7/20/2026 at 11:47:23 AM
There is no evidence that $500k has been paid or would be paid for an exploit like this one.Given that the article says that prompts are modified like they are holy scripture, perhaps sell the prompt for $500k.
The author works for https://www.assetnote.io/ , which has AI products for automated scanning.
by Zsfe510asG
7/20/2026 at 12:09:24 PM
Likely referencing https://www.crowdfense.com/exploit-acquisition-program/Zerodium used to offer up to 300k in 2021 https://www.securityweek.com/sites/default/files/images/Zero...
These brokers usually don't pay the bulk sum - they sell access to nation actors and you get payed out over time as long as the bug is not patched to discourage reselling and burning it. I doubt anyone would confirm if they got the full payment or not for something similar.
by kuroguro
7/20/2026 at 12:46:37 PM
I work in the field and I just cannot believe anyone would pay that much for a Word Press exploit. People pay money for iOS or Android because there is valuable information stored on devices running those operating systems. There's absolutely nothing of value on any Word Press site. The only possible reason I can think of is for a watering hole attack, but that would require a second exploit that would be worth far more (and they aren't).by bink
7/20/2026 at 1:26:34 PM
I currently work for a federal contractor including the DoD as their customer, using Wordpress as their main website. You would think there’s no sensitive information there, but some times all it takes is enough information about someone and their team to impersonate that person and gain access to an email thread, file sharing system or even an access card to a building. Never underestimate incompetence.by tedggh
7/20/2026 at 3:48:26 PM
And never underestimate the competence of others.by soulofmischief
7/20/2026 at 9:26:50 PM
lol, a big part of security is being smart enough to never challenge the bored…by kulahan
7/20/2026 at 6:02:53 PM
Bulk reply to all the people replying.bink is correct. The people who buy exploits are governments. There is very little interest in Wordpress or indeed any target that isn't a browser or a mobile. Browsers and mobiles are the only things that are perennially useful to an intelligence agency. Those two are reliable access vectors for the vast majority of things that interest government organisations.
by grugq
7/20/2026 at 8:14:07 PM
Are they only buying browser RCEs or are they also interested in RCEs deliverable via browser?ex: Target hits website -> site delivers RCE for some software that is on the target's system
by strictnein
7/20/2026 at 7:56:38 PM
Aren’t WP exploits valuable for watering hole attacks?by dcrazy
7/20/2026 at 8:09:21 PM
You don't need an RCE for that though. There's a lot of vulnerable plugins deployed everywhere.by strictnein
7/20/2026 at 9:54:02 PM
Ok, but an RCE in WP Core still seems pretty dang valuable, especially if you want to hit non-commercial websites that are less likely to have as many plugins installed?by dcrazy
7/20/2026 at 8:48:15 PM
You already owned the WordPress admin with your browser 0day, you don’t care if WordPress is secure or not.by illliillll
7/20/2026 at 6:44:57 PM
> There is very little interest in WordpressI'd disagree here. Still 41% of all sites use Wordpress [1]... and that means a lot of targets, and a lot of ways to target them. Your good ole' deface/ransomware extortion scheme, leaking data supposed to be confidential (such as account lists), trusted spreaders for exploits, or the latest hit, bets on "prediction markets" that have some Wordpress site set as oracle. People are willing to screw around with airport weather stations to manipulate bets [2], it's not that much of a stretch to assume such incentives would also apply for website hackers.
[1] https://www.wpzoom.com/blog/wordpress-statistics/
[2] https://edition.cnn.com/2026/04/23/europe/france-weather-sen...
by mschuster91
7/20/2026 at 8:15:57 PM
Plenty of underground forums sell exploits for people to do stuff like that, but you're talking $200, not a theoretical $500k.You also don't need an RCE for 99% of that.
by strictnein
7/21/2026 at 5:23:55 PM
This is an axiomatic response to an empirical argument.by tptacek
7/20/2026 at 5:45:52 PM
Remember the Panama papers? That was a Wordpress hack.by JSR_FDED
7/20/2026 at 9:39:05 PM
Compromising a crappy wordpress site means compromising mailbox credentials.by technion
7/20/2026 at 2:06:29 PM
Surprising amount of gov use WP as a CMS on their websites. So it's not that far off.by marysol5
7/20/2026 at 6:03:50 PM
> There's absolutely nothing of value on any Word Press siteThis is just 100% an incorrect assumption. Even just an e-commerce site running Woo has troves of potentially valuable customer data. Not to mention whatever else might be on the server, or what that server is connected to...
by foco_tubi
7/20/2026 at 7:35:30 PM
>There's absolutely nothing of value on any Word Press site.I would hope not, but I’d be surprised if that were true across the millions(?) of Wordpress sites?
by apercu
7/20/2026 at 3:19:41 PM
There’s a server running behind a Wordpress site. If you have RCE, you can run whatever arbitrary code you like there - mine crypto, run a botnet, all sorts of fun and profitable stuff. Hey, you can even make the site make the site’s users your unwitting hosts, too. You don’t go hack a Wordpress site, you go grab a few hundred thousand of them and do industrial scale crimes.by madaxe_again
7/20/2026 at 12:24:37 PM
[flagged]by tptacek
7/20/2026 at 2:37:23 PM
Is there anywhere currently buying that you can approach without a pre-existing relationship?by intheitmines
7/20/2026 at 12:33:28 PM
Of course it is. It just no longer exists.by StrauXX
7/20/2026 at 12:37:54 PM
Oh, you've done business with them then? Know someone who has?by tptacek
7/20/2026 at 12:57:18 PM
Yes actually, I know someone who did business with them many years ago (before the advent of LLMs), although for a smaller sum than the advertised top payouts (the vulnerability they had was much less important).Why post these random unsubstantiated claims on HN?
by cmeacham98
7/20/2026 at 3:31:38 PM
> Why post these random unsubstantiated claims on HN?To show everyone the Gell-Mann amnesia effect in action.
When HN top karma poster and security professional posts something like this, doubles down, and can’t even be bothered to support it in any way (I’m open to learning and changing my opinion) it completely blurs the line going into social media influencer. Quantity over quality.
by close04
7/20/2026 at 11:27:29 PM
Yes, I have briefly done business with them as well. We also worked with Bekrar and Vupen briefly. Albeit, it was done through a broker. The second time around, we exited negotiations.Just because they're exclusive about their clients doesn't mean they're not real. Their impact and effectiveness is a separate topic though. I don't think they're still actively operating or taking new clients, at least.
btw: "Oh, so you've done x?" What a snarky and confrontational way to ask someone something. Especially when it's asserting a well documented company and person is "not real".
by parl_match
7/21/2026 at 3:15:38 AM
[flagged]by tptacek
7/21/2026 at 1:51:24 PM
Why are you constantly responding to people like this? What makes you think you’re above the rest of HN?by ofjcihen
7/21/2026 at 4:07:19 PM
You apparently work in the field. Do you take these "price lists" seriously?by tptacek
7/21/2026 at 4:15:06 PM
They can be and they can not be depending on what you’re selling.But that’s besides the point. You straight up argued that one isn’t real in the most asinine way you could.
Even if you were right that would be ridiculous. The fact that you’re wrong and have multiple people telling you you are makes it even worse.
I’ve seen you replying in snide comments whenever someone disagrees with you before. Your status as…whatever you are doesn’t give you carte to treat randoms like they’re beneath you.
by ofjcihen
7/21/2026 at 5:03:57 PM
I'm noticing you didn't answer my question.by tptacek
7/21/2026 at 5:26:36 PM
I did explicitly answer your question, yes.This is how all of these sites work. You would not get 500k for every exploit obviously. You would get that (or more) for great exploits.
I’m noticing you haven’t addressed anything I mentioned at all. Is that just acceptance that it’s the truth or are you just having a bad day?
Edit: Actually, let me add that for a 0click exploit on mobile devices that leads to root level permissions you’re very likely sitting on millions of dollars.
by ofjcihen
7/21/2026 at 5:56:15 PM
This is 2 years old, but goes deep into the details of how the "0 click" market works, roughly what kind of money you'd be sitting on, and what it takes to actually get that money:https://securitycryptographywhatever.com/2024/06/24/mdowd/
It sounds like you're telling me you believe you might get six figures for a "great" WordPress core RCE. I believe that's false, and I believe that for reasons that probably indicate our premises are much too far apart to hash this out here.
I have open contempt for online price list "brokers" like Zerodium. I do not have contempt for other commenters here. I think it's important that you understand the distinction before coming at me the way you've been in this thread. Disagreeing with me, rebutting or refuting me, sharply or ungenerously: totally fine. Your weird psychoanalysis of me: not fine.
by tptacek
7/21/2026 at 6:27:29 PM
Absolutely not.> Did you get mid-high 5 figures for a serverside vulnerability? I hear the Russians are paying $300k for Postfix! But the UAE might pay $400k through Crowdfense. These numbers are definitely real. How could they not be? They're right there on a web page.<
> Oh, you've done business with them then? Know someone who has?<
You’re replies have been snide and rude and you trying to pivot and say “you were merely talking about the brokers” is further showing you don’t care and feel entitled to continue.
Other users are calling you out on this behavior here and on other threads as well to the point that the comment you made starting this has stayed flagged.
Deflecting from someone calling out this consistent behavior is frankly ridiculous in the face of the receipts, especially trying to villainize the people calling you out for it.
Also, not even the main point anymore, but you’ve intentionally mischaracterized every argument others have put forwards including in your most recent response. I was extremely explicit about what kind of exploit commands a high price and you’ve chosen to again twist the argument to your desired conclusion:
> It sounds like you're telling me you believe you might get six figures for a "great" WordPress core RCE<
My “psychoanalysis” was an attempt at giving you grace but you seem intent on proving that talking down to others and then trying to sidestep justified criticism are default behaviors that you’re entitled to.
by ofjcihen
7/21/2026 at 6:33:19 PM
[flagged]by tptacek
7/21/2026 at 6:50:58 PM
[flagged]by ofjcihen
7/20/2026 at 12:58:16 PM
I do, as a matter of fact.by StrauXX
7/20/2026 at 4:13:49 PM
My lawyer says I can't answer thatby monster_truck
7/20/2026 at 12:56:56 PM
[dead]by jnbcxdrun
7/20/2026 at 1:18:01 PM
Why would you reply with something completely unsubstantiated that anyone in security at that time worth their salt would be able to call you out on and then in subsequent comments call people liars for insisting it did, in fact, exist?I’m just baffled.
by ofjcihen
7/20/2026 at 5:38:50 PM
The pricelist was a marketing stunt.by dadrian
7/20/2026 at 12:34:46 PM
Why would anybody trust criminals to pay them over time?by Hizonner
7/20/2026 at 1:00:59 PM
Because if they don't other people will hear they don't pay and won't sell them 0daysby idiotsecant
7/20/2026 at 1:25:10 PM
How long do you figure a criminal reputation typically needs/wants to last? I have always been skeptical of “black market credit ratings”. If you happen to build one up, it’s likely only in order to rip someone off at a higher price and cash in the value of it. It’s not like you’ll need that good rep for your retirement.by nativeit
7/20/2026 at 1:53:28 PM
ShinyHunters has been "in business" since 2019 and it is their reputation that resulted in eg. Canvas paying their ransom this year. Without that reputation, it is unlikely a large-scale ransom would have been paid, because the reputation is what gives them credibility that paying the ransom will actually result in the promise being upheld.by applfanboysbgon
7/20/2026 at 4:12:49 PM
What do you think the venn diagram looks like for people willing and able to find things like that prior to LLMs and also sell them to a broker, and are also stupid enough to flaunt a massive flashing "arrest me!!!" signClosest you're going to get is something like those kids in florida who just got wrapped for putting malware into steam games and draining peoples accounts. They were going to get caught anyways but it would have taken a lot longer to build a case against them if they weren't flaunting it on socials
by monster_truck
7/20/2026 at 6:44:29 PM
Is this comment pure speculation, or do you have knowledge (or anecdotal evidence) of a similar exploit being sold for $500k?by nickff
7/20/2026 at 3:00:42 PM
"People paid $5,000 for a Macintosh computer when they were new. I found one at a yard sale for $25."by trollbridge
7/21/2026 at 2:11:16 AM
Pre-1990s Macs (Mac Plus, SE, etc.) in good condition are actually worth a decent amount nowadays as collectors items. Not $5000, but quite a bit more than $25.by sgerenser
7/20/2026 at 5:08:55 PM
this is the most accurate summary.by grugq
7/20/2026 at 6:16:35 PM
I actually found a 1999 iMac set out for a special rubbish pick up day. The owner of the house was there so I chatted a bit, asked her if she minded if I took it.It had last been booted on it, complete with working hard drive an; MacOS X 10.3. So $1.299 -> $0.
by trollbridge
7/20/2026 at 7:13:54 PM
That's just typical for computer hardware though. Depreciation is 3-5 years normally, after which it's considered worthless.by SoftTalker
7/21/2026 at 12:32:02 AM
Ok, we've taken $500k out of the title above.by dang
7/20/2026 at 1:22:36 PM
> modified like they are holy scriptureSo never modified at all, even if plainly contradictory and/or ethically and morally compromised?
by nativeit
7/20/2026 at 2:12:01 PM
[flagged]by stellamariesays
7/20/2026 at 12:31:09 PM
[dead]by T3RMINATED
7/20/2026 at 12:02:37 PM
[flagged]by functionmouse