PDF

VMark: A Market for Cyber Risk Settled on Proof of Capability

Omar Bohsali

28 August 2026

Abstract. Cyber risk is unique among major risk classes: the capability to cause a loss can be demonstrated without causing it. Credit default swaps pay after default, parametric catastrophe contracts pay after a physical threshold is crossed, and insurance pays after a claim. We propose a market that uses this proof of capability as the settlement event. An operator lists a named system, which we call a realm, thereby authorizing in-scope, non-destructive tests of published types. Participants take long or short positions on whether a valid proof against that realm will be verified before a stated time. The party that can produce the proof takes the short, notifies the operator privately, and is paid when the proof is verified. No separate finder’s fee is used. The same instrument pays for a hole in one system and for a zero-day in a component shared by many: a researcher who finds a widely deployed flaw can take the short on every listed realm on which it can be demonstrated, then submit. The resulting price is whether a qualifying proof will be verified, not expected loss. As long as only in-scope, non-destructive proofs settle, a researcher ought to find it more profitable to trade the proof than to cause the corresponding harm.

1 Introduction

Cyber defense is presently organized around prevention, after-the-fact insurance, and vendor-run bounty programs. While these work well enough for many incidents, they do not produce a price for residual exposure on a named system. Bounty payments are set by the vendor. Insurance pays after loss and typically excludes the correlated events that matter most. Purchasers of vulnerabilities on illicit markets do not publish prices. Recent proposals for a collective response to AI-enabled attacks have emphasized tools, funding, and coordination [1]. They do not specify a settlement event that would allow capital to move before the loss.

What is needed is an instrument that can be priced continuously and that pays on evidence that a loss was available, not on the loss itself. In this paper, we propose such an instrument. We rely on a property of digital systems that other major risk classes do not share: capability can be shown without the act. We call this Rule 1. The market we describe has one contract, two locked pools, and no leverage. Settlement is a verified, non-destructive proof. The pools are parimutuel because the researcher may already know the answer. VMark is a centrally operated market, not a cryptocurrency protocol.

2 Proof of Capability

We define a proof of capability as a non-destructive, independently reproducible demonstration that a specified attack would have succeeded on a listed realm. The proof must not itself cause the harm it demonstrates. Ordinary instruments cannot use this kind of evidence. A credit default swap cannot pay because a borrower could have defaulted; it pays because they did. A catastrophe bond cannot pay because a hurricane could have formed. In cyber, the analogue of default can be exhibited in advance. Rule 1 is this fact: cyber is the only major risk class in which the loss can be proven possible without the loss occurring. That holds where a non-destructive marker can stand in for the protected action.

The marker must represent the contracted capability, not a nearby harmless act. Permission to write only a reserved DNS name is not proof of control over the zone. A request that can fire a beacon is not proof of remote code execution. The private disclosure has to show that the same unauthorized path could have done the protected thing.

Earlier designs settled on a different event. Exploit derivatives pay if an exploit occurs [2]. Bug bounties pay an amount chosen by the vendor. Insurance-linked securities pay after insured loss. Equity-factor constructions infer cyber risk from the prices of other assets. None of these settle on a non-destructive proof against a named realm.

The first market should start with markers anyone can check. The cases below are those.

3 Examples

Each case names what is protected, what the researcher publishes, and what does not count as a proof.

DNS zone

An operator lists a domain, say example.com, and names the records that would actually matter if they changed: the zone apex, www, mail exchangers. A researcher who can write the zone does not touch those records. They write a signed TXT at _vmark.example.com containing the contract, a nonce, and the hash of a private disclosure. Anyone can query it: dig TXT _vmark.example.com.

The lookup shows that the zone can be written. It does not show that the path was unauthorized. The disclosure has to show that the same credentials or exploit could have changed a named protected record, and that they did not. An employee using the official registrar console to write _vmark produces the marker and fails the proof. A listing may use a reserved CNAME instead of TXT; the test is the same.

Signing key

An operator lists a named key: a wallet, a code-signing key, a TLS private key. Unauthorized use of that key would be the loss—funds moved, malware shipped, certificates issued. The researcher does none of those things. They sign a message that exists only for this contract: the realm, the tenor, a nonce, and the hash of the disclosure. Anyone who has the public key can check the signature. Funds stay put. Nothing is issued. Production state does not change.

A signature produced under the operator’s dual-control procedure is not a proof. A signature over some other message is not a proof. The nonce binds the claim to this contract, so a signature harvested from elsewhere does not settle. The disclosure has to show that the key was used through an unauthorized path.

Restricted file

An operator lists write access at a named host, container, or privilege boundary—the kind of access that, used fully, would be ransomware or a webshell. The researcher writes a small signed file at a reserved path, for example /var/lib/vmark/proof.txt, or an object in a bucket that should not have been writable. The file holds the contract, the nonce, and the hash of the disclosure. It is removable. It does not encrypt anything, and it does not leave that path. Anyone who can fetch the path can see that it landed.

Write access to a world-writable scratch directory is not remote code execution. The disclosure has to show that the method crossed the contracted boundary, not a permission that exists only to write the marker.

Web origin

An operator lists a production website: the pages and responses a customer actually gets. The researcher does not deface it. They place a reserved, inert change at that origin. Three forms are equivalent if the listing names them:

Anyone can fetch the page or the headers and look. The visible customer experience does not change. A server-side request that can fire a beacon from some other host is not proof of origin write. A compromised analytics tag that can load a pixel is not proof of control over the site unless that tag is the contracted boundary. The disclosure has to show that the method used the same content or deployment authority that protects the origin.

Canary secret

An operator lists read access within a named secret boundary: a vault path, a production database role, an identity-provider secret. They place a rotating canary in that boundary and nowhere else. The researcher authenticates or calls back using the current canary. They do not dump customer secrets. They do not use any other secret. The callback is checkable. The canary rotates, so a copy taken last month does not settle this tenor.

Presenting a canary that leaked through an authorized channel is not a proof. The disclosure has to show that the canary was obtained through the unauthorized method, and that the same method could have read a protected secret in the same boundary.

Other surfaces

The same pattern applies wherever a small, attributable state change can stand in for the protected action. A listed contract can require a 0-value call or a signed event rather than a drain. A listed network can require a beacon from an address in that block rather than ransomware. A listed account can require a reserved post rather than a takeover. Those can wait until the marker is as easy to check as a public DNS record. The first market should list the cases above.

4 Listing

A realm is a named digital surface an operator is willing to have priced: a domain, a cloud organization, a product, a network, or a combination of these. The operator must prove control of it. Listing is authorization only for the assets the operator names, and only for the published proof classes. Proofs of those types, against the listed surface, within stated bounds, are in-scope tests. Third-party systems and data remain out of scope unless their operators separately authorize testing. Proofs outside those bounds do not settle and are not authorized by the listing.

A realm cannot be listed by a third party. A government, laboratory, or insurer may put up capital, but it cannot authorize a test on someone else’s system.

Operators list because the alternative is the status quo, in which a party who has found a hole has no legal book on which to trade that information at a market price. Listing also gives the operator private notice of a valid proof and an opportunity to remediate before details are public. Systems that remain unlisted continue to be exposed to the residual market that already exists; the listing does not create that market.

Under-resourced operators, such as some hospitals and water utilities, can list with a sponsor on the other side of the book. The sponsor’s capital is what makes looking at that realm worth a researcher’s time. This is distinct from a grant. The contract pays if a proof is produced.

5 The Contract

For each listed realm, proof class, and tenor T, there is one contract: a valid proof of capability against the realm will be verified before T. There is no second instrument for researchers and no administered finder’s fee.

The contract has two fully collateralized pools. Let S be short capital and L be long capital. If a proof is verified, the shorts get their capital back and divide L. Each dollar short earns L/S. If no proof is verified before T, the longs get their capital back and divide S. Each dollar long earns S/L. Capital, once committed, remains locked until settlement or expiry.

Suppose the long pool contains $1,000,000 and the short pool contains $100,000. If a proof lands, each dollar short earns $10. A researcher who puts up $100,000 earns the $1,000,000 long pool. If no proof lands, each dollar long earns ten cents. The pool ratio S/(S + L) is the price: 9.1 percent in this example, before fees. That number is the market’s price of a verified proof before T on this contract. It is not the probability of a breach and not expected loss.

More short capital lowers the return to every short. If another $900,000 joins the short pool, S rises to $1,000,000 and each dollar short earns $1 instead of $10. The informed participant changes the price against themselves. No market maker is required to keep selling at the old price. The researcher need not put up all of the short capital. Information and money can be different parties, as in other markets.

Anyone may take either side, subject to the market’s trading rules. A researcher who knows a class of devices, an insurer with claims experience, and an operator who has just rotated a key all enter the same pools.

VMark operates the market directly. It holds the collateral, records the positions, closes the books, checks the proofs, and pays the winners. A claimant also posts a separate bond, so that freezing books is not free.

6 Settlement

The steps are as follows:

  1. The researcher prepares a disclosure document D describing the method, computes its hash, and prepares the public marker.
  2. The researcher sends VMark one instruction containing the short positions, the hash of D, and the claim bond. Either all of the positions are accepted or none are. VMark closes every named book before any realm is notified.
  3. The researcher publishes the signed marker and immediately sends D privately to VMark.
  4. The proof is checked. Did the committed method cause the marker? Was it in scope, non-destructive, and reproducible? If so, the contract settles and the short pool is paid. If not, the contract reopens and the researcher’s short capital remains at risk through T.
  5. Exploitable detail remains with the operator. The market is informed that a proof of a given class was verified, not how to repeat the attack.

A proof that causes harm is invalid. A proof outside the listed scope is invalid. A ransom note is not a proof. Exfiltrated data is not a proof.

This single instruction limits the interval between position and disclosure. It also stops the first notice from giving away the rest of the trade. If one flaw reaches many listed realms, the books close together and the operators are notified together. Some delay remains possible before the instruction reaches VMark, as it does in ordinary vulnerability research. The alternative is not always immediate disclosure. The same fact may otherwise be hidden, sold, exploited, or never found. The market works if prompt disclosure pays best.

7 Verification

A compromise is, to most observers, invisible. That is why cyber risk is hard to price: the loss can be available for months without anyone outside the operator—and often inside it—having a checkable fact. Rule 1 supplies that fact.

Many proof outcomes are publicly observable. Anyone can query a DNS TXT record. Anyone can request a public page and look for a reserved header, a hidden element, or a 1-by-1 pixel that calls back with a nonce. Anyone can fetch a marker file from a misconfigured bucket. A lookup verifies that the marker landed. It does not, by itself, establish that the path was unauthorized or that the committed method caused the outcome. The average person will not make that lookup. Most people do not read certificate transparency logs either. The market does not require that they do. It requires that the evidence be checkable by anyone who cares to check.

There are two things to check. First, the public marker shows the outcome: the record was written, the file appeared, or the key signed. Second, someone still has to check that the committed method caused it. VMark does that check, with the operator’s logs and, where the listing says so, an independent laboratory. A financially interested operator cannot decide the claim alone. The first market should prefer proof types where the outcome is public and the method is easy to confirm.

8 Incentive

Markets of this form are reflexive: the existence of the payout changes the probability of the event [3]. If the event were the harm itself, the market would pay for causing it. A market that paid on the date of a person’s death would pay the person who chose the date [4]. That is the objection usually raised against trading on disasters or crimes.

We choose a different event. Settlement requires a non-destructive proof on a listed realm. The party best able to predict the event is the party able to produce the proof, and producing the proof is disclosure, not attack. The cheapest way to be paid should be the legitimate demonstration. If some cheaper illegitimate path exists, the definition of the proof is wrong and should be tightened.

A party who has a valid proof ought to find it more profitable to take the short and submit the proof than to sell the same fact into an illicit market or to carry out the corresponding attack. Exploitation is operationally costly and legally exposed. It remains possible, as it is today. The market does not need to prohibit it in order to compete with it. It needs to pay.

The payout has two scales. Against one listed realm, a valid proof settles that contract. That is the incentive to look at a particular hospital, water plant, or firm. Against a shared component—a library, a VPN concentrator, an identity provider, a cloud control plane—the same flaw can be demonstrated on every listed realm that depends on it. The researcher commits the short positions as one portfolio and submits the proofs together. Disclosure is simultaneous. The payout is the sum of the long pools. A vendor bounty pays once, at a price the vendor set. A widely deployed zero-day, on this market, is a position in every listed realm on which the flaw can actually be demonstrated.

Bug bounty programs remain useful for vendors who wish to buy patches for software they ship, at prices they set. They do not price residual exposure on a named realm, and they do not let a third party take the other side. The two can coexist.

9 Subsequent Contracts

After settlement of a tenor:

  1. The operator holds the proof privately.
  2. Shorts have been paid.
  3. The operator remediates, or does not.
  4. The next contract on the same realm prices the new state.

If the condition has been removed, parties who believe that commit long capital to the next tenor. If the proof still reproduces, parties who can still produce it commit short capital. The new pool ratio is what an operator, insurer, or regulator can observe. No second contract on whether the operator will patch is required, and no committee scores remediation. An operator who wants a lower short ratio has to earn it on the next tenor.

A researcher who was short into the proof may commit long capital if they believe the fix, or remain short if they do not. The same construction prices discovery and, later, whether the fix held.

10 Objections

An insider could write the DNS record. An authorized administrator making an authorized change is not a proof. An employee bypassing a published dual-control rule may be a proof, if that rule is in scope. An employee who takes a position and then creates the hole is manipulating the market and does not settle. The disclosure and the logs distinguish these cases. The public marker alone does not.

Won’t this pay people, and agents, to find vulnerabilities? Yes. That is the purpose of the instrument.

Who takes the long side? Operators, insurers, governments, and other sponsors can put long capital behind realms they want examined. A trader who believes no valid proof will arrive also goes long. The short pool is the return for being right. If a hospital cannot post long capital, a sponsor’s job is to post it. If no one will, the realm has no funded reward and no meaningful market. That fact is visible.

Is the long pool merely a bounty? From a sponsor’s perspective it is a refundable, market-priced bounty. If a proof arrives, the pool pays for discovery. If none arrives, the sponsor recovers its capital and earns the short pool. The amount paid to each short is not administered. It is determined by the ratio of opposing capital. The researcher must stake capital, risks rejection, and competes with every other short. A sponsor funds the question; the market prices both answers.

Does the ratio measure cyber risk? It measures the price of a verified proof under one contract. A low price may mean a hard realm, a thin long pool, little attention, or an expensive proof. It is not expected loss.

Can a false claimant freeze the market? Closing books requires a claim bond. Frivolous or fabricated claims put that bond at risk. If the proof is rejected, the books reopen.

Won’t this produce more zero-days? Yes. Better they are found here, under Rule 1, than stockpiled. Franklin wrote that three may keep a secret if two of them are dead [5]. The grey market keeps the secret. This market does not.

11 Conclusion

We have proposed a market for cyber risk that settles on proof of capability rather than on loss. We started from the observation that digital harm can be shown without being done. Operators list realms, thereby authorizing in-scope tests against assets they control. Each contract has two locked pools. A valid proof pays the shorts; expiry without a proof pays the longs. The researcher is paid by the book, not by a fee. A shared vulnerability is a short across every listed realm on which it can be demonstrated. Subsequent contracts price whether the condition remains.

The system can begin with a small number of volunteer realms and with proof types that are easy to verify without touching production, such as DNS control and cloud misconfiguration, using designated verifiers and ninety-day tenors. VMark can hold the collateral, close the books, and run settlement directly. The market depends on Rule 1, on a public marker joined to a private disclosure, and on one book that pays for a proof without paying for the harm.

Pool identities, settlement procedure, and the intended regulatory form are in the PDF.

References

  1. [1] OpenAI, “A call for collective action on cyber defense,” 27 August 2026. https://openai.com/collective-cyberdefense
  2. [2] R. Böhme, “Vulnerability Markets: What is the Economic Value of a Zero-Day Exploit?” 22nd Chaos Communication Congress, 2005.
  3. [3] O. Bohsali, “Reflexive Prediction Markets,” July 2026. https://omarish.com/p/reflexive-prediction-markets
  4. [4] J. Bell, “Assassination Politics,” 1995.
  5. [5] B. Franklin, Poor Richard’s Almanack, 1735. “Three may keep a Secret, if two of them are dead.”
  6. [6] Commodity Futures Trading Commission, “Prediction Markets Advisory,” CFTC Letter No. 26-08, 12 March 2026; 17 C.F.R. § 40.11. https://www.cftc.gov/csl/26-08/download
  7. [7] Commodity Futures Trading Commission, “Advisory on Enforcement Authority over Event Contracts,” 25 February 2026. https://www.cftc.gov/media/13351/Enf_AdvisoryKalshi022526/download
  8. [8] U.S. Department of Justice, “9-48.000—Computer Fraud and Abuse Act,” Justice Manual, updated 6 February 2025. https://www.justice.gov/jm/jm-9-48000-computer-fraud