GitHub Bans Security Researcher Who Published Windows Zero-Day Exploits

The researcher known online as Chaotic Eclipse and Nightmare-Eclipse has spent months at war with Microsoft. This week, the company, which owns GitHub, cut off one of their accounts, deleting access to the platform where they had published exploit code for a Windows vulnerability the researcher says Microsoft ignored.

The ban, reported by Tom’s Hardware, came after the researcher published a zero-day exploit called YellowKey that bypasses BitLocker drive encryption on Windows 11 using a simple USB key. Microsoft is tracking the flaw as CVE-2026-45585 and has acknowledged the vulnerability, but it has criticized the way the researcher disclosed it.

“The proof of concept for this vulnerability has been made public, violating coordinated vulnerability best practices,” Microsoft said in a statement. The company argued that releasing working exploit code for unpatched flaws puts customers at risk and undermines the private disclosure process that lets vendors fix bugs before attackers weaponize them.

The researcher tells a different story. In a blog post after the ban, they said Microsoft deleted the account they had used to report vulnerabilities through the Microsoft Security Response Center, refused to pay bounties they were owed, and ignored their attempts to communicate. “I got zero pennies from doing so and I still happily did like an idiot,” they wrote. “Now you take the courtesy to flag my GitHub account and wipe it out of the public, just like that?”

The dispute raises a question that has grown more urgent as security research becomes more adversarial: what happens when a researcher follows the disclosure rules, gets no response, and decides the rules no longer apply? Security experts say the gray zone between coordinated disclosure and platform rules is becoming a legal battleground.

The researcher claims to have uncovered six zero-day vulnerabilities and to have been working with Microsoft for years. The YellowKey disclosure, they said, was deliberate: “I could have made some insane cash selling this, but no amount of money will stand between me and my determination against Microsoft.” They have also threatened further disclosures, posting a date in July and promising retaliation.

The episode has divided the security community. Some researchers side with Microsoft, arguing that publishing working exploit code without a patch is reckless and that the researcher’s threats crossed a line. Others see the case as a cautionary tale about vendors who reward reporters poorly and punish them when they go public.

“Researchers weigh whether a process that stays open on paper will still protect a combative submitter during a live dispute,” one security analyst said. “When the platform owner is also the vendor you are reporting to, the conflict of interest is built in.”

Microsoft initially took a hard line, describing uncoordinated disclosures as “never justifiable” and invoking its Digital Crimes Unit, language that researchers said threatened legal action. Under pressure from the community, the company softened its stance days later, saying it had “no intention to pursue action against individuals conducting or publishing their security research” and acknowledging that “some interactions have fallen short.”

The researcher was not mollified. They noted that Microsoft had not addressed the specific allegations: deleted accounts, unpaid bounties, and communications that went unanswered. “I have proof for every single word I said,” they wrote, promising to release documents in the future.

The case is the latest test of how platforms police security research. GitHub has long been the de facto home of exploit code, and its policies walk a line between hosting legitimate research and harboring material that could be used to attack systems. When the platform is owned by the company whose software is being targeted, the questions get harder.

The stakes extend beyond one dispute. Security researchers have long operated on an informal bargain: find the bug, tell the vendor, wait for a fix, then publish. That bargain only works when both sides act in good faith, and episodes like this one erode it. If researchers conclude that reporting to Microsoft risks losing their accounts while publishing openly risks losing their platform, the third option, selling the bug on the gray market, starts to look rational.

Some of the exploits the researcher released have since been used in the wild, according to security researchers tracking the fallout, which complicates the argument for full disclosure. Defenders had no patch ready when the code appeared, and the gap between disclosure and fix is where real damage happens.

For Microsoft, the episode has become a public relations problem as much as a security one. The company built its reputation partly on working with researchers, and its bug bounty program is among the oldest in the industry. A high-profile researcher vowing retaliation, with a disputed bounty claim and a deleted account, is not the image the program’s marketing promises.

For the research community, the lesson is about who holds the cards. Vendors need researchers to find their bugs, and researchers need platforms to publish their work. When one side controls both the bounty program and the platform, the balance of power shifts, and the disclosure process becomes, in the researcher’s words, a fight rather than a partnership. The fight, for now, is not over.

Related Posts

  • September 6, 2026
  • 10 views
Anthropic Moves Its IPO Filing to Late September

The bankers and lawyers running Anthropic’s initial public offering had told investors to expect the company’s registration documents as soon as this week. The calendar has moved. Anthropic now plans…

  • September 6, 2026
  • 8 views
Seattle Times and Newsday Sue OpenAI and Microsoft

The complaint filed Friday carries the tone of an elegy with a legal caption. The Seattle Times and Newsday, the Long Island daily, accuse OpenAI and Microsoft of scraping their…