A cybersecurity startup that claims to pay millions of dollars for zero-day vulnerabilities in widely used software is run by a pair of convicted felons and far-right conspiracy theorists whose prior ventures included fake intelligence firms and a now-defunct AI lobbying platform operated under assumed names. The company, IRIS C2, has attracted thousands of followers on X since its account was created in January 2025 by posting frequently about security vulnerabilities and software exploits. Its website openly offers payouts ranging from $10,000 to $7 million for exclusive access to zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms. According to business registration records, the company is operated by Calvexa Group LLC, a Virginia-based federal contractor registered to an address in Arlington that is occupied by Jack Burkman, a 60-year-old lobbyist who referred inquiries to his longtime associate, 28-year-old Jacob Wohl.
Who Are the People Behind IRIS C2?
Jack Burkman and Jacob Wohl have a long and well-documented history of operating fraudulent enterprises. In 2019, they held press conferences fabricating sexual assault allegations against then-FBI Director Robert Mueller and former South Bend Mayor Pete Buttigieg. They also made false claims about extramarital affairs involving Senator Elizabeth Warren and then-presidential candidate Kamala Harris. Following the 2020 election, they were prosecuted in multiple states for orchestrating a robocall scheme that targeted battleground states with false information about mail-in ballots. Sentenced in late 2025, they received probation after their appeals were rejected. In 2022, both pleaded guilty to a single felony count of telecommunications fraud in Ohio. A New York civil case in March 2023 found them in violation of federal and state civil rights laws, resulting in a $1 million settlement. The FCC imposed a $5.1 million fine against them in June 2023—the largest ever sought under the Telephone Consumer Protection Act at the time.
Wohl’s Background in Finance and Fraud
By the age of 17, Wohl had started multiple investment firms, earning the nickname “Wohl of Wall Street” after a 2015 appearance on Fox News. In 2017, the Arizona Corporation Commission charged him with 14 counts of securities fraud, ordering $35,000 in restitution. He pleaded guilty in California in 2019 to four felony counts of selling unregistered securities and was sentenced to two years of probation. Wohl has stated he has no formal education or training in computer science, claiming his technical knowledge is self-taught.
How IRIS C2 Markets and Operates
IRIS C2’s social media strategy is unusually aggressive for the offensive security market. Its pinned post explicitly states the company wants to attract “the very best vulnerability researchers and exploit developers in the world,” focusing on “junior engineers with raw talent/extremely high IQ.” The company claims to have approximately 40 employees, though Wohl has stated none are permitted to list their employment on LinkedIn for operational security reasons. Wohl said IRIS C2 originally began as a penetration testing firm but shifted its focus to selling phone-hacking services to the government. He mentioned working on federal government contracts but refused to provide specifics.
What Is a Zero-Day Exploit and Why Does It Command High Prices?
A zero-day exploit is a software vulnerability that is unknown to the vendor and has no patch available. Because attackers can use it to compromise systems with no warning or defense, such exploits are extremely valuable to both nation-state actors and cybercriminals. The market for zero-days is typically opaque, with government contractors recruiting researchers discreetly. IRIS C2’s open and brazen approach—publishing price lists and recruiting publicly on social media—is highly unusual for the industry. Security researchers have described the company’s pitch as aggressive and out of character for the legitimate vulnerability research community.
Previous Ventures Under False Names
In September 2024, Politico reported that Burkman and Wohl had been operating a company called LobbyMatic, which claimed to use artificial intelligence for political lobbying, under the pseudonyms “Jay Klein” and “Bill Sanders.” Two former employees resigned after learning the true identities of the company’s founders, while others only discovered the truth after leaving the company. The firm is now defunct. Wohl has used the alias “Jay” on his GitHub account, which lists projects related to security and software development.
What This Means for the Vulnerability Research Community
KrebsOnSecurity first learned of IRIS C2 after an attendee at a regional cybersecurity conference reported that Wohl and representatives of Calvexa Group were aggressively soliciting vulnerability researchers for their work. The offensive security market has always attracted a mix of legitimate researchers, academics, and occasional charlatans, but the involvement of individuals with extensive fraud convictions and a history of fabricating information raises significant red flags. Researchers considering selling their work to IRIS C2 should be aware that the company is operated by individuals who have engaged in identity deception, securities fraud, and telecommunications fraud. The promise of million-dollar payouts is unverified, and the company has provided no evidence of existing government contracts or legitimate customers.
What Vulnerability Researchers Should Do Before Selling Exploits
Researchers considering selling their work should conduct thorough due diligence on any potential buyer. Verify the company’s registration, ownership, and legal history through independent sources such as state business registries and government contracting portals. Ask for references from known and respected figures in the security community. Be wary of companies that cannot provide verifiable proof of their operational history or that require employees to conceal their employment. Consider engaging with established, reputable vulnerability brokerage firms that operate transparently and have a track record of ethical behavior. Using a reputable, no-log VPN service when communicating about sensitive vulnerabilities can help protect your identity and research from interception. A multi-layer endpoint protection solution on all devices used for vulnerability research is also strongly recommended. If you have already sold an exploit to an entity you now distrust, change any shared credentials immediately and monitor for signs of misuse. The safest course is to prioritize working with organizations that have a clear and verifiable reputation within the professional security research community.