Cybersecurity Startup IRIS C2, Dangling Millions for Zero-Day Exploits, Linked to Convicted Felons and Conspiracy Theorists

A cybersecurity startup that is actively soliciting zero-day vulnerabilities in popular software, offering substantial financial incentives that could reach millions of dollars, has been revealed to be operated by individuals with a history of far-right conspiracy theories, felony convictions, and the operation of defunct ventures under assumed identities. The entity, operating under the moniker IRIS C2 and identified by the X/Twitter handle @C2IRIS, has rapidly gained traction in the cybersecurity community since its inception in January 2025, boasting over 4,000 followers and a consistent stream of posts concerning security vulnerabilities, artificial intelligence, and software exploits. Based in McLean, Virginia, IRIS C2 publicly declares its business as the acquisition and provision of offensive cybersecurity capabilities.
A Bold Recruitment Strategy and Unconventional Business Model
The core of IRIS C2’s public-facing strategy, as highlighted in a pinned post on its X account, centers on attracting top-tier vulnerability researchers and exploit developers. The message emphasizes a unique recruitment philosophy: "Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience." This approach suggests a deliberate pivot away from traditional hiring metrics, seeking raw talent over formal qualifications, potentially to bypass the scrutiny that might accompany a more conventional background check.
The company’s website, irisc2[.]com, elaborates on this business model, detailing a comprehensive acquisition program for "zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms." The potential payouts are staggering, ranging from $10,000 to an astonishing $7 million, contingent on the exploit’s target, reliability, and operational value. This aggressive pricing strategy, as illustrated by a prominent image on their website, is clearly designed to capture the attention of skilled individuals in a highly competitive field.
Unmasking the Operatives: A Trail of Deception and Convictions
Government contracting portals, such as g2exchange.com, identify irisc2[.]com as being operated by Calvexa Group LLC, a Virginia-based entity. Further investigation into Calvexa Group LLC’s contact information, calvexagroup[.]com, reveals that it redirects directly to the IRIS C2 website, reinforcing the interconnectedness of these operations. While Calvexa Group LLC is registered as a federal contractor, public records do not indicate any active direct government contracts.
The registered address for Calvexa Group LLC in Arlington, Virginia, leads to the residence of Jack Burkman, a 60-year-old individual known as the founder and managing partner of the lobbying firm Burkman & Associates. When questioned about IRIS C2, Burkman deferred inquiries to his long-time associate, Jacob Wohl, a 28-year-old.

Burkman and Wohl possess a documented and extensive history of controversial activities, including the establishment of fictitious intelligence firms used to disseminate misinformation and orchestrate smear campaigns against public figures. Notably, they have been associated with fabricating sexual assault allegations against former FBI Director Robert Mueller and Pete Buttigieg, who was then the mayor of South Bend, Indiana, and a Democratic presidential candidate. In 2019, Burkman and Wohl held press conferences making unsubstantiated claims of extramarital affairs involving Senator Elizabeth Warren (D-Mass.) and Kamala Harris, who was a candidate for the 2020 presidential election.
Legal Entanglements and Regulatory Sanctions
The duo’s activities have not gone unnoticed by law enforcement and regulatory bodies. Following the 2020 presidential election, Wohl and Burkman faced prosecution in multiple U.S. states for their involvement in a scheme involving thousands of robocalls directed at residents of battleground states. These calls disseminated false information regarding mail-in ballots, aiming to suppress voter turnout. In Cleveland, they were indicted on 15 felony counts for orchestrating a robocall operation targeting the Black vote in Detroit. By late 2025, after their appeals to dismiss the charges were unsuccessful, they were sentenced to probation.
Further legal repercussions followed. In 2022, both Wohl and Burkman pleaded guilty to a single felony charge of telecommunications fraud in Ohio, resulting in a fine, probation, and community service. A New York civil court ruling in March 2023 found Wohl and Burkman to have violated federal and state civil rights laws, leading to a $1 million settlement. The Federal Communications Commission (FCC) levied a significant $5.1 million fine against them in June 2023 for their robocall campaigns. At the time, this represented the largest fine ever sought by the FCC under the Telephone Consumer Protection Act.
A Pattern of Financial Irregularities and Pseudonymous Operations
Jacob Wohl’s entrepreneurial endeavors began at a young age. By 17, he had founded multiple investment firms and gained notoriety as the "Wohl of Wall Street" following appearances on Fox News in 2015 to discuss his hedge funds. However, his financial dealings attracted regulatory scrutiny. In 2017, the Arizona Corporation Commission charged Wohl and his investment funds with 14 counts of securities fraud, ordering him to pay $35,000 in restitution. Subsequently, in 2019, Wohl pleaded guilty in California to four felony counts of selling unregistered securities, receiving a two-year probation sentence.
The market for undisclosed software vulnerabilities, often referred to as zero-days, has historically attracted a diverse group of actors, ranging from legitimate security researchers and academics to charlatans and individuals involved in cybercriminal activities. However, the sector focused on selling offensive security services to government entities typically operates with a higher degree of discretion. While many government contractors engage vulnerability researchers and secure exclusive rights to novel exploits, IRIS C2’s overt and aggressive approach stands out.
KrebsOnSecurity became aware of IRIS C2’s activities when an attendee at a regional cybersecurity conference reported being approached by Wohl and representatives of Calvexa Group regarding the sale of their vulnerability research.

Wohl’s Perspective and Claims of Technical Prowess
In an interview with KrebsOnSecurity, Wohl asserted that Jack Burkman is not involved in the day-to-day operations of IRIS C2. Wohl stated that the company initially focused on penetration testing but recently shifted its emphasis to providing phone-hacking services to the government. He repeatedly alluded to working on federal government contracts but declined to provide specific details, citing confidentiality restrictions.
Wohl admitted to lacking formal education or training in computer science or information security, describing his expertise as largely self-taught. He confidently claimed, "I know more about tech than anyone. My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin."
He further explained that security researchers frequently submit vulnerability findings to IRIS C2, though many are preliminary. "Let’s say someone finds a flaw in a media decoder on a phone," Wohl elaborated. "A lot of times what we receive is an exploit primitive, where the idea is there but the [execution] needs work. You need that exploit to be stable and reliable, and that’s what we do."
Wohl estimates IRIS C2 employs approximately 40 individuals, though none are permitted to publicly disclose their affiliation on platforms like LinkedIn for "operational security reasons." This clandestine operational posture mirrors a previous disclosure from the author of the IRIS C2 X account, who mentioned his girlfriend was unaware of his professional activities. The lack of transparency regarding Wohl’s own history and true identity raises further concerns for potential employees and partners.
The LobbyMatic Deception and Pseudonymity
A September 2024 report by Politico revealed that Burkman and Wohl had been promoting their now-defunct company, LobbyMatic, which purported to utilize artificial intelligence for political lobbying. Politico’s investigation uncovered that the pair operated LobbyMatic under pseudonyms, with Wohl reportedly using "Jay Klein" and Burkman employing "Bill Sanders." The report indicated that at least two former LobbyMatic employees resigned after discovering their employers’ true identities, while others learned of the deception only after their departure.
Allegations of Facilitating Cryptocurrency Fraud
An update to the initial reporting highlighted a March 31 publication by journalist Molly White, which detailed that Burkman and Wohl had received a $300,000 retainer from a Canadian cryptocurrency fraudster wanted by U.S. authorities and several other nations. This individual is accused of defrauding crypto platforms KyberSwap and Indexed Finance of $65 million. According to White’s report, Burkman and Wohl were hired to pursue a "presidential pardon to avert a miscarriage of justice" on behalf of the accused hacker, who had not yet been convicted at the time of the retainer agreement.

Implications for the Cybersecurity Ecosystem
The emergence of IRIS C2, with its high-stakes financial incentives and the controversial backgrounds of its operators, raises significant questions for the cybersecurity industry and government procurement. The practice of acquiring zero-day exploits is a sensitive area, with legitimate government contractors and security firms operating within strict ethical and legal frameworks. The overt nature of IRIS C2’s solicitation, coupled with the operators’ history of deceptive practices and legal entanglements, suggests a potential disregard for these established norms.
The implications are multifaceted:
- Erosion of Trust: The involvement of individuals with a history of fabricating information and engaging in fraudulent activities could undermine trust in the broader cybersecurity market, particularly for those seeking to sell offensive capabilities to government entities.
- National Security Risks: If IRIS C2 were to successfully acquire and weaponize zero-day exploits without robust oversight, it could present significant national security risks, potentially exposing critical infrastructure or sensitive government systems to exploitation.
- Ethical Considerations: The recruitment strategy, seemingly prioritizing raw talent over ethical vetting, could inadvertently onboard individuals who may be unaware of the full scope of IRIS C2’s operations or the past misconduct of its leaders.
- Regulatory Scrutiny: The aggressive business model and the operators’ past legal issues are likely to attract increased scrutiny from regulatory bodies such as the FCC, SEC, and potentially intelligence agencies concerned with the acquisition of offensive cyber capabilities.
The cybersecurity landscape is in constant evolution, and the demand for sophisticated offensive tools remains high. However, the manner in which IRIS C2 is attempting to enter this market, leveraging substantial financial inducements while being helmed by individuals with a checkered past, underscores the critical need for due diligence and transparency in the procurement of such sensitive technologies. The confluence of advanced technological pursuit with a history of deception and legal infractions presents a complex and potentially perilous scenario for all stakeholders involved.







