Cybersecurity Startup Dangles Millions for Zero-Day Exploits, Led by Convicted Felons and Conspiracy Theorists

A burgeoning cybersecurity startup, IRIS C2, is actively soliciting the acquisition of zero-day security vulnerabilities in popular software, offering potential payouts reaching millions of dollars. However, a deeper investigation into the company’s leadership reveals a troubling association with individuals known for far-right conspiracy theories and a history of felony convictions. The founders’ recent ventures include defunct fake intelligence companies and an AI-driven lobbying platform operated under assumed identities, raising significant concerns about the integrity and motives behind IRIS C2’s operations.
IRIS C2’s Ambitious Pursuit of Vulnerabilities
The entity known as IRIS C2 has rapidly gained traction in the cybersecurity landscape since its inception in January 2025, evidenced by its X/Twitter account, @C2IRIS, which has amassed over 4,000 followers. The account consistently publishes content related to security vulnerabilities, artificial intelligence, and software exploits. IRIS C2 positions itself as a company based in McLean, Virginia, specializing in the sale of offensive cybersecurity capabilities.
A prominently pinned post on the @C2IRIS X account outlines the company’s recruitment strategy: "Our business model is this: Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience." This approach suggests a focus on raw talent over traditional qualifications, potentially drawing in individuals with exceptional technical skills but perhaps less conventional backgrounds.
The company’s website, irisc2[.]com, corroborates this recruitment drive, listing numerous open positions. A recent LinkedIn post from IRIS C2 highlighted an overwhelming response to their hiring efforts, indicating a significant influx of applications. The website explicitly states the company’s mission: acquiring "zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms. Payouts range from $10,000 to $7 million depending on target, reliability, and operational value." This ambitious pricing structure signals a high-stakes game in the exploit acquisition market, where the value of a vulnerability is directly tied to its potential impact and the cost to neutralize or exploit it.
Unearthing the Corporate Structure and Leadership
Government contracting portal g2exchange.com identifies irisc2[.]com as being operated by Calvexa Group LLC, a Virginia-based entity. The "contact" link on Calvexa Group’s website, calvexagroup[.]com, redirects visitors to irisc2[.]com, further intertwining the two entities. While G2Exchange indicates Calvexa Group LLC is registered as a federal contractor, there is no public record of it currently engaged in direct government contracts.

Publicly available incorporation records for Calvexa Group LLC list an Arlington, Virginia address. This address is associated with Jack Burkman, a 60-year-old individual identified as the founder and managing partner of the lobbying firm Burkman & Associates. When questioned about IRIS C2, Burkman deferred inquiries to his long-time associate, 28-year-old Jacob Wohl.
A Troubled History of Deception and Criminal Convictions
The association of Burkman and Wohl with IRIS C2 is particularly concerning given their documented history. Both individuals have been involved in the creation of fabricated intelligence firms used to disseminate false information and frame public figures. Their past activities include fabricating sexual assault allegations against former FBI Director Robert Mueller and Pete Buttigieg, who was then the mayor of South Bend, Indiana, and a Democratic presidential candidate. In 2019, Burkman and Wohl held press conferences making unsubstantiated claims of extramarital affairs involving Senator Elizabeth Warren (D-Mass.) and Kamala Harris, a leading Democratic contender for the presidency in the 2020 election cycle.
The aftermath of the 2020 U.S. presidential election saw Wohl and Burkman facing prosecution by multiple states for orchestrating robocall campaigns. These campaigns targeted residents of battleground states with misleading information about mail-in ballots, aiming to suppress voter turnout. They were indicted in Cleveland on 15 felony counts for their role in a robocall scheme allegedly designed to disenfranchise Black voters in Detroit. In late 2025, following the rejection of their appeals to dismiss the charges, they were sentenced to probation.
Further legal entanglements include a guilty plea by both Wohl and Burkman in 2022 to a single felony charge of telecommunications fraud in Ohio. This plea resulted in a sentence of a fine, probation, and community service. In March 2023, a New York civil court judge ruled that Wohl and Burkman had contravened federal and state civil rights laws, leading to a $1 million settlement agreement.
Adding to their legal troubles, the Federal Communications Commission (FCC) imposed a $5.1 million fine against Wohl and Burkman in June 2023 for their robocall activities. At the time, this represented the largest fine ever sought by the FCC under the Telephone Consumer Protection Act, underscoring the significant regulatory scrutiny their actions attracted.
Jacob Wohl’s entrepreneurial endeavors began at a young age, with multiple investment firms launched by the age of 17. He gained notoriety as "Wohl of Wall Street" after appearing on Fox News in 2015 to discuss his hedge funds. However, this early success was overshadowed by legal issues. In 2017, the Arizona Corporation Commission charged Wohl and his investment funds with 14 counts of securities fraud, ordering him to pay $35,000 in restitution. In 2019, Wohl pleaded guilty in California to four felony counts of selling unregistered securities, receiving a two-year probation sentence.
The Murky World of Exploit Brokering

The market for previously undisclosed software vulnerabilities, commonly known as zero-day exploits, has historically attracted a diverse range of actors. This ecosystem includes legitimate researchers, academics, cybersecurity professionals, but also individuals with less transparent intentions, including those involved in cybercriminal activities. While many government contractors engage in recruiting vulnerability researchers and purchasing exclusive rights to novel exploits, IRIS C2’s approach is notably more overt and less discreet.
KrebsOnSecurity first became aware of IRIS C2 last month, after an attendee at a regional cybersecurity conference reported that Wohl and Calvexa Group were actively soliciting vulnerability research from conference participants.
IRIS C2’s Strategic Pivot and Wohl’s Self-Proclaimed Expertise
In an interview with KrebsOnSecurity, Jacob Wohl stated that Jack Burkman is not involved in the day-to-day operations of IRIS C2. Wohl elaborated that the company initially focused on penetration testing services but has recently shifted its emphasis to providing phone-hacking services to government clients. Throughout the interview, Wohl repeatedly alluded to working on federal government contracts but declined to provide specific details, citing confidentiality agreements.
Wohl admitted to lacking formal education or training in computer science or information security, asserting that his expertise is largely self-taught. He confidently stated, "I know more about tech than anyone. My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin."
He further described the company’s intake process for vulnerability research: "Security researchers bring the company unique vulnerability findings on a regular basis, but that in many cases those findings are preliminary and not fully fleshed-out." Wohl provided an example: "Let’s say someone finds a flaw in a media decoder on a phone. A lot of times what we receive is an exploit primitive, where the idea is there but the [execution] needs work. You need that exploit to be stable and reliable, and that’s what we do." This suggests IRIS C2’s role might involve refining raw vulnerability findings into functional exploits.
Wohl claims IRIS C2 employs approximately 40 individuals, though he stated none are permitted to list their employment on LinkedIn due to operational security concerns. This lack of transparency extends to the employees themselves, who may be unaware of Wohl’s history of fabrications or even his true identity.
Operating Under Pseudonyms: The LobbyMatic Precedent

IRIS C2’s operational opacity is consistent with past practices of its leadership. In September 2024, Politico reported that Burkman and Wohl were promoting their now-defunct company, LobbyMatic, which claimed to leverage artificial intelligence for political lobbying. However, Politico discovered that the pair operated LobbyMatic using pseudonyms, with Wohl reportedly adopting the name "Jay Klein" and Burkman using the moniker "Bill Sanders." Politico’s report indicated that several former LobbyMatic employees resigned upon discovering their employers’ true identities, while others only learned of the deception after their departure.
Allegations of Legal Representation for Cryptocurrency Fraudster
An update to this reporting highlighted a March 31 publication by journalist Molly White, which revealed that Burkman and Wohl allegedly received a $300,000 retainer from a Canadian cryptocurrency fraudster sought by the United States and other countries. This individual is accused of stealing $65 million from cryptocurrency platforms KyberSwap and Indexed Finance. According to White’s report, Burkman and Wohl were engaged to pursue a "presidential pardon to avert a miscarriage of justice" on behalf of the accused hacker, who had not yet been convicted at the time of the report. This revelation further deepens the ethical and legal questions surrounding the duo’s involvement in high-stakes transactions and their pursuit of influence.
Implications for the Cybersecurity Ecosystem
The emergence of IRIS C2, led by individuals with a history of deception and criminal convictions, raises significant concerns for the cybersecurity industry and governmental bodies. The active solicitation of zero-day exploits, particularly from a company with such a background, could potentially place powerful and dangerous tools in the hands of actors with questionable intentions.
The lucrative market for zero-day exploits, while necessary for national security and defensive cybersecurity research, is a double-edged sword. When coupled with entities that have a proven track record of spreading disinformation and engaging in fraudulent activities, the risks are amplified. The ability of IRIS C2 to attract talent and potentially secure government contracts, despite its leadership’s history, highlights potential gaps in vetting processes within the defense contracting ecosystem.
The broad implications extend to the trust placed in cybersecurity vendors and the security of critical infrastructure. The active recruitment of vulnerability researchers by IRIS C2, coupled with their opaque operational structure and the founders’ past, necessitates a thorough and ongoing examination by regulatory bodies and intelligence agencies to ensure that the pursuit of offensive cybersecurity capabilities does not inadvertently compromise national security or facilitate illicit activities. The company’s stated aim of acquiring "offensive cybersecurity capabilities" and its high payouts for exploits suggest a business model focused on developing or acquiring tools that could be used for surveillance, disruption, or espionage, making scrutiny of their clients and end-users paramount.







