; Operation Zero $20M smartphone chains. Premium tier still pays for capability, not effect.

The 2024-2025 Salt Typhoon campaign is the operational case at strategic scale. The August 2025 CISA / NSA / FBI joint advisory, co-signed by twelve nations, attributed compromise of nine US carriers including the systems used to service CALEA wiretap requests. The operational outcome — access to a target's location, communications, metadata — was achieved without endpoint exploit chains. Substitution at the top of the market does not necessarily route through the broker tier.

Three substitution axes operate simultaneously: 0-day vs n-day (time), exploit vs credentials (vector), endpoint vs cloud-or-telco (architecture). When MIE pushes endpoint chain prices into eight figures, cloud-account takeover at $5K from an access broker becomes the rational substitute for many operational objectives. The exploit is a means; capability is benchmarked against the cheapest substitutable means of producing the same effect.

Persistence has been quietly demoted as a consequence. Symantec / Broadcom documents 62 percent of CrowdStrike's 2025 detections as malware-free; in-memory tradecraft dominates at the endpoint. But persistence has migrated rather than disappeared: M-Trends 2025 reports 44 percent of 2024 zero-days hit enterprise edge devices — VPNs, firewalls, security appliances — precisely because those targets survive endpoint EDR.

Section 8Market Bifurcation

The exploit market is splitting along a clear seam. Premium-few full chains for sovereign customers; commodity-many "button" tools for municipal-tier buyers; the middle thinning.

Idea I-8
The market is bifurcating into a premium tier (NSO-style full chains, multi-million dollar customers) and a commodity tier (Grayshift / Cellebrite / Magnet "button" forensics).
Atlantic Council Mythical Beasts, 2024
Mythical Beasts mapped 435 entities across 42 countries: 49 vendors, 36 subsidiaries, 24 partners, 20 suppliers, 32 holding companies, 95 investors, 179 individuals. 80+ countries confirmed as government customers; 14 of 27 EU states have purchased from NSO alone. Spyware vendors were attributed to 50 percent of all in-the-wild zero-days exploited in 2023.
Citizen Lab Paragon, 2025
First Look at Paragon: documented sales reaching municipal-level police forces. Cellebrite grew revenue 23 percent to $401M in 2024.

The mechanism is mechanical: as mitigations stack and chains get longer, brittler, and more expensive, the producer faces a choice. Serve a few customers paying top dollar for full chains, or commoditise and serve many customers cheaply. The middle — where chains are not trivial but not strategic crown jewels — thins because the maintenance economics do not support boutique custom work for a small number of mid-budget customers.

The supply side concentrates geographically. Mythical Beasts identifies six structural patterns:

  1. Three jurisdictions dominate. Israel, India, and Italy host the majority of identified entities.
  2. Serial entrepreneurship is rife. Founders rotate through multiple vendors, carrying capability and customer relationships across corporate identities.
  3. Hardware-surveillance partnerships are common. Spyware vendors regularly co-sell with IMSI-catcher and telecom-intercept vendors.
  4. Vendor identities shift frequently. Renaming, restructuring, and re-domiciling are deliberate strategies for evading scrutiny.
  5. Jurisdictional arbitrage is a strategy, not a side-effect. Vendors place subsidiaries in lighter-regulation jurisdictions while concentrating R&D elsewhere.
  6. Capital flows cross borders. Each vendor or supplier averages 4.75 identified investors. Italy, Israel, the United States, and the United Kingdom together account for 46.3 percent of identified investors.

The 0-day price paradox resolves through the same mechanism. Discovery cost is collapsing — AI helps. Weaponisation cost is exploding — modern chains require five or more components where three sufficed five years ago, each independently maintained. Zerodium reduced 1-click iOS payouts from $1.5M to $1M citing oversupply at that tier; Crowdfense and Operation Zero raised premium-tier ceilings 2-3x over the 2019 baseline. The market is bifurcated, not uniformly inflating.

Section 9The FOSS Supply Chain Exception

The defender tailwind reaches managed stacks. It does not reach the federated FOSS supply chain at all.

The Section 5 cost-curve thesis assumes a vendor architecture where a merged pull request becomes a shipped patch within a release cycle the vendor controls. Most exploitable code does not live in that architecture. Open-source dependencies travel through maintainer review (often one unpaid individual), upstream release, distro repackaging, container-image rebuild, transitive-dependency resolution, and downstream consumer adoption — a chain measured in months to years.

Three live cases anchor the asymmetry:

The structural point: FOSS supply chain is the inverse of the managed-vendor ecosystem the cost-curve thesis describes. Authority is decentralised, maintainer capacity is the binding constraint, downstream propagation is unowned, trust is built socially. The Linux Foundation's Census III documents that a small number of critical packages have one or zero active maintainers. AI raises the floor for attackers in this ecosystem — cheap PRs, cheap social engineering, cheap fuzzing of obscure dependencies — without raising it commensurately for defenders, because there is no vendor budget to spend the AI tailwind on.

Section 10Geopolitical Platform Fragmentation

The mobile and disclosure-regime threat model is fragmenting along geopolitical lines. The 2010s assumption that iOS-and-Android encompasses the strategic surface no longer holds in Asia.

Idea I-9
Geopolitical balkanisation produces distinct platform threat models with distinct economics.
Atlantic Council Sleight of Hand, 2023
2021 RMSV requires disclosure to MIIT within 48 hours and prohibits foreign disclosure or PoC release. China-attributed CVE acknowledgements have declined post-2021.
Counterpoint / SCMP, Q2 2025
HarmonyOS 17 percent China share, iOS 16 percent; sixth consecutive quarter HarmonyOS surpassed iOS domestically. 8M developers mid-2025.

Two regulatory regimes have diverged. China's CNNVD, operated by the MSS 13th Bureau, beats NVD to publication 43 percent of the time on average but only 3 percent of the time when a vulnerability is being actively exploited by Chinese APT groups; 267 publication dates have been retroactively altered to obscure the MSS evaluation window. The US-side equivalent infrastructure is meanwhile partially decommissioned: NIST acknowledged a backlog and reduced enrichment of CVEs in February 2024; CISA stood up the Vulnrichment ADP container in May 2024 to fill the gap; the MITRE CVE program required emergency funding extension in April 2025. The asymmetry is the load-bearing point: China's adversarial mirror operates at full capacity while the US central infrastructure has been federated under emergency conditions.

The competition pipeline mirrors the regulatory divergence. China runs an estimated 54 annually-recurring hacking competitions (Atlantic Council, 2024) that route vulnerabilities into MSS, MPS, and PLA branches. Matrix Cup 2024 offered ¥18M (roughly $2.5M) for zero-day exploits; Tianfu Cup returned January 2026 under MPS lead with an AI-assisted vulnerability-discovery track and the contest website blocked to non-China IP addresses after the event.

Section 11Great-Power Competition as Exogenous Variable

Sanctions, indictments, mandatory-disclosure regimes, AI export controls, and adversarial vendor-security investments now drive the same variables the model is trying to price.

Idea I-10
Great-power competition is an exogenous force on the marketplace at the same magnitude as AI cost dynamics. Any model that ignores political weather uses the wrong frame.
US Treasury OFAC, Dec 2024 - Jan 2025
Sanctions on Sichuan Silence (Sophos firewalls), Integrity Tech (Flax Typhoon), Sichuan Juxinhe (Salt Typhoon) in a single 38-day window.
DOJ + ODNI, 2024-2025
March 2025 DOJ indictment of 12 i-Soon and APT27 actors; 2025 ATA couples Volt Typhoon and Salt Typhoon as paired strategic concerns.

The Atlantic Council's Crash, exploit, and burn (DeSombre Bernsen, June 2025) is the comparative study. Western (US, FVEY) supply is "international, opaque, loosely affiliated networks" with feast-or-famine procurement cycles, prime-contractor concentration (L3Harris, ManTech), and middlemen extracting value rather than creating it. PRC supply is a comprehensive feeder system from CTFs through universities into the MSS, MPS, and PLA, with state-mandated vulnerability flow into CNNVD, decentralised provincial procurement, civil-military fusion since 2017, and an "A-team to D-team cascade" that extends every chain's shelf-life through tiers of operators. The Western middle market is structurally weak in ways the Chinese middle is not.

The political pressure is bidirectional. The 2024 trajectory was toward more state intervention: the Pall Mall Process Code of Practice (April 2025) committed 23 states to oversight of commercial cyber intrusion capabilities; China has not engaged. The late-2025 trajectory was toward less: Treasury lifted sanctions on three Intellexa-affiliated executives; the DHS Cyber Safety Review Board was disbanded in January 2025, terminating its Salt Typhoon investigation; ICE acquired Paragon-related contracts post-inauguration. The marketplace is being actively re-engineered on both sides.

The capital story complicates the policy story. Mythical Beasts documents 14 distinct US-based entities investing in spyware vendors or suppliers, 12 of which target Israeli firms. Paragon Solutions, established in Israel in 2019, is backed by Battery Ventures and Blumberg Capital out of Boston; the firm sells to municipal-tier customers (per Citizen Lab) and was acquired by ICE-adjacent contracting in late 2025. The same US that sanctions Chinese contractors and signs the Pall Mall Process is also the largest non-Israeli source of capital fuelling the very vendors those sanctions ostensibly target. Capital, talent, and policy are running on three different clocks.

Idea I-11
Equities regimes are diverging asymmetrically. The Western centralised vulnerability infrastructure has been partially decommissioned at the same moment China's CNNVD funnel operates at full capacity.
NIST + CISA, 2024-2025
NIST acknowledged the NVD enrichment backlog in February 2024; CISA stood up Vulnrichment in May 2024; the MITRE CVE Program required emergency funding extension in April 2025.

Section 12Limits and Uncertainty

No model of a market this opaque is right. The question is whether it is useful.

What this paper gets right

What this paper might get wrong

What this paper genuinely cannot price

Section 13Sources

All sources cited inline above are listed here. Treated as peers; no single source is privileged.

Empirical foundations

Vendor primary sources

Threat intelligence and incident response

Market and policy analysis

Government and regulatory

Academic and research

FOSS supply chain

Marketplace and trade press

Practitioner sources