A Cybersecurity Startup Offering Millions for Zero-Day Exploits Linked to Far-Right Conspiracy Theorists and Convicted Felons

A nascent cybersecurity firm, IRIS C2, is actively seeking to acquire high-value zero-day vulnerabilities in popular software, dangling the prospect of seven-figure payouts. However, an investigation has revealed that the company is allegedly run by individuals with a documented history of promoting far-right conspiracy theories, operating under assumed names, and accumulating multiple felony convictions. This revelation raises significant questions about the security and ethical implications of such an enterprise, particularly given its stated interest in offensive cybersecurity capabilities and potential dealings with government entities.
IRIS C2, which has garnered over 4,000 followers on the social media platform X (formerly Twitter) since its inception in January 2025, presents itself as a company based in McLean, Virginia, specializing in the sale of offensive cybersecurity tools and information. Its X account, @C2IRIS, frequently disseminates content related to security vulnerabilities, artificial intelligence, and software exploits. A pinned post on their X profile explicitly outlines their recruitment strategy: "Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience." This approach suggests a focus on raw technical aptitude over traditional credentials, potentially appealing to a demographic of independent researchers.
IRIS C2’s Business Model and Affiliations
The company’s official website, irisc2[.]com, echoes this recruitment drive, listing numerous open positions and boasting about a significant influx of applications, as noted on their LinkedIn page. The website boldly advertises its core business: the acquisition of "zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms. Payouts range from $10,000 to $7 million depending on target, reliability, and operational value." This tiered pricing structure, with the highest valuations reserved for the most impactful and reliable exploits, highlights the lucrative nature of the zero-day market.
Further investigation into IRIS C2’s corporate structure reveals a link to Calvexa Group LLC, a Virginia-based entity that operates the irisc2[.]com website. Government contracting portals, such as g2exchange.com, confirm this affiliation. While Calvexa Group LLC is registered as a federal contractor, public records do not indicate any active direct government contracts. The "contact" link on the Calvexa Group website, calvexagroup[.]com, redirects directly to irisc2[.]com, reinforcing the close operational ties between the two entities.
The Unfolding Association with Jack Burkman and Jacob Wohl
The registered address for Calvexa Group LLC in Arlington, Virginia, is linked to Jack Burkman, a 60-year-old figure known for his conservative political activism and founder of the lobbying firm Burkman & Associates. When questioned about IRIS C2, Burkman deferred inquiries to his longtime associate, 28-year-old Jacob Wohl.

Burkman and Wohl share a well-documented and controversial past, characterized by the creation of fictitious intelligence firms and the dissemination of disinformation. Their previous activities include fabricating sexual assault allegations against prominent figures such as former FBI Director Robert Mueller and Pete Buttigieg, then Mayor of South Bend, Indiana, and a Democratic presidential candidate. In 2019, Burkman and Wohl held press conferences that falsely accused Senator Elizabeth Warren (D-Mass.) and Kamala Harris, then a 2020 presidential candidate, of extramarital affairs.
A Pattern of Legal Troubles and Disinformation Campaigns
The legal entanglements of Burkman and Wohl escalated significantly following the 2020 presidential election. They faced prosecution in multiple U.S. states for orchestrating thousands of robocalls targeting residents in battleground states, spreading false information about mail-in ballots. In Cleveland, they were indicted on 15 felony counts related to a robocall scheme designed to suppress the Black vote in Detroit. In late 2025, after their appeals to dismiss the charges were rejected, they were sentenced to probation.
Further legal repercussions followed. In 2022, both Wohl and Burkman pleaded guilty to a single felony charge of telecommunications fraud in Ohio, receiving a fine, probation, and community service. A New York civil court judge ruled in March 2023 that Wohl and Burkman had violated federal and state civil rights laws, leading to a $1 million settlement.
The Federal Communications Commission (FCC) also took action, imposing a $5.1 million fine against Wohl and Burkman in June 2023 for their extensive robocall campaigns. At the time, this represented the largest fine ever sought by the FCC under the Telephone Consumer Protection Act, underscoring the severity of their actions.
Wohl’s Early Ventures and Securities Fraud Allegations
Jacob Wohl’s entrepreneurial journey began at a remarkably young age. By 17, he had founded multiple investment firms, earning the moniker "Wohl of Wall Street" after appearing on Fox News in 2015 to discuss his hedge funds. However, this early success was overshadowed by legal challenges. In 2017, the Arizona Corporation Commission charged Wohl and his investment funds with 14 counts of securities fraud, ultimately ordering him to pay $35,000 in restitution. In 2019, Wohl pleaded guilty in California to four felony counts of selling unregistered securities, resulting in a two-year probation sentence.
The Zero-Day Market: A Complex Ecosystem
The market for previously unknown software vulnerabilities, often referred to as zero-day exploits, has historically attracted a diverse range of actors. This ecosystem includes legitimate security researchers, academics, but also individuals with questionable intentions, charlatans, and those actively involved in cybercrime. While many government contractors engage in recruiting vulnerability researchers and acquiring novel software exploits, their operations are typically conducted with a higher degree of discretion than IRIS C2’s overtly public approach.

KrebsOnSecurity first became aware of IRIS C2 last month, following reports from an attendee at a regional cybersecurity conference who observed Wohl and representatives from Calvexa Group actively soliciting vulnerability research from attendees.
Wohl’s Perspective and Claims
In an interview with KrebsOnSecurity, Jacob Wohl stated that Jack Burkman is not involved in the daily operations of IRIS C2. Wohl characterized IRIS C2’s initial focus as penetration testing, but indicated a recent shift towards providing phone-hacking services to the government. He repeatedly alluded to working on federal government contracts but declined to provide specific details, citing confidentiality.
Wohl admitted to lacking formal education or training in computer science or information security, asserting that his expertise is largely self-taught. He confidently stated, "I know more about tech than anyone," and described his background as "extremely technical" and his ability to create "spectacularly exquisite capabilities that would make your head spin."
He further explained that security researchers regularly submit vulnerability findings to IRIS C2. However, Wohl noted that many of these submissions are preliminary, often consisting of "exploit primitives" where the core concept exists but the execution requires refinement. IRIS C2’s role, according to Wohl, is to "make that exploit stable and reliable."
Wohl claims IRIS C2 employs approximately 40 individuals, though he stated they are not permitted to list their employment on LinkedIn for "operational security reasons." This secrecy, coupled with Wohl’s history of using pseudonyms, raises concerns about transparency and accountability within the organization.
The Use of Pseudonyms in Past Ventures
Further complicating the narrative, Politico reported in September 2024 that Burkman and Wohl were associated with LobbyMatic, a now-defunct company that claimed to leverage artificial intelligence for political lobbying. Politico’s investigation revealed that Burkman and Wohl operated LobbyMatic under pseudonyms, with Wohl reportedly using "Jay Klein" and Burkman adopting the moniker "Bill Sanders." According to the report, some former LobbyMatic employees resigned upon discovering their true identities, while others only learned of the deception after their departure.

Financial Ties to Cryptocurrency Fraud Suspect
An update from July 9th highlighted a significant financial connection reported by journalist Molly White. According to White’s March 31st publication, Burkman and Wohl received a $300,000 retainer from a Canadian cryptocurrency fraudster who is wanted by the United States and other countries for allegedly stealing $65 million from crypto platforms KyberSwap and Indexed Finance. The report indicated that Burkman and Wohl were retained to pursue a "presidential pardon to avert a miscarriage of justice" on behalf of the accused hacker, who had not yet been convicted at the time of that report.
Broader Implications and Regulatory Scrutiny
The emergence of IRIS C2, led by individuals with such a contentious background, within the high-stakes zero-day acquisition market raises several critical implications. Firstly, it underscores the persistent challenges in regulating the cybersecurity industry, particularly concerning the acquisition and potential misuse of powerful offensive tools. The lucrative nature of zero-day exploits attracts a wide spectrum of actors, and the line between legitimate security research and potentially illicit activities can become blurred.
Secondly, the alleged involvement of Burkman and Wohl with IRIS C2 suggests a potential avenue for individuals with a history of engaging in disinformation and fraudulent activities to gain access to sophisticated cybersecurity capabilities. The government’s reliance on external contractors for offensive cybersecurity tools necessitates rigorous vetting processes to ensure that such capabilities do not fall into the wrong hands or are used for malicious purposes.
The transparency (or lack thereof) surrounding IRIS C2’s operations, including its claim of government contracts and its employees’ anonymity, warrants further scrutiny. The cybersecurity landscape is constantly evolving, and entities operating within it, especially those with ties to controversial figures, must be subject to robust oversight to maintain trust and national security. The potential for vulnerabilities acquired by IRIS C2 to be exploited by state-sponsored actors or criminal organizations, given the founders’ past methodologies, remains a significant concern. Regulatory bodies and intelligence agencies will likely be monitoring IRIS C2’s activities closely in the coming months.






