🛡️ Defense
Zero-Day Exploits Used to Cost $2.5 Million. AI Finds Them for $50. The Backlog Is Already 79 Deep.
AI collapsed exploit-discovery costs by 99.998%, and patching hasn't sped up to match. A calculation nobody has run reveals the steady-state vulnerability backlog that will define cybersecurity for the next decade.
Zerodium, the gray-market exploit broker, pays up to $2.5 million for a zero-click Android exploit chain with persistence, $2 million for an iOS remote jailbreak, half a million for a Chrome sandbox escape. These prices have held roughly stable for years, because finding a genuine zero-day and weaponizing it requires months of elite human labor and deep knowledge of memory layouts, kernel internals, and exploit mitigations.
Anthropic's Mythos Preview found a 27-year-old OpenBSD TCP stack bug for roughly $50 in compute, not $50,000 or $500,000 but fifty actual dollars.
That is a 50,000× cost reduction, equivalent to the price of a Boeing 737 dropping to the cost of a burrito, and it isn't theoretical. ExploitGym, a benchmark created by researchers from UC Berkeley, the Max Planck Institute, Anthropic, OpenAI, and Google, tested frontier AI models against 898 real-world CVEs across userspace programs, Google's V8 JavaScript engine, and the Linux kernel. Claude Mythos Preview produced 157 working exploits, GPT-5.5 produced 120, and even with ASLR and stack canaries enabled, the success rates held.
Nobody disputes these numbers, because two of the ExploitGym co-authors work at Anthropic, one at OpenAI, and three at Google. Thorsten Holz, the senior author, published a Nature editorial on July 16 arguing that organizations must "redesign their defences" because automated tools now accelerate both discovery and exploitation faster than any institutional process can absorb. He is right that organizations must redesign their defenses, but the editorial did not run the math on what that redesign actually entails at scale when you combine AI-accelerated discovery rates with the documented patch timelines that hospitals, banks, manufacturers, and government agencies have been reporting for the past decade.
Calculation 1: How Fast the Backlog Grows
Mike Sentonas, president of CrowdStrike, told Fast Company on July 16 that his near-term projection is ten exploitable zero-days per week hitting enterprise networks, and not ten CVEs in the general sense but ten zero-days, meaning flaws with no existing patch that attackers can weaponize before defenders even know they exist.
Edgescan's 2026 report puts the mean time to remediate high-severity application vulnerabilities at 54.81 days, and Qualys's 2026 Patch Benchmark found that complex enterprise applications take five months and ten days on average.
Run the arithmetic: if AI-accelerated attackers generate ten new exploitable zero-days weekly, and defenders need 55 days to close each one, the steady-state backlog is 10 × (55 ÷ 7) ≈ 79 concurrent unpatched exploitable vulnerabilities in any given enterprise environment, a number that climbs to 229 under Qualys's five-month figure for complex enterprise systems.
Seventy-nine is not a worst case. It is the median, calculated from industry-reported remediation timelines that have been stable for years. And Mandiant's M-Trends 2026 report adds a detail that makes it worse: the mean time to exploit a newly discovered vulnerability is now negative seven days, meaning exploitation routinely begins before a patch exists, so by the time a fix ships, the exploit has already been circulating for a week.
Calculation 2: What $100 Million Buys on Each Side
Anthropic launched Project Glasswing in April, a $100 million defensive coalition giving Microsoft, AWS, Apple, Google, Cisco, NVIDIA, and CrowdStrike early access to Mythos for vulnerability scanning. Noble goal. Serious money.
Now run the offensive math. At $50 per exploit-discovery operation and ExploitGym's 17.5% conversion rate, $100 million buys an adversary 2 million discovery operations yielding approximately 350,000 working exploits. Indusface reported 6,235 zero-day vulnerabilities across all protected websites in 2025, a figure the industry considered alarming, and 350,000 is 56 times that number. No nation-state has ever possessed a stockpile of that magnitude, and compute prices fall every quarter even without model improvements.
Calculation 3: Cybersecurity as an AI Tax
Reuters argued on July 14 that cybersecurity costs will eat a material chunk of AI's productivity gains. CrowdStrike trades at roughly $190 billion and Palo Alto Networks at $270 billion, meaning $460 billion in combined market capitalization exists because finding vulnerabilities is hard and stopping exploitation requires specialized, expensive, constantly updated defenses.
When discovery becomes cheap, the volume of threats scales with compute budgets rather than human headcount. McKinsey noted in late 2024 that phishing sites ballooned 138% shortly after ChatGPT's release, and that was from language models with zero exploit-development capability. Frontier models now chain four vulnerabilities into a working browser exploit autonomously, and every CISO in Sentonas's network received "a panicked call from their CEO or from a board member" after Mythos shipped.
Global cybersecurity spending already exceeds $200 billion annually, and if discovery rates accelerate tenfold while patch timelines compress by only 40%, the math demands a spending increase that would dwarf current AI infrastructure investment.
Why "AI Helps Defenders Too" Is Necessary but Insufficient
AI genuinely does help defenders, and that argument deserves its full weight rather than dismissal. Glasswing partners will patch thousands of Mythos-discovered vulnerabilities before attackers find them, Google's Big Sleep project identified a critical SQLite vulnerability before criminal actors could weaponize it, and SentinelOne's AI-powered endpoint detection caught Claude Code executing a trojaned supply-chain package in real time, killing the process before lateral movement could deploy.
But the asymmetry is structural, because a defender must patch every vulnerability across every system in the environment while an attacker needs exactly one working exploit in one unpatched system. At 79 concurrent unpatched exploitable flaws, the attacker's search space is not one needle in a haystack but 79 unlocked doors in a building where the locksmith takes eight weeks to arrive.
Patching is accelerating too, with mean remediation times dropping from 63 days to 38 days between 2024 and 2025, genuine progress by any measure, but discovery is accelerating far faster: Opus 4.6 produced two working Firefox exploits across hundreds of attempts, while Mythos produced 181 from the same benchmark. That's a 90× improvement in a single model generation, and no patching infrastructure on Earth has improved 90× in one cycle or anything close to it, which means the gap between offensive capability and defensive response widens with every model release rather than narrowing.
What the Next Twelve Months Look Like
Glasswing's 90-to-135-day coordinated disclosure timeline means the first wave of Mythos-discovered patches will arrive through Q3 and Q4 2026, and organizations that apply them promptly will close a substantial portion of the newly discovered attack surface. Organizations that don't will face adversaries armed with the same discovery tools, operating at $50 per attempt, with no disclosure obligation.
Only 9% of organizations remediate critical vulnerabilities in production within 24 hours. Among those who miss that window, 80% report security incidents involving known vulnerabilities, and those figures reflect today's volume, not a world where ten new exploitable zero-days arrive weekly. Sentonas's prescription is blunt: "You can't outsource risk. You own the risk. It's your network." Compensating controls, network segmentation, and runtime monitoring will matter more than patching speed alone, but managing 79 concurrent exploitable vulnerabilities is a fundamentally different operational posture than managing nine.
What You Can Do
If you run a security team, bring three numbers to your next board meeting: your organization's mean time to remediate critical vulnerabilities, the number of unpatched CVEs currently in your environment, and how many of those have public exploits. If you don't know those numbers, that is the first problem to solve, because the threat model just changed and your exposure surface expanded by orders of magnitude without anything in your infrastructure actually changing.
If your organization qualifies for Glasswing or a comparable AI-augmented vulnerability scanning program, request access now and budget for it in 2027 planning. If it does not, the ExploitGym methodology is published on arXiv and the scanning tools are commercially available. Running them defensively against your own codebase before someone runs them offensively is the single highest-leverage security investment available today.
If you are an individual user rather than a security professional, the honest answer is that most of these economics operate above the level where personal action changes outcomes, but the basics matter more than ever: enable automatic updates everywhere, use hardware security keys for critical accounts, and assume that any software running unpatched for more than two weeks is compromised-until-proven-otherwise. In a world with 79 to 229 exploitable zero-days floating at any given time, the most realistic goal is not invulnerability but making sure you are not the softest target on the network.
What We Don't Know
This analysis rests on three load-bearing numbers, each with meaningful uncertainty. Anthropic's $50-per-discovery figure is self-reported by a company with commercial incentives to present its model favorably, and we cannot independently verify their compute costs; if actual amortized cost per exploit is $500 rather than $285, the headline compression ratio drops from 50,000× to 5,000×, which is still catastrophic but less dramatic. Sentonas's "10 zero-days per week" is a forward projection from a company that sells zero-day response, and if the actual rate stabilizes at three per week, the steady-state backlog drops from 79 to roughly 24, a number that is dangerous but perhaps manageable for well-resourced organizations. And the ExploitGym benchmark tested AI against known CVEs, not novel zero-day discovery in wild codebases; the 17.5% success rate may not generalize to code that has never been fuzzed or audited, where success rates could be higher or substantially lower.
The Bottom Line
For three decades, cybersecurity economics rested on a single structural fact: finding a zero-day and turning it into a working exploit was prohibitively expensive, and Zerodium's price list was proof of scarcity. AI destroyed it in eighteen months, collapsing discovery costs by 50,000× while raising conversion rates to 17.5% of all tested CVEs. Seventy-nine concurrent unpatched exploitable vulnerabilities is not a scenario but arithmetic, calculated from numbers CrowdStrike, Mandiant, Edgescan, and Qualys have published. Whether that number defines the next decade depends on how fast institutions can rewire processes designed for a threat environment that no longer exists.