Home Security Million-dollar bounty offered for Tor exploits

Million-dollar bounty offered for Tor exploits

An exploit vendor has offered a bounty of US$1 million for zero-day exploits that target the Tor browser on Tails Linux and Windows.

The Washington DC-based Zerodium said the offer was open until 30 November.

However, it added a rider: the bounty could be withdrawn if its total payments to researchers reached US$ 1 million.

The million-dollar offer for Tor exploits is for those that work with JavaScript blocked. The default install of Tor allows JavaScript to run and exploits for the browser in this state will earn lower payouts

The Tor browser is used by security-conscious individuals and can be used to access those portions of the Internet known as the dark web.

zerodium million

In a Q and A, the company said it was offering the million-dollar bounty for Tor to make the world a safer place.

"While the Tor network and Tor Browser are fantastic projects that allow legitimate users to improve their privacy and security on the Internet, the Tor network and browser are, in many cases, used by ugly people to conduct activities such as drug trafficking or child abuse," the company said.

"We have launched this special bounty for Tor Browser zero-days to help our government customers fight crime and make the world a better and safer place for all." 

In a FAQ, Zerodium explained that its customers were mainly US Government agencies.

"Zerodium customers are mainly government organisations in need of specific and tailored cyber security capabilities, as well as major corporations from defence, technology, and financial sectors, in need of protective solutions to defend against zero-day attacks," it said.

"Access to Zerodium solutions and capabilities is highly restricted and is only available to a very limited number of organisations."

Last month, Zerodium offered increased bounties for exploits targeting apps used for encrypted messaging.


Did you know: 1 in 10 mobile services in Australia use an MVNO, as more consumers are turning away from the big 3 providers?

The Australian mobile landscape is changing, and you can take advantage of it.

Any business can grow its brand (and revenue) by adding mobile services to their product range.

From telcos to supermarkets, see who’s found success and learn how they did it in the free report ‘Rise of the MVNOs’.

This free report shows you how to become a successful MVNO:

· Track recent MVNO market trends
· See who’s found success with mobile
· Find out the secret to how they did it
· Learn how to launch your own MVNO service


Sam Varghese

website statistics

A professional journalist with decades of experience, Sam for nine years used DOS and then Windows, which led him to start experimenting with GNU/Linux in 1998. Since then he has written widely about the use of both free and open source software, and the people behind the code. His personal blog is titled Irregular Expression.