Zerodium

Zerodium is an American information security company. The company was founded in 2015 with operations in Washington, D.C., and Europe. The company develops and acquires zero-day exploits from security researchers.

History
Zerodium was launched on July 25, 2015 the founders of by Vupen. The company pays bounties for zero-day exploits. A zero-day exploit is a cybersecurity attack that targets security flaws in computer hardware, software or firmware in order to maliciously plant malware, steal data, or damage the program. Bug bounty programs, including Zerodium, pay bounties for knowledge of these security flaws.

Zerodium was the first company to release a full pricing chart for zero-days, ranging from $5,000 to $1,500,000 per exploit. The company was reported to have spent between $400,000 to $600,000 per month for vulnerability acquisitions in 2015.

In 2016, the company increased its permanent bug bounty for iOS exploits to $1,500,000.

Fast-forward to September 2019, Zerodium increased its bounty for Android exploits to $2,500,000, and for the first time, the company is paying more for Android exploits than iOS. Payouts for WhatsApp and iMessage have also been increased. The company is now reportedly spending between $1,000,000 to $3,000,000 each month for vulnerability acquisitions.

Criticism
Reporters Without Borders criticized Zerodium for selling information on exploits used to spy on journalists to foreign governments.