GitHub bans security researcher who posted zero-day Windows exploits
What they're not telling you: Microsoft's GitHub Purge: Who Pays When Bug Bounties Become a Hostage Negotiation Microsoft deleted a researcher's account after he refused to stay silent about unpaid zero-day bounties, then banned him from GitHub when he went public—a move that reveals how market-dominant platforms weaponize their control of infrastructure against the security researchers who sustain their products. The researcher known as Nightmare-Eclipse, operating under the handle Chaotic Eclipse, reported six zero-day vulnerabilities to Microsoft's Security Response Center (MSRC) beginning in April. According to Eclipse's own accounting, Microsoft either ignored these reports or refused to pay bounties totaling what Eclipse claims amounts to significant financial harm.
What the Documents Show
In response, Eclipse published BlueHammer, an unpatched zero-day exploit, without prior warning. Microsoft's reply was algorithmic: the company deleted Eclipse's Microsoft research account, then escalated by banning his GitHub account entirely—the primary distribution point for security research in the developer economy. Here's what matters: the MSRC bug bounty program offers up to $30,000 to $100,000 per endpoint zero-day, scaling to $250,000 for Hyper-V vulnerabilities. These are not academic figures. They represent Microsoft's declared valuation of the work required to find critical security flaws before hostile actors do.
Follow the Money
Yet the mechanics of that bounty program remain opaque. Microsoft decides unilaterally whether a report qualifies, whether payment is warranted, and how long researchers wait for answers. There is no appeals process with independent arbitration. There is no regulatory oversight. There is no published timeline of payment disputes. Eclipse's language in public statements is raw and suggests genuine financial desperation.
What Else We Know
He claims Microsoft told him personally "they will ruin my life and they did." He references a dead-man switch—implying additional exploits are staged for automatic release. He states directly: "I got zero pennies from doing so." Whether Eclipse's account of events is complete or emotionally heightened, the underlying structure is clear: a researcher discovered critical security gaps in products used by millions of enterprises and government agencies, reported them through the official channel, received either silence or rejection, and then faced account deletion and platform banning when he went public. The GitHub ban is the telling detail. GitHub, owned by Microsoft since 2018, hosts the infrastructure through which the global security research community coordinates vulnerability disclosure, peer review, and remediation. By deploying that ownership stake as a weapon against a researcher disputing payment terms, Microsoft converted a key piece of the internet's security backbone into a leverage point in a commercial dispute. The researcher moves to GitLab.
Primary Sources
- Source: Hacker News
- Category: Corporate Watchdog
- Cross-reference independently — don't take our word for it.
Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.