What is a bug worth?
A multi-edition exploration of how the market for software vulnerabilities actually clears: what counts as a bug, who buys it, and how its price is set. The 2026 model is stress-tested against a corpus of ~150 confirmed historical exploit and surveillance-product transactions drawn from court records, leaked invoices, government disclosures, and journalism. The September update tests what happened when frontier cyber capability moved faster than the public price surface.
The wall moved. The market didn't. Frontier systems crossed capability boundaries the July edition treated as unproven, but public chain prices stayed put. The scarce object is now trusted access to the system that can build the chain.
The full argument, rebuilt for reading. Opens with the four pricing objects, surfaces the eight emergent themes, and treats every forward-leaning claim as a falsifiable proposition with a supporting and a detracting data point.
Pick a pricing object × target × buyer, tune the five forces, toggle AI / geopolitics / provenance, and read the bracketed range. Includes Validation Mode scored against the confirmed-price corpus.
The original AI repricing pass: what moved between January 2025 and July 2026, six rival explanations, and six explicit falsifiers.
The argument condensed into an idea-card format.
The original decision-tree framework: what counts as a bug, who buys it, how the market clears.
First refinement of the 2022 framework.
Second refinement of the 2022 framework.
The model's algorithm is stress-tested against a machine-readable corpus of confirmed prices, each row carrying a live source link and a third-party archive snapshot. Three data files, kept deliberately separate because they hold different classes of evidence: confirmed offensive transactions, published defensive offers, and a fixed-universe sample that reports what did not change.