The global market for zero-day software vulnerabilities—previously unknown software flaws traded for millions of dollars by brokers, intelligence agencies, and elite security researchers—has long operated in the shadows. It is an ecosystem populated by mathematicians, reverse-engineering virtuosos, state-sponsored contractors, and shady intermediaries. However, a newly emerged startup operating under the moniker IRIS C2 has broken all traditional conventions of this secretive industry. Promising multi-million dollar payouts for high-value software exploits, the firm has leveraged social media platforms like X (formerly Twitter) and LinkedIn to aggressively recruit self-taught engineering talent, boasting about its capacity to acquire vulnerabilities across all major platforms.
Yet, an investigative look behind the curtain reveals a startling reality: IRIS C2 is not the brainchild of seasoned defense contractors or veteran computer scientists. Instead, corporate registration documents, government contracting registries, and physical surveillance tie the Virginia-based operation directly to Jacob Wohl and Jack Burkman. These two figures are infamous far-right conspiracy theorists, convicted felons, and serial fraudsters whose track records include orchestrating voter suppression robocalls, manufacturing fake sexual assault allegations against political figures, and deploying fraudulent AI-driven lobbying fronts under assumed names.
The entry of Wohl and Burkman into the offensive security sector raises urgent questions regarding the vetting processes of government contractors, the lax oversight of federal procurement registries, and the security implications of unqualified, litigious operatives attempting to handle critical cyber capabilities. This report details the genesis of IRIS C2, explores the background of its operators, analyzes its recruitment mechanics, and contextualizes the broader risks associated with this strange corporate reincarnation.
Detailed Chronology: From Fake Intelligence to Zero-Day Brokering
To understand how a pair of notorious political hoaxsters landed in the high-stakes world of software exploits, one must trace the timeline of their successive business ventures—each more audacious than the last.
The Foundation of IRIS C2
In January 2025, a new account appeared on X under the handle @C2IRIS, branding itself as IRIS C2. Operating out of McLean, Virginia, the account quickly amassed over 4,000 followers by posting continuous commentary regarding artificial intelligence, software exploits, and cybersecurity vulnerabilities.
The startup’s pinned post laid out a distinctively unorthodox business model:
"Our business model is this: Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience."
Linked within the profile was the domain irisc2[.]com, a website showcasing open hiring positions alongside a pricing tier for software exploits. According to the site, IRIS C2 actively purchases "zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms," with payouts scaling wildly from $10,000 to $7 million depending on operational value and reliability.
The Calvexa Group Connection
Financial and government contracting databases provide crucial insight into the legal vehicle driving this enterprise. According to federal contracting portal g2exchange.com, irisc2[.]com is operated by a Virginia-based entity called Calvexa Group LLC. Visitors attempting to access the corporate website for Calvexa Group (calvexagroup[.]com) are automatically redirected to the IRIS C2 page. While Calvexa Group LLC is officially registered as a federal contractor, government procurement tracking indicates that it currently holds no direct government contracts.
A public records search mapping the Arlington, Virginia address listed in Calvexa Group’s incorporation paperwork led investigators directly to Jack Burkman, the 60-year-old managing partner of Burkman & Associates. When approached for comment regarding the true nature of IRIS C2, Burkman deflected and directed inquiries to his long-standing business associate, 28-year-old Jacob Wohl.
The LobbyMatic Precursor
IRIS C2 is merely the latest iteration in a long line of pseudonymous corporate setups run by the duo. In September 2024, investigative reporting by Politico exposed that Wohl and Burkman were operating a now-defunct AI-powered political lobbying platform called LobbyMatic.
While bragging to prospective clients about major corporate accounts, the pair operated entirely under assumed names: Wohl used the pseudonym "Jay Klein," while Burkman went by "Bill Sanders." The deception unraveled when internal employees discovered their true identities, prompting multiple resignations.
The Crypto Pardon Retainer
Further complicating their recent professional maneuvers, reporting published in March 2025 by journalist Molly White revealed that Burkman and Wohl had accepted a $300,000 retainer from a Canadian cryptocurrency fugitive. Wanted by the United States and international law enforcement for allegedly stealing $65 million from decentralized finance platforms KyberSwap and Indexed Finance, the unconvicted hacker hired the pair to aggressively lobby for a "presidential pardon to avert a miscarriage of justice."
Supporting Context & Metrics: A History of Legal Fallouts and Fraud
The operators behind IRIS C2 carry a staggering paper trail of civil judgments, criminal indictments, and federal regulatory fines spanning over a decade.
Financial Fraud Origins
Jacob Wohl’s entry into public life began before he was out of his teens. By age 17, he had established several investment funds and cultivated the moniker "Wohl of Wall Street" following an appearance on Fox News.
2017: The Arizona Corporation Commission charged Wohl and his investment entities with 14 counts of securities fraud, ordering him to pay $35,000 in restitution.
2019: Wohl pleaded guilty in California to four felony counts of selling unregistered securities, receiving two years of probation.
Political Hoaxes and Defamation
Wohl and Burkman gained national notoriety for orchestrating smear campaigns and fake intelligence operations aimed at derailing high-profile political figures:
Fabricated sexual assault allegations against then-FBI Director Robert Mueller and Democratic presidential candidate Pete Buttigieg (2019).
Press conferences featuring actors paid to push false claims regarding extramarital affairs involving Senator Elizabeth Warren and then-candidate Kamala Harris.
Voter Suppression and Federal Penalties
Following the 2020 U.S. presidential election, the pair scaled their operations into systemic voter suppression. Operating robocall campaigns across battleground states, they disseminated false claims warning residents that mail-in ballots would be used by law enforcement to collect outstanding debts and by credit companies to track citizens.
Cleveland Indictment: Indicted on 15 felony counts for orchestrating a robocall scheme specifically designed to suppress the Black vote in Detroit. In late 2025, after exhausting appeals to dismiss the charges, they were sentenced to probation.
Telecommunications Fraud Plea: In 2022, both men pleaded guilty to felony telecommunications fraud in Ohio, incurring fines, probation, and mandatory community service.
Civil Rights Judgments: A March 2023 New York civil ruling found the pair liable for violating federal and state civil rights laws, resulting in a $1 million settlement agreement.
The Record FCC Fine: In June 2023, the Federal Communications Commission (FCC) levied a $5.1 million fine against Wohl and Burkman—marking the largest penalty ever sought by the agency under the Telephone Consumer Protection Act.
Official Statements and Operator Claims
During an interview with cybersecurity journalist Brian Krebs, Jacob Wohl attempted to distance Jack Burkman from the day-to-day administrative burdens of IRIS C2, asserting that Burkman is not involved in its routine operations.
Wohl stated that IRIS C2 initially launched as a conventional penetration-testing outfit before pivoting toward selling mobile-hacking capabilities directly to the federal government. Throughout the discussion, Wohl repeatedly alluded to ongoing federal contracts, though he ultimately declined to provide concrete specifics, citing national security sensitivities and non-disclosure obligations.
When questioned about his technical qualifications, Wohl freely admitted that he holds no formal degrees, certifications, or academic training in computer science or software engineering, characterizing his expertise as entirely self-taught.
"I know more about tech than anyone," Wohl boasted during the interview. "My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin."
Regarding vulnerability acquisition, Wohl explained that researchers frequently pitch raw, unpolished concepts rather than fully weaponized zero-day exploits:
"Let’s say someone finds a flaw in a media decoder on a phone. A lot of times what we receive is an exploit primitive, where the idea is there but the execution needs work. You need that exploit to be stable and reliable, and that’s what we do."
Wohl claimed that IRIS C2 currently employs approximately 40 people. However, he maintained that operational security protocols prohibit these workers from listing their employment on professional networks like LinkedIn—a policy that conveniently shields employees from discovering their employer’s extensive history of legal fraud and alias usage.
Future Outlook: Risks to the Offensive Cyber Ecosystem
The public emergence of IRIS C2 highlights critical vulnerabilities within the commercial cyber-arms pipeline. While traditional vulnerability brokers—such as Zerodium, Crowdfense, and various defense contractors—operate with strict compliance frameworks, robust legal oversight, and established technical vetting, the ecosystem remains vulnerable to opportunists seeking to monetize high-value exploits.
Several critical concerns define the trajectory of this venture:
Supply Chain and Operational Security Risks: If IRIS C2 is actively pooling raw exploit primitives from junior developers without formal oversight, the risk of data leakage, improper code handling, and espionage exposure multiplies significantly. Unvetted brokers operating under pseudonyms or shell companies create massive counterintelligence liabilities.
Regulatory Scrutiny: Given Wohl and Burkman’s multi-million dollar liabilities with the FCC, civil rights plaintiffs, and state prosecutors, regulatory bodies and financial institutions are likely to scrutinize Calvexa Group LLC’s banking relationships and corporate filings.
The Talent Pipeline Trap: By targeting impressionable, self-taught junior engineers who lack industry mentorship or legal guidance, operations like IRIS C2 risk drawing young talent into legally and ethically perilous arrangements under false pretenses.
As cybersecurity researchers continue to monitor the @C2IRIS social media footprint and associated infrastructure, the episode serves as a cautionary tale: in an industry dealing in cyber weapons capable of compromising global digital infrastructure, the line between legitimate defense contracting and grifter opportunism has become dangerously blurred.