Operation Zero
Operation Zero (OPZERO) is a Saint Petersburg, Russia-based brokerage that purchases zero-day vulnerabilities from independent researchers and resells them exclusively to vetted Russian private and government clients, operating across desktop, mobile, server, virtualization, router, and baseband target categories.
- Company typePrivate
- Founded2021
- HeadquartersSaint Petersburg, Russia
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Operation Zero does
Operation Zero (OPZERO) is a Saint Petersburg-headquartered brokerage that purchases zero-day vulnerabilities and offensive-security research output from independent information-security researchers and resells those exploits exclusively to vetted Russian private-sector and government clients. The company positions itself as the only official Russian platform for zero-day exploit acquisition and states it holds the regulatory permits required to operate in this segment domestically, which materially restricts competitive entry by foreign intermediaries into the Russian buyer pool.
The platform operates across six target categories — desktops/PCs, mobiles, servers, virtualization software, routers, and baseband chips — with a stated 2026 product-line focus on pre-authenticated remote code execution (RCE) in enterprise software. Transactions are conducted directly with vetted buyers via PGP-encrypted email; the platform itself does not appear to be a hosted marketplace UI but rather a vetted intermediary routing researcher output to approved Russian purchasers. Researchers retain intellectual property in their work and receive payment for the exploit, with bonuses paid to the original finder when the platform resells to its clients.
Operation Zero runs as a one-time-purchase broker rather than a subscription platform, with revenue mechanics tied per-exploit rather than per-seat. Public disclosures include a self-reported '0 USD capitalization' figure and a zero-ruble marketing budget through 2026, implying a bootstrapped, low-overhead operating model. Researcher compensation is reported at 450,000–900,000 rubles per month plus performance-linked bonuses, and the firm maintains an active multi-year presence at the OFFZONE and UnderConf security conferences for researcher and buyer outreach.
Operation Zero firmographics
Firmographics- Name
- Operation Zero
- Legal name
- Operation Zero
- Website
- https://opzero.ru
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Operation Zero (OPZERO) is a Saint Petersburg, Russia-based brokerage that purchases zero-day vulnerabilities from independent researchers and resells them exclusively to vetted Russian private and government clients, operating across desktop, mobile, server, virtualization, router, and baseband target categories.
- Ownership category
- akta.pro rank
Operation Zero industry classification
Industry- Product category
- Offensive Security / Vulnerability Research
- NAICS
- Computer Systems Design and Related Services (5415), Investigation and Security Services (5616)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Bug Bounty, Vulnerability Disclosure & Security Services (FSAPAJAL)
Keywords
Where Operation Zero is headquartered
LocationHeadquarters
- HQ city
- Saint Petersburg
- HQ country
- Russia
- HQ region
- Europe
Offices1 record
Markets served
Operation Zero business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Zero-Day Exploit Transactions: One-time purchase transactions where researchers sell their zero-day exploits to the platform, which then resells or licenses them to vetted Russian clients. Payments to researchers match international competitor standards.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Pay-as-you-go | Pre-authenticated RCE in enterprise software for initial access (Summer 2026 trend) |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels3 records
Operation Zero product offering
Product offeringCore offering
Operation Zero operates a zero-day vulnerability acquisition platform that purchases fully functional exploits from independent security researchers and provides them to vetted Russian private and government organizations. The platform covers six target categories — personal computers, mobile devices, servers, virtualization software, routers, and baseband chips — and manages the full acquisition lifecycle including researcher outreach, assessment, code verification (completed within one working week), and payment processing. Transactions are conducted via PGP-encrypted email with payments to researchers set to match international competitor standards.
Product overview
Operation Zero operates a unified zero-day vulnerability purchase platform that connects independent security researchers with Russian private and government organizations seeking offensive security capabilities. The core offering is a marketplace for acquiring fully functional, pre-authenticated RCE exploits across six target categories: Desktops/Personal Computers, Mobiles/Android, Servers, Virtualization Software, Routers, and Baseband/Cellular modems. The platform provides end-to-end services including researcher outreach, exploit verification, code review, and payment processing. Their 2026 focus areas include pre-authenticated RCE exploits in enterprise software for initial access, with requirements for default configuration compatibility, zero user interaction, execution under one minute, and near-100% reliability.
Differentiator
Problem solved
Functional benefit
Products and services
- Zero-Day Vulnerability Platform (Платформа уязвимостей нулевого дня)
Quantifiable outcome
- Exploit verification completed within one working week
- +1 more outcomes
Companies that use Operation Zero
Customer profileNamed customers2 records
Segments2 records
Ideal customer profiles2 records
Operation Zero technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature1 record
Operation Zero partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered minor and core.
- UnderConfminorOPERATION ZERO was partner/sponsor of UnderConf 2025, held September 28, 2025 at Quattro Space, Moscow.
- OFFZONE ConferencecoreOPERATION ZERO was sponsor and partner of OFFZONE 2025, held August 21-22 at Moscow GOELRO Hall, organized by BI.ZONE. Continued partnership with the annual cybersecurity conference.
- UnderConfminorOPERATION ZERO participated as partner/sponsor of UnderConf 2024, held September 29, 2024 at Holiday Inn Sokolniki, Moscow.
- OFFZONE ConferencecoreOPERATION ZERO again became official sponsor and partner of OFFZONE 2024 conference, held August 22-23 at the ZIL Cultural Center in Moscow. Company actively participates in sponsoring conferences directly related to information security to support exchange of experience among leading specialists.
- OFFZONE ConferencecoreOPERATION ZERO became official sponsor and partner of OFFZONE 2023 conference, held August 24-25 in Moscow at GOELRO Hall. OFFZONE is an international conference on practical cybersecurity that has united security professionals, developers, engineers, researchers, and students from dozens of countries since 2018.
Scale indicators2 records
Recent moves3 records
Expansion highlights3 records
Operation Zero competitors and assessment
Company assessmentRegional players
- Positive Technologies: Positive Technologies is a major Russian cybersecurity firm with offensive security research, exploit development, and government contracts. It overlaps with Operation Zero on Russian offensive-security demand and government-facing expertise.
- BI.ZONE: BI.ZONE is a major Russian cybersecurity firm that organizes the OFFZONE conference at which Operation Zero is a sponsor. It is a regional peer in the Russian cybersecurity services market, with broader defensive and consulting offerings alongside some offensive capabilities.
- Kaspersky Lab: Kaspersky is a leading Russian-headquartered cybersecurity vendor with deep offensive research expertise (e.g., GReAT team). It is comparable as a Russian cybersecurity peer but operates globally and across the defensive/intel spectrum rather than as a zero-day broker.
Broad incumbents
- Bugcrowd: Bugcrowd operates a crowdsourced cybersecurity platform with bug-bounty and penetration-testing programs. It competes for researcher attention but is positioned for defensive enterprise buyers, not offensive exploit resale.
- YesWeHack: YesWeHack is a European bug-bounty and vulnerability disclosure platform with government and enterprise customers. Comparable to Operation Zero in researcher pipeline mechanics but oriented toward responsible disclosure rather than offensive resale.
- HackerOne: HackerOne runs a major bug-bounty and vulnerability disclosure platform connecting researchers with enterprise and government programs. It is adjacent to Operation Zero's researcher-acquisition flow but serves defensive rather than offensive use cases.
- Trend Micro Zero Day Initiative (ZDI): ZDI is the largest independent bug-bounty program, acquiring vulnerabilities from researchers and disclosing them (responsibly) to vendors. It overlaps with Operation Zero on the research-acquisition side but operates a defensive disclosure model rather than selling offensive exploits.
Direct peers
- Zerodium: Zerodium is a leading global zero-day exploit broker that purchases vulnerabilities from researchers and resells them to government clients. It is the closest international analogue to Operation Zero's exploit-acquisition marketplace business model.
- Crowdfense: Crowdfense operates an exploit acquisition platform with published bounties for mobile and desktop zero-days targeted at government buyers. It is a direct competitor in the same niche of curated, high-value zero-day marketplaces.
- Exodus Intelligence: Exodus Intelligence conducts original zero-day vulnerability research and sells exploit intelligence to government and enterprise customers. It directly mirrors Operation Zero's combination of in-house research and government-focused offensive capabilities.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat3 records
Key risks6 records
Key highlights6 records
Customer concentration
Operation Zero social profiles
Digital presenceOperation Zero compliance and trust
Trust signalCompliance1 record
Operation Zero financial estimates
Financial estimateRevenue estimate
Valuation estimate
Operation Zero leadership team
Management profileNumber of profiles
Operation Zero funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Operation Zero M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Operation Zero
What does Operation Zero do?
Operation Zero operates a zero-day vulnerability acquisition platform that purchases fully functional exploits from independent security researchers and provides them to vetted Russian private and government organizations. The platform covers six target categories — personal computers, mobile devices, servers, virtualization software, routers, and baseband chips — and manages the full acquisition lifecycle including researcher outreach, assessment, code verification (completed within one working week), and payment processing. Transactions are conducted via PGP-encrypted email with payments to researchers set to match international competitor standards.
Is Operation Zero a public or private company?
Operation Zero is a private company. It is classified as unknown and is currently operating.
When was Operation Zero founded?
Operation Zero was founded in 2021. It employs 1 to 10 people.
Where is Operation Zero based?
Operation Zero is headquartered in Saint Petersburg, Russia, in the Europe region.
How does Operation Zero make money?
One revenue line is on record: zero-Day Exploit Transactions.
Who are Operation Zero's main competitors?
Regional players on record are Positive Technologies, BI.ZONE and Kaspersky Lab. Broad incumbents are Bugcrowd, YesWeHack, HackerOne and Trend Micro Zero Day Initiative (ZDI). Direct peers are Zerodium, Crowdfense and Exodus Intelligence.
Does Operation Zero have an API?
No public API is recorded for Operation Zero.
What industry is Operation Zero in?
Operation Zero's product category is Offensive Security / Vulnerability Research. Its primary akta.pro industry code is BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 5415 and its SIC code is 7370.