Vulnerability Economics

What is a bug worth?

A multi-edition exploration of how the market for software vulnerabilities actually clears: what counts as a bug, who buys it, and how its price is set. The 2026 model is stress-tested against a corpus of ~150 confirmed historical exploit and surveillance-product transactions drawn from court records, leaked invoices, government disclosures, and journalism. The September update tests what happened when frontier cyber capability moved faster than the public price surface.

New
September 2026 Update
Sep 2

The wall moved. The market didn't. Frontier systems crossed capability boundaries the July edition treated as unproven, but public chain prices stayed put. The scarce object is now trusted access to the system that can build the chain.

2026-ai-repricing-september-update.html
Start here
2026 Evidence Edition
★ THE PAPER

The full argument, rebuilt for reading. Opens with the four pricing objects, surfaces the eight emergent themes, and treats every forward-leaning claim as a falsifiable proposition with a supporting and a detracting data point.

Defect Primitive Chain Access
2026 — Interactive Model
Calculator

Pick a pricing object × target × buyer, tune the five forces, toggle AI / geopolitics / provenance, and read the bracketed range. Includes Validation Mode scored against the confirmed-price corpus.

Editions
The validity layer

The model's algorithm is stress-tested against a machine-readable corpus of confirmed prices, each row carrying a live source link and a third-party archive snapshot. Three data files, kept deliberately separate because they hold different classes of evidence: confirmed offensive transactions, published defensive offers, and a fixed-universe sample that reports what did not change.

Research corpus synthesis Validity stress-test confirmed-prices-2026-04.json bounty-repricing-2026.json bounty-universe-sample.json September research synthesis september-2026-snapshot.json