Overview
A new report published by the Atlantic Council's Cyber Statecraft Initiative on June 25, 2025 argues that the United States is losing ground to China in the competition for offensive cyber capabilities — and that structural failures in how Washington acquires, funds, and deploys zero-day exploits lie at the root of that deficit. Titled *Crash (Exploit) and Burn: Securing the Offensive Cyber Supply Chain to Counter China in Cyberspace*, the report was authored by Winnona DeSombre Bernsen and draws on ten months of original research conducted between June 2024 and March 2025, including literature review, open-source data analysis, and dozens of background interviews with practitioners in the U.S. offensive cyber industry.
The report arrives at a moment of heightened scrutiny of U.S.-China cyber competition and follows sustained public debate over the proliferation of commercial spyware. It is among the most detailed public accounts to date of how the U.S. government actually obtains and manages offensive cyber tools — and, crucially, how that system compares unfavorably to China's.
A "Horrendously Inefficient and Broken" Acquisition System
The report's most striking finding is that Washington's zero-day acquisition pipeline is deeply dysfunctional. A senior U.S. Department of Defense official working on offensive cybersecurity research is quoted as saying that "the system by which zero day vulnerabilities are acquired is horrendously inefficient and broken." A former official from the Office of the National Cyber Director (ONCD) adds that pricing opacity compounds the problem: "An individual researcher who isn't informed on what bugs are selling for may sell a good bug for 100k. By the time it makes it to a customer, an individual bug could go for 750k to 1 million dollars."
These price distortions are not merely a fiscal concern. Because middlemen work with other middlemen in multi-layered brokerage chains, the original source of a zero-day exploit is often difficult to ascertain, raising counterintelligence risks and the possibility that adversaries have access to the same capabilities. The author also notes that creating a single zero-day exploit against a widely used technology product can require between six and eighteen months of full-time engineering and research work — a time horizon compounded by the risk that the vendor may patch the underlying vulnerability before the exploit can be fielded.
Structural Fragility of the Zero-Day Market
DeSombre Bernsen situates these operational problems within broader market dynamics. Because only a small number of large technology firms produce most of the products used globally today, "bug collisions" — the parallel, independent discovery of the same vulnerability by multiple researchers — are growing increasingly common. When a bug collision occurs, multiple parties may simultaneously possess the same exploit, sharply increasing the likelihood that the vulnerability is discovered and patched, eroding whatever operational advantage the U.S. government believed it had purchased.
The report also contextualizes recent Biden-era policies targeting commercial spyware proliferation, which, while aimed at human rights concerns, have had measurable knock-on effects on the availability and pricing of zero-day exploits available to U.S. government customers. The author notes these dynamics without characterizing the spyware-targeting policies as mistaken; rather, she argues they underscore the need for a more deliberate and resilient U.S. acquisition architecture.
Policy Recommendations
The report advances several concrete recommendations. First, it calls on the U.S. government to establish a government-sponsored vulnerability broker housed within a federally funded research and development center (FFRDC) to decentralize and simplify exploit purchases and increase capability budgets. Second, it urges expanded investment in automated exploit chain generation research. Third, it recommends adjusting policy frameworks to incorporate counterintelligence strategies into the zero-day marketplace — including "burning" capabilities held by malicious actors while funneling willing, responsible researchers into a more formal acquisition pipeline. Fourth, the report recommends funding additional "n-day" research (the exploitation of known but unpatched vulnerabilities) through U.S. Cyber Command (USCYBERCOM). Finally, it calls on Washington to leverage multilateral initiatives — explicitly naming the Pall Mall Process — to coordinate with allies in countering China's growing dominance in offensive cyber capabilities.
The report's conclusion is unambiguous: without meaningful institutional and legal reforms to the offensive cyber supply chain, "the United States risks ceding to China whatever strategic advantage it has left in cyberspace."
Significance for Cyber Law and Policy
For practitioners of cyber law, the report raises questions that go beyond operational efficiency. A government-sponsored vulnerability broker operating inside an FFRDC would require new legal authorities, classification frameworks, and liability protections. The counterintelligence recommendations — burning adversary capabilities and recruiting researchers into formal pipelines — implicate export controls, contract law, and potentially the law of armed conflict if such capabilities are later operationalized. How U.S. authorities would interact with the Pall Mall Process's normative framework for responsible state behavior in the cyber domain remains unaddressed, but represents a significant area for future legal analysis.
The report does not represent official U.S. government policy. It is a think-tank research product, and its recommendations would require legislative or executive action to implement. Nevertheless, as one of the most detailed open-source analyses of the U.S. offensive cyber acquisition system to emerge in recent years, it is likely to inform congressional debate, executive branch planning, and allied consultations on offensive cyber governance.
Sources
- Crash (Exploit) and Burn: Securing the Offensive Cyber Supply Chain to Counter China in Cyberspace — https://www.atlanticcouncil.org/in-depth-research-reports/report/crash-exploit-and-burn/ - Crash (Exploit) and Burn (Full PDF) — https://www.atlanticcouncil.org/wp-content/uploads/2025/06/Crash-exploit-and-burn_DeSombre-Bernsen.pdf