A security exchange that rewards disclosure A developer has proposed a "security exchange" designed to realign the economics of vulnerability disclosure so that verified reporting pays better than exploitation. The proposal follows an audit in which a remotely reachable, pre-association memory-safety flaw in a widely shipped chip was fixed via a silent binary blob update with no CVE or advisory. The author argues that because vendors bear the cost of transparency while downstream integrators and users reap the benefits, protection is structurally underprovided. This article was originally published on my personal blog: https://fughil.li/blog/security-exchange/ The economics of finding security bugs are upside down. Clean disclosure routinely pays less than exploitation, resale, or reporting a flaw only after you’ve used it — and the vendors on the other side can quietly benefit from keeping weaknesses out of view. AI is about to make both attack and remediation dramatically faster. I’m working on whether we can align the money, the evidence, and the decision rights around that faster cycle, so that the protective move is also the profitable one. This isn’t a conclusion from years in the field; it’s what a single side quest made obvious. In a recent audit https://fughilli.substack.com/p/auditing-the-closed-esp32-c6-wi-fi , a remotely reachable, pre-association memory-safety bug in a widely shipped chip was fixed — and shipped as a silent binary blob bump, with no CVE and no advisory. Not because anyone acted in bad faith, but because the vendor bears the cost of transparency while its benefits land on downstream integrators and their users. When the party who pays for protection isn’t the party who needs it, protection gets underprovided. Look once and you see it everywhere: the apparatus we lean on to handle security disclosure is quietly, structurally inadequate. That’s an incentive problem, and incentive problems don’t yield to good intentions