The Economics of Vulnerability: Why the Same Bug Can Be Worth $1,500 or $1.5 Million

Picture three researchers, none of whom know each other, each holding a working exploit for a remote code execution flaw in a popular messaging app. The first sends it to the app's own bug bounty program and is quoted a reward in the low thousands. The second sells it to an American exploit broker for as much as $500,000. The third, in a different part of the world, gets offered $1.5 million for the same category of flaw by a broker with government clients who need it to stay unpatched, not fixed.

None of these three researchers found a different bug. The exploit is the same. The severity is the same. The only thing that moved was who was standing on the other side of the transaction. That is the part of vulnerability economics most security conversations skip past: a bug does not have a price. It has as many prices as there are buyers willing to pay for it, and which one a researcher chooses says a great deal about whether the legitimate path was ever made worth taking.


What Google Pays for a Bug That a Smaller Company Could Never Afford

In 2025, Google paid out $17.1 million across its Vulnerability Reward Program, spread across 747 researchers, with a single report earning as much as $250,000. Chrome findings alone accounted for over $3.7 million paid to 100 reporters, and the company's newer Cloud and AI-focused programs added millions more. Microsoft's numbers tell a similar story: over $20 million paid to 562 researchers across 64 countries between mid-2025 and mid-2026, with an average payout of roughly $35,586 per researcher and a top single reward of $200,000.

Those figures are not just impressive. They describe a scale that almost no organization outside a handful of trillion-dollar companies can realistically match. A critical remote code execution bug reported to Google or Microsoft can be worth a life-changing sum. The same class of bug reported to a mid-sized company running its first bounty program might be worth a few thousand dollars, not because the vulnerability matters less, but because the company sponsoring the program has a fundamentally different budget, risk profile, and researcher pool to draw from.

This is the first and most visible layer of vulnerability economics: price follows the size and priorities of whoever is paying, not the objective severity of the bug.


Severity Is Not the Same as Value

Before going further into who pays what, it is worth being precise about what "valuable" even means here, because it is not the same thing as "severe."

Most programs start from CVSS, the industry-standard scoring system that rates a vulnerability from 0 to 10 based on factors like how it is exploited, what privileges it requires, and how much damage it can do. CVSS is useful for communicating severity in a standardized way, but it was never designed to function as a payout calculator, and treating it like one causes more disputes in bug bounty programs than almost anything else. A vulnerability can score high on paper and still be worth relatively little in practice, and a lower-scoring bug can be worth far more, depending on a handful of practical questions: How reliably can the exploit be reproduced? Does it require authentication or a privileged account to trigger, or can anyone on the internet use it? How many users or systems does it actually touch? Is a mitigating control, like a firewall rule, already blocking it in the live environment even though it worked in a test setup? And critically, does the finding expose real, sensitive data, or does it expose a theoretical path to data that turns out to be masked, limited, or low-value?

One documented example makes the gap concrete: an insecure direct object reference exposing what looked like full credit card numbers scored a 7.1, a "high" severity rating, under CVSS. Once the program's reviewers noticed the card numbers were actually masked, limiting real exposure, they downgraded the finding to medium severity and cut the payout roughly in half. The technical severity score got the report taken seriously. The actual business impact is what set the price. That distinction, between severity and worth, is the foundation everything else in vulnerability economics is built on.


The Two Markets Bidding for the Same Bug

Zoom out from any single program's pricing table and a bigger structure comes into view. Researchers and policy analysts who study this space generally describe it as three overlapping markets rather than one. There is the white market: legitimate vendors and bug bounty platforms paying for disclosure, historically in the range of a few thousand to, at the high end, around $100,000 per finding. There is a gray market, made up of governments and specialized brokers who buy working exploits for intelligence and surveillance purposes, at prices reported to run ten to one hundred times higher than the white market, precisely because they are not paying for a fix. And there is a black market, where criminal buyers pay for unrestricted access to exploit at scale, with no relationship to the vendor at all.

Those three markets are not just priced differently. They want opposite outcomes. The white market wants the vulnerability found, confirmed, and closed. The gray and black markets both need it to stay open, because an exploit stops being useful the moment it gets patched. That is the real shape of the decision a researcher is making when they choose where to send a finding. It is not really a competition between one bug bounty program and another. It is a competition between the market that pays for disclosure and the market that pays for secrecy, and a legitimate program only wins that competition when it gives a researcher enough reason, in trust as well as money, to prefer the outcome where the bug actually gets fixed.


Following the Signal Exploit Back to Its Buyers

The scenario above is not hypothetical dressing. It is a close read of how the market for a single class of vulnerability, a working Signal-style messaging exploit, actually breaks down once you follow the money past the first offer.

A legitimate bug bounty program pays for the fix. It wants the vulnerability reported, validated, and closed, and it prices accordingly. A gray-market exploit broker pays for the opposite: continued access. These brokers, often based outside the country where a vulnerability's victims live, acquire working exploits and resell or license them to governments and intelligence services, and their pricing reflects demand from buyers who need the flaw to stay open, not fixed.

That is exactly the gap on record. Zerodium, an American exploit broker, has publicly priced Signal and similar messaging app exploits at up to $500,000 since 2017. A newer, Russia-based broker called OpZero reportedly offered three times that amount, $1.5 million, for a comparable Signal remote code execution exploit, a premium researchers attributed to intelligence services in the region urgently needing that specific capability. Across the gray market as a whole, exploit prices are reported to have grown by 1,240 percent over six years. No legitimate bug bounty program comes close to tracking that kind of inflation, because legitimate programs are not pricing against geopolitical urgency. They are pricing against a budget line.

A researcher choosing where to report a critical bug is not just weighing ethics against money in the abstract. They are looking at genuinely different numbers attached to genuinely different outcomes, and the gap between them is where legitimate disclosure programs either hold researcher trust or lose it.


When the Market Pays Less for More Bugs

Pricing does not only move upward. In 2026, HackerOne's Internet Bug Bounty program, which rewards researchers for finding vulnerabilities in widely used open source software, cut its payouts dramatically: critical vulnerability rewards fell from $9,250 to $2,257, a 76 percent reduction, and low-severity rewards dropped 89 percent, from $597 to $68. The program has since paused new submissions entirely while it reevaluates.

The stated reason was that reward levels adjust dynamically based on sponsor contributions, but researchers pointed to a more specific pressure: a flood of AI-generated vulnerability reports has made finding plausible-looking bugs dramatically cheaper to produce at volume, even when most of them are low-quality or duplicated. One researcher described the shift as finding plausible bugs becoming far cheaper to produce at scale, while the genuinely expensive part remains human: the judgment, verification, and real-world exploitation work that separates a genuine finding from AI-generated noise.

This matters for the same reason the Signal exploit gap matters. When a program's payouts collapse relative to what a hunter's time is actually worth, the researchers with the skill to find the bugs that matter do not stop finding them. They simply stop bringing them to that program.


Why the Price Signal Matters More Than It Looks

It is tempting to treat bounty pricing as a researcher-side concern, something that affects hunter income but not organizational security. That framing misses what the price actually signals, and it misses that "pay more" is not even the full lesson.

A bounty priced too low relative to a bug's real value does not make the bug less dangerous. It changes who ends up finding out about it first. Bugcrowd's own analysis notes that when reward levels fall out of step with the effort a target requires, researchers may simply take a comparable finding elsewhere, including to brokers with no obligation to protect the organization that owns the flawed system. But raising the number is not a complete fix either: one recent industry analysis found that when a program doubled its payouts, overall submission volume rose by only 20 percent, while critical vulnerability reports specifically tripled, a sign that money mainly changes which researchers bother to engage, not how many reports arrive.

What those engaged researchers weigh first is rarely the payout line. Practitioners who run mature programs describe trust as something that "lives and dies by responsiveness," tracked in time-to-triage and time-to-fix, and one CISO's assessment was blunt: researcher experience matters more than reward tables, and fast, human triage with respectful feedback matters more than the size of the check. Clarity of scope, response time, and triage quality function as a kind of currency alongside the actual payout, which is exactly where a professionally run program can compete even without a Silicon Valley budget: not by matching the dollar amount, but by removing every other reason a researcher might hesitate.


What This Means for Philippine and Southeast Asian Organizations

None of this means an organization needs to match Google's or Microsoft's budget to run a credible program. A Philippine mid-sized bank, a regional e-commerce platform, or a local government agency will never write a $250,000 check for a single bug, and that is not actually the competitive disadvantage it looks like. What a researcher deciding where to send a serious finding is weighing is not "how does this payout compare to Google's," a comparison no organization outside a handful of trillion-dollar companies can win. It is will this organization take my report seriously, fix the issue, and treat me fairly along the way.

A smaller organization's systems can still hold the financial records, personal data, or government services of millions of people, and a researcher who finds a flaw in one of them does not need Silicon Valley money to choose disclosure over silence. They need a credible, well-run path that respects their time and their finding. Secuna Hunt is built around exactly that model: a vetted hunter community, transparent scope, and a triage process that gets serious findings in front of your team quickly, so the value proposition is not the size of the check but the certainty that a good report gets a fair, fast response. For government agencies specifically, Secuna's government-focused Hunt program applies the same structure to public-sector systems, where budgets are tighter still but the stakes of an unreported vulnerability are just as high. Organizations that are not ready to run a continuous bounty program can still give researchers that same legitimate path through Secuna Response, a structured vulnerability disclosure program that costs nothing to run and closes the exact gap a gray-market broker is waiting to fill.

Getting the economics right locally is not about outbidding the black market. It is about making sure the honest path is clear, fair, and fast enough that a researcher never has to seriously weigh the alternative.


Conclusion

A vulnerability does not have one true price. It has as many prices as there are buyers willing to pay for it, and the gap between what a legitimate program offers and what a gray-market broker offers is where a researcher's decision actually gets made. Organizations that understand this treat their bounty pricing as a real, ongoing part of their security posture, not an afterthought bolted onto a program's terms page.

The organizations that pay attention to what a bug is actually worth are the ones that see it reported first.

Secuna Hunt helps organizations build a program researchers trust enough to choose, backed by fair scope, fast triage, and a structure suited to what your organization can sustain, not a number pulled from what a trillion-dollar company happens to be paying this year.

To learn more, reach out to our team at sales@secuna.io or explore our services at secuna.io.


Sources: Google Bug Bounty Payouts Reach Record $17 Million in 2025, Cybernews · Microsoft Bug Bounty Program: $20 Million Paid to 500+ Researchers, SecurityWeek · CVSS Scoring for Bounty Hunters: How Severity Ratings Affect Payouts, Bug Bounties · Market for Zero-Day Exploits, Wikipedia · New Exploit Broker on the Scene Pays Premium for Signal App Zero-Days, Dark Reading · HackerOne Takes an Axe to Its Bug Bounty Rewards, The Register · Why You Can't Ignore the Economics of a Bug Bounty, Bugcrowd · How to Get Better Results From Bug Bounty Programs Without Wasting Money, Help Net Security