Natto Thoughts

Natto Thoughts

China’s Vulnerability Research: What’s Different Now?

China’s bug-hunting scene is maturing - more players, bigger prizes, tighter structure, and a growing focus on domestic products, driven by profit, prestige, and national security.

Eugenio Benincasa's avatar
Natto Team's avatar
Eugenio Benincasa and Natto Team
Oct 08, 2025
∙ Paid

Over the past two decades, China’s vulnerability research ecosystem has undergone a dramatic transformation. In the early 2000s, it was a fragmented landscape of free databases and easily accessible, low-cost exploits. Over time, it evolved toward commercialization, with organized vulnerability markets and institutional research labs emerging within major tech and cybersecurity companies.1 By the mid-2010s, Chinese hackers were competing – and excelling – in global exploit hacking contests2 and bug bounty programs3 to identify weak spots in Western products.

As this ecosystem has evolved, the Chinese state moved to harness the vulnerability research for national priorities through both formal and informal channels. From the top down, it imposed institutional mechanisms such as direct oversight of researchers and regulations that mandate or incentivize reporting to state-run entities. From the bottom up, informal networks among prominent researchers, who exchange insights and acquisition o…

User's avatar

Continue reading this post for free, courtesy of Natto Team.

Or purchase a paid subscription.
© 2026 Natto Thoughts · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture