What is a zero-day, and why do companies pay hackers to find bugs?
A flaw that its maker does not know about can sell for millions, and the vendor itself may offer only a bounty.
▶ Start the storyA zero-day is a security hole in software that nobody who could fix it knows about. The name comes from the old counting of days since release: "zero-day software" was obtained by hacking a developer's computer before the public could get it, and the term moved on to the flaws behind that hacking and to the number of days a vendor has had to fix them. Virtually all products contain bugs. A bug that creates a security risk is a vulnerability, and the most dangerous let an attacker run their own code without the user being aware.
Zero-days are dangerous because there is no patch: all systems with the flaw are at risk, even banks and governments with every patch up to date. Yet they are not the usual way in. It is likely that most cyberattacks use known vulnerabilities, not zero-days. They are mainly used by governments, because finding or buying one, and writing the attack software, is costly.
That cost makes a market. Zero-day exploits can fetch millions of dollars, and there are three main kinds of buyers: "white" ones like the vendor, "gray" ones like government and intelligence agencies, and "black" ones in organized crime. The trade tends to be secretive: if the vulnerability becomes known, it can be patched and its value crashes.
Vendor bounty (white market)
- Fix the flaw
- Recognition and money
- Estimated at least ten times smaller than the other two
Governments and criminals
- Use or stockpile it
- Can fetch millions
- Secret: public means patched
The vendor's alternative is the bug bounty: a deal offering recognition and money to people who report security bugs. In 1983 a company offered a Volkswagen Beetle for bugs in its operating system, and Netscape ran a bounty in 1995. The catch is that hackers could earn much more selling a bug to brokers, spyware firms or governments, so a bounty often competes with a far richer market.
Quiz me
0/3
Recap
A zero-day is worth money only while it stays secret: once known, it can be patched and its value crashes.
💡 A trick to remember it · Zero days to fix means zero patch; a bounty is a price tag set against the secret market.
Surprising fact · Zero-day exploits can sell for millions of dollars.
Connects to
- ☢️ How did a computer worm wreck uranium centrifuges?
- 💔 How did one bug put much of the internet at risk, from Heartbleed to Log4Shell?
- 🪱 How did one student's experiment slow down the early internet?
- ⚖️ Should governments tell vendors about the flaws they find, or keep them for spying?
- 🦋 Was the first computer bug really a moth?
Sources (2)
No source, no claim. Every fact in this lesson (16 claims) cites at least one of these.