A newly surfaced cybersecurity startup offering multi-million-dollar bounties for high-tier zero-day software vulnerabilities has been unmasked as the latest venture of convicted felons and far-right political provocateurs Jacob Wohl and Jack Burkman.
Operating under the moniker IRIS C2 (promoted via the X account @C2IRIS) and registered through a Virginia entity known as Calvexa Group LLC, the company claims to specialize in acquiring, developing, and reselling advanced offensive cyber capabilities to government clients. Promising payouts ranging from $10,000 to $7 million for working software exploits across major operating systems, IRIS C2 aggressively targets junior vulnerability researchers and self-taught developers.
However, an in-depth investigation reveals that behind IRIS C2’s high-tech veneer lies a pattern of deceit consistent with Wohl and Burkman’s history. Over the past decade, the duo has orchestrated fabricated intelligence firms, high-profile political smear campaigns, illegal voter-suppression robocall schemes, and a pseudonymous AI lobbying company.
Industry experts and government contracting records cast deep skepticism on IRIS C2’s claims of holding federal defense contracts. Instead, the firm’s emergence raises severe red flags across the cybersecurity ecosystem regarding potential research theft, financial misrepresentation, and national security vulnerabilities.
Detailed Chronology: From Financial Fraud to Cyber Offense
The launch of IRIS C2 marks the latest iteration in a documented history of financial schemes, political disinformation, and corporate fabrications executed by Wohl, 28, and Burkman, 60.
+-----------------------------------------------------------------------------------+
| CHRONOLOGY OF OPERATIONS |
+-----------------------------------------------------------------------------------+
| 2015–2017 | Wohl launches early hedge funds; charged with securities fraud (AZ). |
| 2018–2020 | Fabricated intel firms; fake assault claims against public figures. |
| 2019 | Wohl pleads guilty to felony securities fraud in California. |
| 2020–2022 | Battleground state robocall schemes; felony telecom fraud convictions.|
| 2023 | $1M civil rights settlement; landmark $5.1M FCC robocall fine. |
| 2024 | LobbyMatic pseudonym scandal; $300k retainer from crypto hacker. |
| 2025–Pres.| Launch of IRIS C2 / Calvexa Group targeting zero-day researchers. |
+-----------------------------------------------------------------------------------+
1. Early Financial Misconduct (2015–2019)
Jacob Wohl’s history of public misrepresentation began in his late teens. Promoting himself as the "Wohl of Wall Street," he made media appearances discussing his newly established hedge funds.
This enterprise rapidly unraveled:
2017: The Arizona Corporation Commission charged Wohl and his investment vehicles with 14 counts of securities fraud, ordering him to pay $35,000 in restitution.
2019: Wohl pleaded guilty in California to four felony counts of selling unregistered securities, resulting in a sentence of two years’ probation.
2. Fabricated Intelligence Agencies and Disinformation Operations (2018–2020)
Partnering with conservative lobbyist Jack Burkman, Wohl pivoted toward political disinformation. The pair established fictitious intelligence firms—such as "Surefire Intelligence"—which were deployed to stage press conferences and circulate fabricated sexual assault allegations against public figures.
Their targets included:
Special Counsel Robert Mueller
Then-Mayor Pete Buttigieg
Senator Elizabeth Warren
Then-presidential candidate Kamala Harris
These operations relied on paid actors, forged documents, and manipulated domain registrations, establishing a playbook of using fake corporate structures to project influence.
3. Voter Suppression, Felony Convictions, and Federal Fines (2020–2023)
During the 2020 U.S. presidential election, Wohl and Burkman executed a massive robocall campaign targeting Black voters in battleground states, including Michigan, Ohio, and Pennsylvania. The automated calls contained false statements designed to deter recipients from utilizing mail-in ballots.
Criminal Prosecution: The duo was indicted in Cleveland on 15 felony counts. In 2022, both pleaded guilty to felony telecommunications fraud in Ohio, receiving sentences of probation, fines, and community service (with final appellate rejections stretching into late 2025).
Civil Rights Settlement: In March 2023, a New York federal court found that the duo violated state and federal civil rights laws, forcing them to agree to a $1 million settlement.
FCC Enforcement: In June 2023, the Federal Communications Commission (FCC) issued a record-setting $5.1 million fine against Wohl and Burkman under the Telephone Consumer Protection Act.
4. Pseudonymous Ventures and Crypto Retainers (2024)
As legal judgments mounted, Wohl and Burkman adopted false identities to enter new technology markets.
The LobbyMatic Affair: In late 2024, reporting revealed that the pair operated an AI-driven lobbying startup called LobbyMatic under assumed names—Wohl as "Jay Klein" and Burkman as "Bill Sanders." The company collapsed after employees discovered they were working for convicted felons.
Crypto Defense Retainers: In early 2024, the duo secured a $300,000 retainer from an indicted Canadian cryptocurrency hacker accused by U.S. federal prosecutors of stealing $65 million from KyberSwap and Indexed Finance. The duo was hired to lobby for a presidential pardon before the case went to trial.
5. Pivot to Offensive Cybersecurity: IRIS C2 (2025–Present)
In January 2025, the X account @C2IRIS appeared, representing IRIS C2, a self-described offensive security firm located in McLean, Virginia. By mid-2025, the account actively solicited zero-day vulnerability submissions, claiming high payout capabilities backed by government-tier funding.
Supporting Context & Structural Metrics
The Zero-Day Acquisition Model
The market for zero-day exploits—unpatched software vulnerabilities unknown to the vendor—is typically split into three sectors:
White-Hat Bounties: Managed directly by software vendors (e.g., Apple, Microsoft) or platform brokers (e.g., HackerOne) offering transparent rewards and public disclosure timelines.
Defensive/Government Brokers: Established defense contractors (e.g., Lockheed Martin, Raytheon) or specialized brokers (e.g., Zerodium, Crowdfense) that maintain strict non-disclosure, government vetting, and formal legal contracts.
Gray/Black Markets: Illicit channels selling exploits to cybercriminal syndicates or unauthorized state actors.
IRIS C2 positions itself as an aggressive broker within the defense market, advertising compensation tiers designed to attract independent researchers:
Vulnerability Target / Primitive
Advertised Payout Range
Claimed Operational Value
Partial Chains / Isolated Primitives
$10,000 – $100,000
Low to Moderate
Major Mobile OS Exploits (iOS / Android)
$500,000 – $3,500,000
High
Full Zero-Click Remote Code Execution (RCE)
$3,000,000 – $7,000,000
Critical / Exclusive
[Independent Researcher]
│
▼ (Submits Exploit Primitive)
┌─────────────────────────────────────────┐
│ IRIS C2 │
│ (Calvexa Group LLC / Wohl & Burkman) │
└─────────────────────────────────────────┘
│
├─► Payout Claim: $10K–$7M (Unverified)
│
▼ (Resale / Refinement)
[Alleged Federal Government Buyers]
*(G2Exchange records show ZERO active federal contracts)*
Analysis of the Corporate Shell
IRIS C2 lists its operating corporate entity as Calvexa Group LLC. Government procurement analysis reveals a stark contrast between the startup’s marketing claims and its official record:
Incorporation Address: Official state filings for Calvexa Group LLC link back to an Arlington, Virginia address owned and occupied by Jack Burkman’s lobbying firm, Burkman & Associates.
Contracting Status: Federal databases monitored by contracting portal G2Xchange show that while Calvexa Group LLC is registered as a federal vendor entity, it holds zero active or historic federal contracts.
Talent Targeting Strategy: IRIS C2’s social media campaigns specifically target young engineers, explicitly stating: "We don’t care if they have a college degree/industry experience."
Official Statements, Interviews, and Key Claims
When confronted regarding the corporate structure and ownership of IRIS C2, the founders provided evasive and conflicting responses.
Burkman’s Deflection
When initially approached at his Arlington address regarding Calvexa Group LLC and IRIS C2, Jack Burkman declined to answer technical queries directly, redirecting all operational questions to Jacob Wohl.
Wohl’s Assertions and Technical Claims
In a series of direct interviews, Jacob Wohl asserted full operational leadership over IRIS C2 while minimizing Burkman’s daily involvement:
"Mr. Burkman is not involved in the day-to-day operations of IRIS C2. We started originally as a penetration testing company, but shifted our focus recently to selling phone-hacking services to the government."
When pressed on his credentials—given his lack of formal computer science training or industry certifications—Wohl claimed to be self-taught, framing his background in technical terms:
"I know more about tech than anyone. My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin."
Regarding the firm’s business operations, Wohl claimed that IRIS C2 ingests raw research and refines it in-house:
"Let’s say someone finds a flaw in a media decoder on a phone. A lot of times what we receive is an exploit primitive, where the idea is there but the execution needs work. You need that exploit to be stable and reliable, and that’s what we do."
Discrepancies in Workforce and Operational Security
Wohl asserted that IRIS C2 employs approximately 40 full-time personnel. However, he admitted that none of these employees are listed on professional networks like LinkedIn, citing strict "operational security" (OPSEC) protocols.
Industry analysts point out that this secretiveness closely mirrors the structure of LobbyMatic, where employees were kept in the dark about the founders’ true identities and criminal records through the use of pseudonyms like "Jay Klein."
Future Outlook and Risks to the Cybersecurity Ecosystem
The entry of persistent fraudsters into the offensive cybersecurity marketplace presents multi-layered risks for vulnerability researchers, defense contractors, and regulatory bodies.
1. Risk of Exploitation Theft and Non-Payment
The primary threat posed by an unvetted zero-day broker is the potential expropriation of intellectual property. Independent researchers who submit proof-of-concept code or partial exploit primitives to IRIS C2 risk having their research stolen without receiving compensation. Given Wohl’s documented history of securities fraud and financial misrepresentation, security analysts strongly advise against submitting code to unverified platforms.
RISK MATRIX FOR RESEARCHERS & DEFENSE SECTOR
┌─────────────────────────────────────────────────────────┐
│ 1. RESEARCH THEFT: Non-payment for submitted zero-days │
│ 2. LEGAL EXPOSURE: Unlawful transfer of cyberweapons │
│ 3. COUNTERINTELLIGENCE: Misdirection to foreign actors │
│ 4. REPUTATIONAL HARM: Association with convicted felons │
└─────────────────────────────────────────────────────────┘
2. Counterintelligence Concerns
The acquisition of zero-day exploits by an unregulated entity managed by felons presents a clear counterintelligence vulnerability. Advanced exploits purchased or acquired under false pretenses could easily be resold on gray markets or leaked to foreign adversaries, bypassing U.S. export control frameworks like the Wassenaar Arrangement and International Traffic in Arms Regulations (ITAR).
3. Regulatory and Law Enforcement Scrutiny
Given Wohl and Burkman’s ongoing probation terms and substantial unpaid civil judgments (including the $5.1 million FCC penalty), their commercial activities remain under active observation by legal authorities. If Calvexa Group LLC or IRIS C2 misrepresents its government contracting status to investors or vendors, the venture could face immediate federal scrutiny for wire fraud and misrepresentation.
Conclusion
While IRIS C2 attempts to project the image of a high-value defense contractor operating in the shadows of the intelligence community, evidence shows it is an unregulated venture led by serial fraudsters. Security professionals, vulnerability researchers, and government agencies are urged to exercise extreme caution when interacting with IRIS C2, Calvexa Group LLC, or its associated aliases.