Operation Zero, a Russian zero-day broker, is offering up to $4 million for Telegram exploits. They seek $500K for one-click RCE, $1.5M for zero-click RCE, and $4M for a full-chain exploit that can fully compromise a device. The firm only sells exploits to the Russian government and local companies.
We are looking for:
Telegram 1-click RCE — Up to $500,000
Telegram 0-click RCE — Up to $1,500,000
Telegram full chain — Up to $4,000,000
The exploits available are for Android, iOS, and Windows. Prices vary based on zero-day limitations and privilege levels.
Zero-day companies, like Operation Zero, create or buy security vulnerabilities in popular software and sell them at a profit. Targeting Telegram is logical due to its popularity among users in Russia and Ukraine.
A zero-day broker like Operation Zero might be willing to pay millions for Telegram exploits for several reasons, including:

Government and Intelligence Demand:
Telegram is popular for secure communication among journalists, activists, and politicians. Russian intelligence may exploit vulnerabilities for surveillance and espionage.
Strategic Cyber Warfare:
In geopolitical conflicts, access to Telegram accounts and devices could provide military and intelligence advantages, like eavesdropping on important messages and finding informants.
Law Enforcement and Cybercrime Control:
Russian authorities may seek to monitor criminal organizations, opposition groups, or foreign entities on Telegram. Gaining access without Telegram’s cooperation would be very advantageous.
An exploit that bypasses Telegram’s end-to-end encryption could significantly impact cyber espionage, given its widespread use.
Zero-days are unknown vulnerabilities in software or hardware that are highly sought after by exploit brokers and hackers. They allow for easier exploitation without the maker or target being aware.
Remote Code Execution (RCE) flaws are particularly valuable because they enable hackers to control an app or operating system remotely. Zero-click exploits, which don’t require any interaction from the target, are even more valuable than phishing attacks.
Thus, a zero-click, RCE zero-day is the most valuable type of exploit.