In the high-stakes, clandestine world of zero-day vulnerability acquisition—where multimillion-dollar payouts are the norm for those who can silence the digital world’s most critical security flaws—a new player has emerged in McLean, Virginia. IRIS C2, a firm promising up to $7 million for software exploits, has rapidly cultivated an online presence, drawing thousands of followers and claiming to hunt for the world’s most elite engineering talent.
However, beneath the polished veneer of a high-tech cybersecurity startup lies a familiar and controversial duo. IRIS C2 is operated by Jacob Wohl and Jack Burkman, two notorious far-right conspiracy theorists and convicted felons whose history involves a decade of orchestrated fabrications, fraudulent investment schemes, and high-profile legal battles. Their pivot from political disinformation to the sensitive market of offensive cyber-intelligence has raised alarm bells among security researchers and federal observers alike.
The Rise of IRIS C2: Marketing Millions
Since its inception in January 2025, the X (formerly Twitter) account @C2IRIS has positioned itself as an aggressive recruiter for the "best vulnerability researchers and exploit developers in the world." With over 4,000 followers, the account functions as a digital storefront for offensive cybersecurity capabilities.
The company’s website, irisc2[.]com, brazenly advertises payouts ranging from $10,000 to $7 million, contingent upon the “target, reliability, and operational value” of the exploits provided. Their business model specifically targets junior engineers, explicitly stating a disregard for traditional credentials like college degrees or industry experience, favoring "raw talent" and "high IQ" instead.
Government contracting databases, specifically G2Exchange, link the domain to Calvexa Group LLC, a Virginia-based entity. While Calvexa is registered as a federal contractor, there is no public evidence of the company fulfilling direct government contracts. The registered address for Calvexa points to a property occupied by Jack Burkman, the 60-year-old founder of the lobbying firm Burkman & Associates. When questioned about the venture, Burkman diverted inquiries to his long-time associate, 28-year-old Jacob Wohl.

A Chronicle of Deception: The Wohl-Burkman Track Record
To understand the skepticism surrounding IRIS C2, one must look at the extensive, well-documented history of its architects. The careers of Wohl and Burkman have been defined by a series of schemes that often mirror the "fake intelligence" model they are now allegedly applying to the cyber-security sector.
The Disinformation Era (2018–2020)
Wohl and Burkman rose to infamy by creating shell companies designed to manufacture false narratives. In 2018, they attempted to frame then-FBI Director Robert Mueller with fabricated sexual assault allegations. This pattern of behavior continued, targeting figures such as Pete Buttigieg and Senator Elizabeth Warren with baseless claims of misconduct. Their press conferences, often chaotic and debunked in real-time, became a hallmark of their operation.
The Robocall Prosecution (2020–2025)
Following the 2020 presidential election, the pair faced significant legal consequences for a mass robocall campaign targeting voters in battleground states with disinformation regarding mail-in ballots. This culminated in a 15-count felony indictment in Cleveland for voter suppression efforts targeting Detroit. In late 2025, they were sentenced to probation after a lengthy legal battle. Prior to this, in 2023, the FCC imposed a record-breaking $5.1 million fine against them for violating the Telephone Consumer Protection Act—the largest fine of its kind in the agency’s history.
Financial Fraud and "LobbyMatic"
Wohl’s history of financial instability dates back to his teenage years. In 2017, the Arizona Corporation Commission charged him with 14 counts of securities fraud related to his hedge funds. In 2019, he pleaded guilty in California to selling unregistered securities. More recently, in 2024, Politico exposed "LobbyMatic," an AI-powered lobbying firm where the pair operated under pseudonyms—Wohl as "Jay Klein" and Burkman as "Bill Sanders." The company collapsed after employees discovered they had been working for the pair under false pretenses.
The "Expertise" Question: Can They Deliver?
When asked about his qualifications to lead a firm dealing in complex zero-day vulnerabilities, Jacob Wohl displayed the same brash confidence that characterized his past ventures. Despite having no formal training in computer science or cybersecurity, Wohl claimed to be "deeply into tech."

"I know more about tech than anyone," Wohl stated in an interview. "People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin."
Wohl claims the firm has roughly 40 employees, though he notes that none are permitted to list their employment on professional networks like LinkedIn for "operational security." This lack of transparency, coupled with the pair’s history of utilizing aliases, suggests a business structure designed to obscure the identity of those behind the curtain. Security experts note that while the market for exploits is indeed filled with a "colorful mix" of characters, legitimate government contractors usually maintain a degree of professional circumspection that IRIS C2 appears to lack entirely.
Implications and Ethical Concerns
The shift of figures like Wohl and Burkman into the vulnerability market poses significant risks, both to the cybersecurity industry and the government agencies they claim to serve.
The Risks of "Amateur" Exploitation
The process of refining a "primitive" (a partial exploit) into a stable, weaponized exploit requires a high degree of technical rigor. If IRIS C2 is indeed soliciting raw, unfinished findings from junior researchers, they may be creating a repository of dangerous, unstable tools. Furthermore, if the "clients" of such firms are indeed government entities, the potential for catastrophic failure or accidental data leakage is high.
The "Pardon-for-Hire" Allegations
Adding to the concern is a report from journalist Molly White, detailing that Wohl and Burkman were paid a $300,000 retainer by a Canadian cryptocurrency fraudster currently wanted for the theft of $65 million from platforms like KyberSwap. The duo was reportedly hired to pursue a presidential pardon for the suspect. This intersection of cybercrime, high-level political influence peddling, and vulnerability acquisition suggests that IRIS C2 may be part of a broader, more opaque ecosystem of legal and technical "fixers."

Conclusion: A Cautionary Tale
The emergence of IRIS C2 is a stark reminder of the "wild west" nature of the zero-day market. While legitimate firms spend years building reputations based on technical prowess and ethical vetting, IRIS C2 operates on the principles of rapid growth, high-stakes promises, and an absolute disregard for historical transparency.
For the cybersecurity community, the presence of Wohl and Burkman in this space is less about the potential for technological innovation and more about the potential for reputational damage. As the industry continues to professionalize, the existence of entities that treat critical software vulnerabilities as tools for clout-chasing and political maneuvering remains a significant liability.
Ultimately, whether IRIS C2 represents a genuine attempt to enter the defense sector or is merely the latest iteration of a "fake intelligence" shell company remains to be seen. However, given the track record of its leadership, the industry is right to treat the firm with extreme caution. The history of Jacob Wohl and Jack Burkman is not one of successful technological development, but of spectacular, well-documented failure—and in the world of high-stakes cybersecurity, failure is not an option that companies can afford to take lightly.
