Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Do you have firsthand or even secondhand knowledge of a market for account takeover bugs where the buyers are monetizing those bugs via celebrity dirt? Do you have knowledge of markets for account takeover where buyers are directly monetizing those bugs at all?

I'm not asking if you can hypothesize such a market. I'm asking if you know about one actually existing.

It's been suggested to me that there is in fact at least one set of buyers for account takeover bugs. But they aren't monetizing those accounts.



If they aren't monetizing them, can you be more specific about what these hypothetical exploit buyers are doing with the pwned accounts?


I don't, but I strongly suspect they exist. While it's not my MO, I am quite certain that a blackhat-hacker with an exploit that enables them to compromise anyone's personal account would have the idea to target wealthy/famous people for personal gain. I also don't think it's beyond reason to think they could generate more than $50,000 through malicious means. Doing it without getting caught would be the challenging part, I guess.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: