Exposing IRIS C2: Inside the High-Stakes, Low-Credibility Zero-Day Startup Run by Jacob Wohl and Jack Burkman

Share
Exposing IRIS C2: Inside the High-Stakes, Low-Credibility Zero-Day Startup Run by Jacob Wohl and Jack Burkman

Executive Overview

The shadowy global ecosystem of offensive cyber-espionage and zero-day vulnerability trading is traditionally characterized by high-end discretion, cryptographic anonymity, elite technical talent, and multi-million-dollar government contracts negotiated behind closed doors. Yet, in early 2025, a new player abruptly shattered these time-tested protocols. Operating under the banner of IRIS C2, a self-professed McLean, Virginia-based startup, a public-facing entity began aggressively dangling eye-watering bounty payouts—ranging from $10,000 to upwards of $7 million—for previously unknown software vulnerabilities, exploit chains, and remote code execution primitives across all major consumer operating systems.

On platforms like X (formerly Twitter) and LinkedIn, IRIS C2 positioned itself as a premier technical brokerage, inviting the world’s most brilliant, anti-establishment software hackers and vulnerability researchers to bypass traditional university requirements in pursuit of astronomical financial compensation. However, a deep-dive investigative probe reveals a jarring reality behind the venture’s high-tech facade: IRIS C2 is not an elite Silicon Valley or Beltway defense contractor. Rather, it is the latest shell game operated by Jacob Wohl and Jack Burkman, a pair of notorious, far-right political operatives, serial fraudsters, and convicted felons.

Famed across American political and legal history for orchestrating elaborate disinformation campaigns, fake intelligence firms, racist voter-suppression robocalls, and fraudulent AI lobbying platforms under pseudonyms, Wohl and Burkman have now pivoted their attention to the multibillion-dollar offensive cybersecurity marketplace. While Wohl insists that the venture is actively developing mobile-hacking capabilities for federal government agencies, cybersecurity experts and investigative journalists warn that IRIS C2 represents a collision between high-stakes digital exploitation and low-brow political charlatanism, leaving the industry questioning whether the startup is a legitimate supplier of cyber weapons or merely another elaborate grift designed to capture headlines, harvest data, and separate unwary individuals from their intellectual property.


Detailed Chronology: From Disinformation to Digital Exploitation

To fully comprehend the operational anatomy of IRIS C2, it is necessary to examine the rapid chronology of its establishment, alongside the long, winding trail of legal infractions and fraudulent ventures that preceded it.

The Launch of IRIS C2 (January 2025 – Present)

In January 2025, an X/Twitter account operating under the handle @C2IRIS (IRIS C2) materialized online. Capitalizing on the growing global demand for offensive cyber capabilities, the account posted a steady stream of commentary concerning complex software exploits, artificial intelligence, and memory corruption vulnerabilities. Garnering over 4,000 followers in a matter of months, the account’s pinned post laid out a brazen, unconventional recruitment model:

"Our business model is this: Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience."

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Linked directly in its profile was the web domain irisc2[.]com, which listed numerous open engineering roles and touted payouts ranging from five figures to $7 million depending on the target architecture, operational stability, and strategic value of the submitted code. Behind the scenes, corporate records revealed that the domain was operated by a Virginia-based entity called Calvexa Group LLC, which listed an office address in Arlington, Virginia. Physical verification of this incorporation address linked the property directly to Jack Burkman, a well-known local lobbyist. When pressed by investigators, Burkman redirected all inquiries to his long-standing business associate, Jacob Wohl.

A Storied History of Fraud and Political Sabotage

The involvement of Wohl and Burkman immediately injects a severe credibility crisis into IRIS C2. Over the past decade, the duo has built a reputation for orchestrating bizarre, highly publicized disinformation campaigns that frequently culminated in civil penalties, federal fines, and felony criminal convictions:

  • The 2015 "Wohl of Wall Street" Debacle: Beginning his career as a teenager, Jacob Wohl founded multiple short-lived investment firms, cultivating a media-friendly persona on television programs. In 2017, the Arizona Corporation Commission charged Wohl and his funds with 14 counts of securities fraud, ordering him to pay $35,000 in restitution. By 2019, Wohl pleaded guilty in California to four felony counts of selling unregistered securities, receiving two years of probation.
  • The 2018–2020 Smear and Disinformation Campaigns: Wohl and Burkman gained national infamy for founding fake intelligence companies designed to frame high-profile public figures. This included orchestrating fabricated sexual assault allegations against then-FBI Director Robert Mueller and South Bend Mayor Pete Buttigieg, as well as holding press conferences falsely alleging extramarital affairs by Senator Elizabeth Warren and then-presidential candidate Kamala Harris.
  • Voter Suppression and Felony Robocalls: In the wake of the 2020 presidential election, the duo executed a massive disinformation campaign, broadcasting thousands of robocalls to residents in swing states with false claims regarding mail-in voting. They were indicted in Cleveland on 15 felony counts for an explicit scheme to suppress Black voter turnout in Detroit. In late 2025, after exhausting appeals, they were sentenced to probation. In 2022, both pleaded guilty to a single felony count of telecommunications fraud in Ohio, receiving fines, probation, and community service.
  • Federal Civil Rights and FCC Penalties: In March 2023, a New York civil court judge ruled that Wohl and Burkman had violated both federal and state civil rights laws via their voter intimidation tactics, resulting in a $1 million settlement agreement. Shortly thereafter, in June 2023, the Federal Communications Commission (FCC) levied a staggering $5.1 million fine against the pair—at the time, the largest penalty ever sought by the agency under the Telephone Consumer Protection Act.
  • The LobbyMatic Pseudonym Scandal: Shifting tactics into artificial intelligence, Wohl and Burkman launched LobbyMatic, an AI-powered political lobbying platform. However, a September 2024 investigation by Politico revealed that the duo was running the entire operation under false names—Wohl utilizing the pseudonym "Jay Klein" and Burkman adopting the moniker "Bill Sanders." Multiple employees resigned upon discovering the true identities of their employers.
  • The Crypto Pardon Retainer: In March 2025, investigative journalist Molly White reported that Burkman and Wohl had accepted a $300,000 retainer from a Canadian cryptocurrency fraudster. Wanted internationally for allegedly executing a $65 million hack against decentralized finance platforms KyberSwap and Indexed Finance, the fugitive hired the pair to lobby for a presidential pardon.

Supporting Context & Metrics

The market for zero-day vulnerabilities—software flaws known only to the vendor or independent discoverers—is a multi-million-dollar industry. It operates across a broad spectrum, ranging from ethical bug bounty platforms (such as HackerOne and Bugcrowd) and defensive security research firms to offensive brokers (like Zerodium or the Exodus Intelligence agency) and state-sponsored espionage contractors.

The Defensive vs. Offensive Cyber Economy

Within this ecosystem, traditional government contractors and offensive security firms generally maintain a strict veil of confidentiality. They cultivate deep relationships with academic cryptographers, reverse engineers, and institutional software analysts through rigorous vetting processes, compliance checks, and legal frameworks designed to prevent the proliferation of dangerous cyber weapons to rogue actors or hostile nation-states.

By contrast, IRIS C2’s entry into the market has been remarkably ostentatious. Metrics regarding their digital footprint highlight a swift, albeit controversial, ascent:

  • X/Twitter Growth: More than 4,000 targeted followers amassed in less than six months of active posting.
  • Bounty Valuation Scale: Advertised payouts ranging from $10,000 for rudimentary bug primitives up to $7 million for fully functional, stable remote code execution exploit chains capable of bypassing modern operating system mitigations (such as pointer authentication, sandboxing, and memory encryption).
  • Corporate Shell Linkages: Calvexa Group LLC, registered as a federal contractor on portals like g2exchange.com, maintains an active registration status despite possessing no publicly verifiable, direct federal prime contracts.

Despite boasting about an overwhelming influx of job applications via LinkedIn and maintaining a purported workforce of approximately 40 employees, the operational reality appears far more insular. Wohl has noted that none of IRIS C2’s purported employees are permitted to list their employment on professional networking platforms due to "operational security concerns"—a convenient excuse that mirrors the secretive structuring of their previous short-lived tech ventures.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Official Statements and Investigative Interviews

When confronted by security journalist Brian Krebs regarding the true nature and backing of IRIS C2, Jacob Wohl offered a mixture of bravado, technical self-aggrandizement, and defensive denials.

Jacob Wohl’s Defense and Technical Claims

During the interview, Wohl sought to distance Jack Burkman from the day-to-day administrative burdens of the cyber startup, asserting that Burkman is not actively involved in IRIS C2’s core operations. According to Wohl, the enterprise originated as a conventional penetration testing provider before pivoting aggressively toward the development and acquisition of mobile-device hacking capabilities intended for federal government consumption.

When pressed for specific details regarding active government contracts or institutional clients, Wohl invoked operational secrecy, stating he was "not at liberty to speak publicly" about federal engagements.

Crucially, Wohl freely admitted that he possesses no formal academic background, university degree, or professional certification in computer science, software engineering, or information security. Instead, he claimed his technical acumen is entirely self-taught.

"I know more about tech than anyone," Wohl boasted during the interview. "My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin."

Detailing the firm’s acquisition pipeline, Wohl explained how vulnerability researchers frequently pitch preliminary, unrefined research to the company:

Felons, Fraudsters Flog Offensive Cybersecurity Startup

"Let’s say someone finds a flaw in a media decoder on a phone," Wohl explained. "A lot of times what we receive is an exploit primitive, where the idea is there but the [execution] needs work. You need that exploit to be stable and reliable, and that’s what we do."

However, security professionals note a stark disconnect between Wohl’s self-proclaimed technical genius and his documented digital footprint. Publicly available code repositories, such as Jacob "Jay" Wohl’s GitHub account (jayglxr), reveal little to no evidence of advanced exploit development, hypervisor escapes, or zero-day kernel research, raising profound questions about whether IRIS C2 possesses the technical competence required to operationalize million-dollar vulnerability chains.


Future Outlook: Implications for the Zero-Day Marketplace

The emergence of IRIS C2 serves as a cautionary tale regarding the lack of regulatory oversight and the blurring lines between legitimate security research and opportunistic grifting in the digital underground.

  1. Vetting Vulnerability Researchers: The zero-day market relies heavily on trust, discretion, and financial solvency. Independent researchers who hand over high-value exploits run the risk of intellectual property theft, non-payment, or unwitting entanglement in illegal brokerage operations if they engage with unverified entities like Calvexa Group LLC.
  2. National Security Concerns: If IRIS C2 is actively attempting to broker offensive mobile exploits to government entities—or conversely, seeking to harvest advanced research from naive junior engineers to resell on international gray markets—it poses potential counterintelligence and supply-chain security challenges. Federal oversight bodies will likely face increased pressure to scrutinize shell companies registered as federal contractors that lack transparent leadership or verifiable past performance.
  3. The Lifecycle of Wohl and Burkman Enterprises: Historically, enterprises founded by Wohl and Burkman follow a predictable trajectory: sensational public launches, rapid media exposure of their fraudulent foundations, regulatory crackdowns, civil lawsuits, and eventual dissolution. Whether IRIS C2 suffers the same fate will depend heavily on whether software security researchers continue to engage with a firm whose leadership’s defining legacy is a series of federal fraud convictions and fabricated public scandals.

Ultimately, while IRIS C2 dangles the alluring promise of million-dollar payouts to entice the next generation of hacking talent, the cybersecurity community has responded with a mixture of skepticism, mockery, and alarm. In an industry where a single line of compromised code can compromise global infrastructure, the presence of two convicted fraudsters at the helm of an offensive cyber startup is a vulnerability that no software patch can fix.

Did you find this story helpful?

Share it with your friends and colleagues on social media.

Share

Leave a Comment

Your email address will not be published. Required fields are marked *