The cybersecurity landscape has recently been unsettled by the emergence of IRIS C2, a startup claiming to offer multi-million dollar payouts for zero-day vulnerabilities while being operated by two of America’s most notorious political operatives and convicted felons. Jacob Wohl and Jack Burkman, a pair known for orchestrating elaborate hoaxes and facing a litany of legal judgments, have transitioned from the worlds of fringe political lobbying and securities fraud into the high-stakes arena of offensive cyber capabilities. Operating under the umbrella of Calvexa Group LLC, the duo’s latest venture seeks to acquire sophisticated software exploits, promising researchers rewards as high as $7 million for tools capable of compromising major operating systems and mobile devices.
The emergence of IRIS C2 marks a significant departure from the traditional, discreet nature of the offensive security market. While established firms in this sector typically maintain a low profile to protect government contracts and operational security, IRIS C2 has adopted a brazen marketing strategy on social media platforms like X (formerly Twitter). Since its inception in January 2025, the company’s account, @C2IRIS, has amassed over 4,000 followers by posting frequently about AI-driven exploits, vulnerability research, and aggressive recruitment drives. The company’s stated goal is to attract "junior engineers with raw talent" and "extremely high IQ," explicitly noting that they do not require formal education or industry experience—a recruitment tactic that critics suggest is designed to target younger, less experienced researchers who may be unaware of the founders’ controversial histories.
The Infrastructure of IRIS C2 and Calvexa Group LLC
The operational core of IRIS C2 is linked to Calvexa Group LLC, a business entity registered in Virginia. According to data from the government contracting portal G2Exchange, Calvexa Group is listed as a federal contractor, though there is no public record of the firm currently holding any direct government contracts. The company’s physical presence is equally elusive; the address listed in incorporation records for Calvexa Group LLC is the Arlington, Virginia, residence of Jack Burkman, the 60-year-old founder of the lobbying firm Burkman & Associates.
The startup’s website, irisc2.com, serves as a digital storefront for what it calls "full chain" capabilities. It lists a pricing structure for exploits across various platforms, including iOS, Android, Windows, and macOS. The promised payouts range from $10,000 for minor primitives to $7 million for reliable, zero-click mobile exploits. This pricing mirrors—and in some cases exceeds—the rates offered by legitimate exploit brokers like Zerodium or Crowdfense. However, unlike these established entities, the internal technical leadership of IRIS C2 remains shrouded in mystery. Jacob Wohl, 28, has claimed in interviews that the firm employs approximately 40 individuals, yet none are permitted to list their affiliation on professional networks like LinkedIn, citing "operational security."

A Decades-Long Chronology of Fraud and Deception
To understand the skepticism surrounding IRIS C2, one must examine the extensive legal and professional history of its principals. Jacob Wohl first gained national attention as a teenager, earning the moniker "Wohl of Wall Street" after appearing on financial news networks to promote his hedge funds. The glamour was short-lived; by 2017, the Arizona Corporation Commission charged Wohl with 14 counts of securities fraud, eventually ordering him to pay $35,000 in restitution. In 2019, Wohl pleaded guilty to four felony counts in California related to the sale of unregistered securities, resulting in two years of probation.
Jack Burkman’s history is similarly marked by controversy. Once a mid-tier lobbyist, Burkman teamed up with Wohl to launch a series of "intelligence" firms designed to smear political opponents. Their track record includes:
- 2018: Attempting to frame then-FBI Director Robert Mueller with fabricated sexual assault allegations.
- 2019: Orchestrating a failed attempt to smear Pete Buttigieg, then a presidential candidate, with similar false claims.
- 2019: Holding press conferences to allege extramarital affairs by Senator Elizabeth Warren and then-candidate Kamala Harris, all of which were debunked as fabrications involving paid actors.
- 2020: Initiating a massive robocall campaign in battleground states during the presidential election. These calls disseminated false information about mail-in ballots, specifically targeting Black communities in Detroit and other urban centers to suppress voter turnout.
The robocall scheme led to significant legal repercussions. In 2022, Wohl and Burkman pleaded guilty to a felony charge of telecommunications fraud in Ohio. In 2023, the Federal Communications Commission (FCC) issued a $5.1 million fine against the pair—the largest fine in the agency’s history for such an offense. Additionally, a New York civil case concluded with the duo agreeing to a $1 million settlement for violating federal and state civil rights laws.
The Transition to "LobbyMatic" and Offensive Cyber
Before launching IRIS C2, Wohl and Burkman attempted to capitalize on the artificial intelligence boom through a company called LobbyMatic. Marketed as an AI-based lobbying platform, the venture collapsed in 2024 after a Politico investigation revealed the founders were running the company using pseudonyms. Wohl operated under the name "Jay Klein," while Burkman used the alias "Bill Sanders." When employees discovered the true identities of their bosses—and their history as convicted felons—many resigned immediately.
The pivot to IRIS C2 appears to be an evolution of this strategy. During an interview, Wohl claimed that he has shifted his focus to selling phone-hacking services to government agencies. Despite having no formal training in computer science, Wohl asserted, "I know more about tech than anyone," and claimed to create "spectacularly exquisite capabilities." These assertions, however, contrast sharply with the reality of the high-end exploit market, which requires deep expertise in memory corruption, reverse engineering, and kernel-level programming—skills that take years of dedicated study to master.

The High-Stakes Market for Zero-Day Exploits
The "zero-day" market—referring to software vulnerabilities unknown to the vendor—is a critical component of modern national security and cyber-espionage. Governments buy these exploits to conduct lawful intercepts or offensive operations against adversaries. Because these tools are "perishable" (they become worthless once the software is patched), the prices are astronomical.
Industry analysts suggest that IRIS C2’s public solicitation of these tools is a "red flag" for the research community. In the legitimate "gray market," trust and reputation are the primary currencies. Researchers who sell to unknown or disreputable brokers risk having their work stolen without payment, or worse, seeing their exploits sold to sanctioned regimes or criminal organizations, which could lead to international legal complications for the developer.
Furthermore, recent reports indicate that Wohl and Burkman have engaged in "mercenary" legal and cyber work. In early 2024, they were reportedly paid a $300,000 retainer by a Canadian cryptocurrency hacker wanted by the United States for a $65 million theft from platforms like KyberSwap. The duo was tasked with seeking a "presidential pardon" for the hacker, further illustrating their willingness to operate on the fringes of the law.
Analysis of Implications and Industry Response
The entry of Wohl and Burkman into the offensive security space presents several risks. First is the potential for "vaporware" or "scamming" within the government contracting space. By leveraging the Calvexa Group’s status as a registered federal contractor, the duo may attempt to secure "set-aside" funds or small contracts based on exaggerated technical claims.
Second, there is the risk of data insecurity. If researchers actually submit code to IRIS C2, there is no guarantee regarding how that sensitive data is handled. Given the founders’ history of using aliases and creating fake companies, the possibility of the firm acting as a front for other interests—or simply as a mechanism to harvest intellectual property—cannot be ruled out.

The cybersecurity community has largely reacted with a mixture of derision and warning. Experts on social media have cautioned vulnerability researchers to perform rigorous due diligence before engaging with any firm offering "too good to be true" payouts, especially those with leadership lacking a verifiable technical pedigree. The consensus among threat intelligence analysts is that IRIS C2 represents a "rebranding" of the same deceptive tactics Wohl and Burkman have employed for a decade, now applied to a more technical and dangerous domain.
Conclusion
The transformation of Jacob Wohl and Jack Burkman from political provocateurs into self-styled "cybersecurity moguls" serves as a cautionary tale about the lack of oversight in the private exploit market. While IRIS C2 continues to post about "exquisite capabilities" and million-dollar bounties, the shadow of their past remains their most prominent feature. For the federal government and the global research community, the presence of convicted fraudsters in the offensive cyber supply chain is a development that demands increased scrutiny and a reinforcement of the ethical standards that govern the trade of digital weaponry. As of mid-2025, IRIS C2 remains active online, but its ability to deliver on its lofty promises remains as unproven as the technical expertise of its founders.
