it was never about the bounty

nightmare eclipse says the feud everyone reported as a bug bounty dispute started with his firing

11 min read
in this post

introduction


you've probably heard of nightmare eclipse if you’ve been following cybersecurity at all these past few months. chaotic eclipse, dead eclipse, msnightmare - same person, new account every time microsoft bans the last one

since april he's been casually dropping windows exploits: bluehammer, yellowkey, redsun, undefend, greenplasma, miniplasma, rogueplanet, legacyhive, and shieldbreak on august's patch tuesday. almost all of then pointed at defender or something right next to it, which isnt a coincidence (!)

and people were mostly on his side for a reason, msrc had a reputation. once his case started gaining numbers, other researchers started posting their own stories about their reports getting outright ignored, downgraded, or quietly patched with no reply

i probably knew about it as much as you do, until last evening, when he opened a discord server...

what everyone knew


it started on march 26th 2026 with a blog post:

But someone violated our agreement and left me homeless with nothing. They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine.

then a week later he dropped bluehammer and the campaign was on

the post never actually says what the agreement was. journalists filled that in and it was a fair guess, because everything else he said publicly pointed the same way. from his may reply to microsoft:

You defame me in public with your CVE-2026-45585 advisory even though you literally deleted the Microsoft account I used to report bugs to you with and I got zero pennies from doing so.

so the story became: researcher reports bugs, msrc mishandles them, doesnt pay, deletes his account, researcher retaliates

microsoft answered on may 28th with an msrc post - "A shared responsibility: Protecting customers through Coordinated Vulnerability Disclosure". the vulnerabilities werent responsibly disclosed, customers were being put at risk, and they brought up the digital crimes unit and were working with law enforcement. they faced so much backslash that within days they put out a softer version: no intention of pursuing people doing or publishing security research, plus an admission that some of their interactions with researchers had fallen short

discord server


on august 18th, around 8:42 pm cest, the twitter account everyone attributes to him posted an invite

screenshot of the twitter post sharing the discord invite, and a later reply saying the server was closed
screenshot of the discord invite screen for a server called MSLoversClub, 90 online, 267 members

so i joined. there were bit more than 200 members, few text channels, one of them being called questions-that-may-or-may-not-be-answered (which aged well)

i kept running Tyrrrz's DiscordChatExporter over the channels every so often, because servers like this dont tend to last

the microsoft story


at 9:32 pm he opened a thread. first message: "The Microsoft story"

someone asked how he even talks to microsoft. email, something encrypted?

im genuinely curious what typa communication do you have with msftlike how do they communicate w youis it thru like email or something encrypted?I was an employeeholy shitIt was internal Microsoft emails/Teams

there it is

What was your role at MS?What was your role at MS?Security Researcher at MSRC Vulnerabilities and Mitigations

msrc. the same msrc everyone assumed he'd been fighting from the outside as some external reporter

getting fired


There was a meeting between me and my CISO which is Tom Gallagherwas thinking this is probably just like another meetinghe's new so maybe he wants to know meturns out it was not the casewhen i joined the meeting, HR was thereI knew it was all overbut I still wanted to know whyTom Gallagher told me, I did actions that have harmed "Microsoft customers"I asked for details or anything, they said no, we're not giving you any details

he's got a calendar invite from a new senior person, so he first thought it was an introduction, till he joined to find hr in the call. he was told he'd done things that "harmed microsoft customers", asked what things, and got told they werent telling him

this was october 2024, which somebody in the channel noticed straight away:

no when ? why ? how ? no nothingso from what I understood in the timeline, it was in october 2024? wasn't it way before your first vulnerability posted on X? Or am I missing somethingso from what I understood in the timeline, it was in october 2024? wasn't it way bef…yeap2024, October

so about eighteen months between getting fired and the first exploit going out

he said we're not telling you anything else, sign this paper and get the fuck outthe offer they gave me was insultingly low20,000€ and fuck off
they hired a lawyer, sent me an emailsaying "OMG Microsoft paid you really well since you only worked here for 6 months, this is a great severance, you should take it"I obviously refusednew offer was 27,000€obviously I refused again, that much work I put for MSFTthat 3 years of sweat I put for Microsoftwas just not worth a 27,000€ severance

he refused 20k. their lawyer wrote to him pointing out he'd only been there six months and that this was a great severance (their words), so he refused that too, then refused 27k

the thing he keeps circling back to isnt the money though, its the three years he spent "rawdogging" work, and nobody telling him what he actually did

a few other bits came out later in the thread. he says he was up for a promotion at the time ("then they revoked my promotion and fired me"), that it wasnt a layoff round and he "got picked out of everyone", and that his own manager wasnt told until the day before

he begged gallagher for another meeting just to find out the reason for his firing. he got one:

he told me I'm completely blacklisted from ever entering Microsoft again and I will have a horrible referral if I asked for one from MicrosoftThe only thing that I got from him was, He just does not trust me and would never say whyAfter a while I got an email from him claiming that I "I gave vulnerability details to a third party" with no more details, no who is this third party, when did it happen ? questions we'll never know

blacklisted, a horrible reference if he ever asked for one, and then an email later on with the only concrete accusation he says he ever got

access


Microsoft has suspiciously kept my access to every single thing I had access to even if the decision was to actually fire mefor almost 2 weeks I had unrestricted access to all communications/source codeI felt like there was some sort honeypot waiting for me to do some sort of mistake to justify the firingbut they scrutinized the records mullions of times and did not find any valid reason to fire memy record was just clean

he thinks it was bait - that they left him logged in hoping he'd do something they could use against him

i said in the channel that it couldve just been the two week kündigungsfrist under §622(3) BGB if he was still in probezeit, which would explain the account staying alive without anyone planning anything

then he gave the dates:

Until late Oct/Sept (i don't remember when exactly) they revoked all of my access to everythingI did not get a termination letter until next year, I can still remember it, horrible day and then I get a Microsoft official termination 3 of March 2025Last working day30 June 2025

official termination letter march 3rd 2025, last working day june 30th 2025 - about four months between them, so whatever those two weeks were, they werent a notice period

german law wouldnt require microsoft to leave a suspected insider sitting on source code during any of it either. they couldve cut the access on day one and just paid him to sit at home, thats the normal way to do it

court


he says he didnt want to sue (waste of time and resources against microsoft, in his words), everyone around him pushed him into it. the hearing was may 2025

so he sued. and then microsoft filed their defence:

they claimed that I was working in germany illegalyinsane thing is they are the ones who did my visaand i scrutinized everything, all of my documents were validthe visa explicitly says I'm allowed to work for MSFTmy residence permit says "NOT AUTHORIZED TO WORK, SEE ADDITIONAL SHEET"Microsoft SPECIFICALLY pointed at that, hey he isn't allowed to work here so that's why we fired himafter a long argument, I brought them the additional sheetthat once again says "Authorized to work for Microsoft Deutschland GMBH"

suprisingly, they argued his work authorization. his residence permit reads NOT AUTHORIZED TO WORK, SEE ADDITIONAL SHEET, which is completely normal, the permit isnt where the permission lives. the additional sheet said "Authorized to work for Microsoft Deutschland GMBH"

so he brought them the additional sheet, and then:

OOOOOOOmg our bad, see we requested those documentations from him multiple times but he never replied to usI asked, where tf did you ask for them ?In your work emailbro you blocked my work email a long time agohow tf am i supposed to get them ?court decided that them sending emails and me not receiving them was just a miscommunication

they'd asked for the documents in his work email, which they had already cut off a long time before. the court apparently called that a miscommunication, which is one word for it

then microsoft argued he'd threatened them, with a witness:

yeap, they said that I threatened them and there are witnesseswho is the witness ? "Tom Gallagher"the dude who is totally not gonna lie for corpo profile, has no consequences of him lying or whatsoever

when i asked about their court position, he paraphrased it with a racial slur about himself, twice. guess that means "they had nothing"

thats where he stopped fighting, and a month later bluehammer happened:

okay who am i wasting my time withclearly I'm not winningthen bluehammer happend in Apriland yall are aware of the rest

my questions


german employment law has a thing for this: under §626(2) BGB, if youre fired without notice and you request the reason, the employer has to give it to you in writing without delay. so i asked whether it was a fristlose kündigung (german for termination without notice) and whether he'd ever requested it:

i (unfortunately) also live in germany, so i was wondering, was that a fristlose kündigung? asking because under §626(2) BGB, if you request it, the employer has to give you the reason in writing. did you ever request that from microsoft, what did they say?if you request it, the employer has to give you the reason in writing. did you ever request that from microsoft, what did they say?they refused, there is nothing you can do about it

the channel kept getting locked and unlocked so i dm'd him too, about whether he ever tried a neutral third party (cert/cc or similar) before any of this went public:

sorry for dming you, this is related to what you're discussing right now, and im afraid you might have moved on to other questions by the time the channel unlocks

i (unfortunately) also live in germany, so i was wondering, was that a fristlose kündigung? asking because under §626(2) BGB, if you request it, the employer has to give you the reason in writing. did you ever request that from microsoft, what did they say?
i wonder if he ever ever try bringing in a third-party mediator/coordinator like cert/cc to try and resolve w/ ms before going publictheir response is go fuck yourselfI tried everythingMS has enough money to be over the lawthere is nothing you can do about it

in the thread he put it shorter - "If you go whine about it to anyone, no cares"

then the one i actually wanted. did microsoft ever name the third party in court?

After a while I got an email from him claiming that I "I gave vulnerability details…when this went to court, did microsoft ever name the said third party?when this went to court, did microsoft ever name the said third party?nowhen this went to court, did microsoft ever name the said third party?they never said anything about me ever leaking anything

so by his account microsoft privately accused him of handing vulnerability information to someone, then refused to say who or when. and then never brought it up in court, where you'd expect them to justify the firing. someone asked whether the court documents are public and he said "not yet"

not the bounty


at 11:05 pm cest i asked whether microsoft ever produced any evidence for the leak claim:

do they have evidendce though? did ms ever produce any logs,etc in court, supporting the claim that you shared vuln details with anyone?do they have evidendce though? did ms ever produce any logs,etc in court, supporting…no, it was plain go fuck yourselfssoit was no me protesting abt bountyit was just protesting this unusual firing technique

if thats true then every article written about this had the motive wrong, and i'd only ever read the articles

so i asked the obvious follow up:

it was just protesting this unusual firing techniqueif this was about the firing from the start, why did you keep the employment part vague publicly for so long?

and then nothing. no answer, and a couple minutes later the server just wasnt in my sidebar anymore. turns out servers like this really dont tend to last. on twitter shortly after: "Closed, too much headache"

fact checking


so how much of this can we actually check? not a lot. i was in the server, the invite came off the twitter account everyone attributes to him, and the exports are sitting on my disk, which is enough to say the q&a happened. who was doing the typing is beyond me

the ex employee thing was already the leading theory before any of this. the verge had it on may 30th, krebs on june 9th, and when the register asked microsoft straight out on may 28th whether he was current or former staff, they just didnt answer. the new bit is that he said it himself, and gave a team and a job title

lots of write ups say he worked there from september 2022 to june 2025, and they all point at krebs and the register as the source. some add that it came off a linkedin profile and a hackerone account belonging to whoever microsoft credited those bugs to

so i went and read both. its not in there. all thats in there is him claiming to be an ex employee and microsoft refusing to comment, so i genuinely dont know where the dates came from

his own version (three years, ending 30 june 2025) lines up with them. but that could just as easily mean he read the same blogs everyone else did

some of it is just wrong though. he calls tom gallagher his CISO. gallagher is vp of engineering at msrc, and microsoft's global ciso is igor tsyganskiy (who took it over from bret arsenault). in the main channel he walked it back a bit, and somebody fact checked him live:

The direct threat was from Tom Gallagher, had a meeting with him, he was CISO at the October 2024, was working for MSRC for two years and a half at that pointHis LinkedIn says 27 years

so "CISO" appears to be shorthand for whoever sat at the top of his reporting line. microsoft has handed that title out to a few people since anyway (theres operating cisos and a deputy ciso for europe now), so it doesnt mean just one person. "new" is still odd for someone with about 25 years there, and c0z was right to pull the linkedin on him

his dates dont quite line up either. he says he gave up on the court thing "that March last year", then that bluehammer happened the april after. but bluehammer went out in april 2026, and he was saying this in august 2026, so "last year" would put march a full year before that. either he meant march 2026 or those two things are thirteen months apart rather than one

microsoft's lawyer told him he'd only been there six months, he says three years. both can be true. the visa sheet names "Microsoft Deutschland GMBH" specifically. so if he moved onto the german payroll partway through, that job would only be six months old, while microsoft as a whole is still three (?)

and then theres this, fourteen minutes before he started the story:

now i may have lied about some stuff i saidmaybe a lot of stuffonly did that because MS lied in courtif they gonna lie in court and they believe themwhy not just lie in public as well ?What did you lie about?I don't remember, have of the stuff I wrote, I probably forgot

so he told a channel full of strangers that some of what he posts publicly is made up, gave a reason for it, and an hour later told them a ninety minute first person story

everything else has no document attached to it, and he says the court file isnt public "yet"

what i think


this is all guesswork

it doesnt look like money to me. he turned down 20,000€, then turned down 27,000€, and if this was about getting paid he'd have taken the second offer and gone. what he keeps coming back to is that nobody would tell him what he did, and two years on he's still saying "still don't understand wtf did i do wrong"

that explains the part i never got. hes been attacking microsoft for months and complaining they wont talk to him, at the same time. if all you wanted was to hurt them, why would you care if they answer

and look what the campaign gives him. he has something microsoft doesnt have, and he gets to decide when it lands. then they have to react. rogueplanet went out on june's patch tuesday, legacyhive right after july's, shieldbreak on august 11th. microsoft can move most dates around. it cant move patch tuesday

i dont buy "this is their decision not mine" though. he knew what dropping those would do, saying microsoft made him doesnt really change that. cisa has bluehammer, redsun and undefend on its known exploited list, and marks bluehammer as having known ransomware use. huntress watched someone run all three against a real company back in april, though none of them appears to have worked there

as for why he kept the firing quiet for five months, i genuinely dont know, and thats the question that got no answer. maybe "researcher who got screwed over by the bounty process" just sounds a lot better than "ex employee with a grudge". maybe the case was still live and someone told him to shut up. i dont know

im not putting the full exports up. theres a couple hundred people in there who just came to ask questions

hes also not doing great. he talked about a fiancee who left him days before the wedding, said he has no income, and mentioned being high on benzos at some point. and he still has no idea what he did wrong, two years later

i hope he gets his answer at some point, and that things start going better for him soon

update


august 19th, 7:30 pm. i was finishing this article when he posted something on twitter suggesting that he had taken an overdose

screenshot of a twitter post from him on august 19th saying he has taken an od

like i said above, he wasnt doing well, and it looks like its gotten worse since. ill update this if anything changes

august 20th and 21st. the follow-up posts suggest the august 19th incident was not fatal, though he was still in crisis:

screenshot of twitter posts from him on august 20th saying the 30mg didnt work
screenshot of twitter posts from him on august 21st saying he is going to swallow pills and then saying he is not going to die

comments

0 comments