What is a bug worth?
A multi-edition exploration of how the market for software vulnerabilities actually clears: what counts as a bug, who buys it, and how its price is set. The 2026 model is stress-tested against a corpus of ~150 confirmed historical exploit and surveillance-product transactions drawn from court records, leaked invoices, government disclosures, and journalism. As of July 2026 the paper covers both sides of the market, offensive and defensive, because AI has now visibly repriced one of them.
What actually happened to vulnerability prices between January 2025 and July 2026. Prices fell where machines now compete and rose where they still cannot go, while the exploit brokers showed no response to AI at all. Six rival explanations argued at full strength, plus what would falsify the thesis.
The full argument, rebuilt for reading. Opens with the four pricing objects, surfaces the eight emergent themes, and treats every forward-leaning claim as a falsifiable proposition with a supporting and a detracting data point.
Pick a pricing object × target × buyer, tune the five forces, toggle AI / geopolitics / provenance, and read the bracketed range. Includes Validation Mode scored against the confirmed-price corpus.
The argument condensed into an idea-card format.
The original decision-tree framework: what counts as a bug, who buys it, how the market clears.
First refinement of the 2022 framework.
Second refinement of the 2022 framework.
The model's algorithm is stress-tested against a machine-readable corpus of confirmed prices, each row carrying a live source link and a third-party archive snapshot. Three data files, kept deliberately separate because they hold different classes of evidence: confirmed offensive transactions, published defensive offers, and a fixed-universe sample that reports what did not change.