Vulnerability Economics

What is a bug worth?

A multi-edition exploration of how the market for software vulnerabilities actually clears: what counts as a bug, who buys it, and how its price is set. The 2026 model is stress-tested against a corpus of ~150 confirmed historical exploit and surveillance-product transactions drawn from court records, leaked invoices, government disclosures, and journalism. As of July 2026 the paper covers both sides of the market, offensive and defensive, because AI has now visibly repriced one of them.

New
2026 AI Repricing Edition
July 28

What actually happened to vulnerability prices between January 2025 and July 2026. Prices fell where machines now compete and rose where they still cannot go, while the exploit brokers showed no response to AI at all. Six rival explanations argued at full strength, plus what would falsify the thesis.

2026-ai-repricing-edition.html
Start here
2026 Evidence Edition
★ THE PAPER

The full argument, rebuilt for reading. Opens with the four pricing objects, surfaces the eight emergent themes, and treats every forward-leaning claim as a falsifiable proposition with a supporting and a detracting data point.

Defect Primitive Chain Access
2026 — Interactive Model
Calculator

Pick a pricing object × target × buyer, tune the five forces, toggle AI / geopolitics / provenance, and read the bracketed range. Includes Validation Mode scored against the confirmed-price corpus.

Editions
The validity layer

The model's algorithm is stress-tested against a machine-readable corpus of confirmed prices, each row carrying a live source link and a third-party archive snapshot. Three data files, kept deliberately separate because they hold different classes of evidence: confirmed offensive transactions, published defensive offers, and a fixed-universe sample that reports what did not change.

Research corpus synthesis Validity stress-test confirmed-prices-2026-04.json bounty-repricing-2026.json bounty-universe-sample.json