VMark: A market for producing verified reductions in digital risk

Cybersecurity is one of the largest risk classes in the digital economy, but it remains unusually difficult to observe and price before a loss.

What if finding a zero-day paid more than selling one?

VMark is a prediction market where security researchers profit by finding and safely proving critical vulnerabilities.

How it works

  • A market asks a concrete question: “Will someone discover a critical vulnerability in OpenSSH before December 31?”
  • Researchers can buy YES, perform the research, and resolve the market by submitting a verified, non-destructive proof.
  • Instead of relying on one company’s bounty budget, researchers compete for capital pooled from speculators, insurers, enterprises, and everyone who depends on the software—bringing defensive research closer to state-scale economics.
  • Independent experts verify the vulnerability confidentially, the maintainer patches it under embargo, and a permanent VMark records the result.
  • The consequence: more of the world’s best researchers hunt vulnerabilities in critical software—and get them fixed before states, criminals, or ransomware groups exploit them.

VMark turns the zero-day arms race toward defense.

The problem

Cybersecurity is one of the largest risk classes in the digital economy, but it remains unusually difficult to observe and price before a loss.

Organizations can pay for audits, security tools, and bug-bounty programs, yet still cannot directly observe many of their most consequential vulnerabilities. Insurers price portfolios using incomplete and indirect evidence. Security researchers who discover serious defects face a fragmented market in which lawful compensation may bear little relationship to the value of the risk they remove. Vulnerabilities in shared software create an additional coordination problem: thousands of organizations benefit from discovery, but no single organization has an incentive to fund the full cost.

The insight

Cybersecurity has a property that many other risk classes do not: dangerous capability can often be proven before harm occurs.

A cryptographic key can be proven compromised by signing a fresh challenge without transferring assets. Privileged access can be demonstrated using a planted canary rather than customer data. A software vulnerability can be reproduced in an isolated environment rather than exploited against a production system.

This separation between capability and harm makes it possible to verify risk before a destructive event.

The protocol

VMark is a market and verification protocol for sponsoring, discovering, pricing, and recording reductions in digital risk.

A sponsor—such as an enterprise, insurer, cloud provider, software foundation, or industry consortium—creates a campaign defining the authorized scope, qualifying vulnerability, proof standard, deadline, research award, market subsidy, and disclosure policy.

Researchers perform authorized work and confidentially submit cryptographic commitments to evidence. Qualified validators independently reproduce the result. When a submission satisfies the campaign standard, the protocol issues a VMark: a non-transferable, cryptographically anchored receipt that a defined security capability was independently verified at a particular time.

The evidence remains confidential during remediation. The VMark records the verification without transferring the exploit or granting access to the proof.

The market

Each campaign may support a fixed-expiry market:

Will this campaign produce at least one accepted VMark before the deadline?

Traders price the probability of discovery. Researchers may take limited, disclosed producer positions and then perform the work necessary to make the outcome occur legitimately. This is a reflexive prediction market: it is designed not only to forecast an outcome, but also to fund the specialized effort that produces it.

Researchers are informed and can influence settlement, so VMark does not depend on unlimited passive liquidity. Sponsors deliberately subsidize the market using a mechanism with predetermined maximum loss. The sponsor purchases both an information signal and an incentive for discovery.

VMark does not make the researcher's primary payoff depend on a vulnerability remaining exploitable. Researchers receive most of their award after independent verification and a final tranche after remediation. They benefit from finding and helping remove risk, not from prolonging it.

How a campaign works

  1. Fund: Sponsors publish an immutable campaign and escrow bounded research and market budgets.
  2. Research: Researchers enter the campaign, optionally acquire capped producer positions, and conduct authorized work.
  3. Commit: A researcher timestamps a cryptographic commitment and submits encrypted evidence.
  4. Verify: A competence-matched panel independently reproduces the proof and applies a published severity standard.
  5. Pay: An accepted case creates a private VMark and releases the initial research award.
  6. Remediate: The target receives the evidence under embargo, develops a fix, and submits it for retesting.
  7. Disclose: After remediation or the defined disclosure deadline, the protocol publishes a sanitized VMark.

Why it is different

VMark adds several layers that a conventional bug-bounty portal does not provide:

  • pooled funding from multiple beneficiaries;
  • a live probability market for discovery;
  • independent, confidential reproduction;
  • standardized receipts that can support underwriting and risk indices;
  • root-cause deduplication for vulnerabilities affecting many organizations;
  • bounded market liability and an auditable disclosure process.

The long-term product is not another submission portal. It is a measurement and settlement standard for digital risk.

Safety and initial deployment

Research against live systems requires explicit authorization and safe harbor. Full evidence remains encrypted and offchain. Validators are selected by proof-class expertise. Researcher-created defects, proofs manufactured by authorized administrators, duplicates, and harmful demonstrations do not qualify. Validators, target insiders, and others with confidential case information cannot trade affected contracts. Governance cannot rewrite active campaign terms or decide individual cases through token-weighted voting.

VMark should begin with a small number of widely used open-source packages tested entirely inside VMark-operated environments. Initial campaigns should use stable collateral, fixed-expiry contracts, expert validators, confidential coordinated disclosure, and no native token. This minimizes authorization risk while addressing vulnerabilities with potentially systemic impact.

The opportunity

VMark can create a legitimate market for high-quality security research, a live price for otherwise hidden cyber risk, direct evidence for insurers and risk managers, pooled financing for shared infrastructure, and stronger incentives to discover and remove vulnerabilities before attackers do.

Sponsors bound the cost, markets price the work, researchers change the outcome, validators establish the evidence, and cryptographic receipts record that risk was found and removed before it caused harm.