---
title: it was never about the bounty
description: >-
  nightmare eclipse says the feud everyone reported as a bug bounty dispute
  started with his firing
published: 2026-08-19T00:00:00.000Z
updated: 2026-08-22T00:00:00.000Z
tags:
  - security
  - microsoft
  - disclosure
draft: false
signature: ./it-was-never-about-the-bounty.md.asc
---

# introduction

---

you've probably heard of nightmare eclipse if you’ve been following cybersecurity at all these past few months. chaotic eclipse, dead eclipse, msnightmare - same person, new account every time microsoft bans the last one

since april he's been casually dropping windows exploits: bluehammer, yellowkey, redsun, undefend, greenplasma, miniplasma, rogueplanet, legacyhive, and shieldbreak on august's patch tuesday. almost all of then pointed at defender or something right next to it, which isnt a coincidence (!)

and people were mostly on his side for a reason, msrc had a reputation. once his case started gaining numbers, other researchers started posting their own stories about their reports getting outright ignored, downgraded, or quietly patched with no reply

i probably knew about it as much as you do, until last evening, when he opened a discord server...

# what everyone knew

---

it started on march 26th 2026 with a [blog post](https://deadeclipse666.blogspot.com/2026/03/first-post-i-never-wanted-to-do-this.html):

> But someone violated our agreement and left me homeless with nothing. They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine.

then a week later he dropped [bluehammer](https://nvd.nist.gov/vuln/detail/CVE-2026-33825) and the campaign was on

the post never actually says what the agreement was. journalists filled that in and it was a fair guess, because everything else he said publicly pointed the same way. from his may reply to microsoft:

> You defame me in public with your CVE-2026-45585 advisory even though you literally deleted the Microsoft account I used to report bugs to you with and I got zero pennies from doing so.

so the story became: researcher reports bugs, msrc mishandles them, doesnt pay, deletes his account, researcher retaliates

microsoft answered on may 28th with an msrc post - ["A shared responsibility: Protecting customers through Coordinated Vulnerability Disclosure"](https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure). the vulnerabilities werent responsibly disclosed, customers were being put at risk, and they brought up the digital crimes unit and were working with law enforcement. they faced so much backslash that within days they put out a [softer version](https://therecord.media/microsoft-says-it-will-not-pursue-security-researchers-disclosure): no intention of pursuing people doing or publishing security research, plus an admission that some of their interactions with researchers had fallen short

# discord server

---

on august 18th, around 8:42 pm cest, the twitter account everyone attributes to him posted an invite

![screenshot of the twitter post sharing the discord invite, and a later reply saying the server was closed](/blog/it-was-never-about-the-bounty/screenshot_twitter_post.png)

![screenshot of the discord invite screen for a server called MSLoversClub, 90 online, 267 members](/blog/it-was-never-about-the-bounty/screenshot_discord_invite.png)

so i joined. there were bit more than 200 members, few text channels, one of them being called `questions-that-may-or-may-not-be-answered` (which aged well)

i kept running Tyrrrz's DiscordChatExporter over the channels every so often, because servers like this dont tend to last

# the microsoft story

---

at 9:32 pm he opened a thread. first message: "The Microsoft story"

someone asked how he even talks to microsoft. email, something encrypted?

```discord
nightmare-eclipse/i-was-an-employee
```

there it is

```discord
nightmare-eclipse/role-at-msrc
```

msrc. the same msrc everyone assumed he'd been fighting from the outside as some external reporter

# getting fired

---

```discord
nightmare-eclipse/the-meeting
```

he's got a calendar invite from a new senior person, so he first thought it was an introduction, till he joined to find hr in the call. he was told he'd done things that "harmed microsoft customers", asked what things, and got told they werent telling him

this was october 2024, which somebody in the channel noticed straight away:

```discord
nightmare-eclipse/october-2024
```

so about eighteen months between getting fired and the first exploit going out

```discord
nightmare-eclipse/sign-this-paper
```

```discord
nightmare-eclipse/severance-refused
```

he refused 20k. their lawyer wrote to him pointing out he'd only been there six months and that this was a great severance (their words), so he refused that too, then refused 27k

the thing he keeps circling back to isnt the money though, its the three years he spent "rawdogging" work, and nobody telling him what he actually did

a few other bits came out later in the thread. he says he was up for a promotion at the time ("then they revoked my promotion and fired me"), that it wasnt a layoff round and he "got picked out of everyone", and that his own manager wasnt told until the day before

he begged gallagher for another meeting just to find out the reason for his firing. he got one:

```discord
nightmare-eclipse/blacklist-and-third-party
```

blacklisted, a horrible reference if he ever asked for one, and then an email later on with the only concrete accusation he says he ever got

# access

---

```discord
nightmare-eclipse/access-kept
```

he thinks it was bait - that they left him logged in hoping he'd do something they could use against him

i said in the channel that it couldve just been the two week kündigungsfrist under §622(3) BGB if he was still in probezeit, which would explain the account staying alive without anyone planning anything

then he gave the dates:

```discord
nightmare-eclipse/the-dates
```

official termination letter march 3rd 2025, last working day june 30th 2025 - about four months between them, so whatever those two weeks were, they werent a notice period

german law wouldnt require microsoft to leave a suspected insider sitting on source code during any of it either. they couldve cut the access on day one and just paid him to sit at home, thats the normal way to do it

# court

---

he says he didnt want to sue (waste of time and resources against microsoft, in his words), everyone around him pushed him into it. the hearing was may 2025

so he sued. and then microsoft filed their defence:

```discord
nightmare-eclipse/court-work-authorization
```

suprisingly, they argued his work authorization. his residence permit reads `NOT AUTHORIZED TO WORK, SEE ADDITIONAL SHEET`, which is completely normal, the permit isnt where the permission lives. the additional sheet said "Authorized to work for Microsoft Deutschland GMBH"

so he brought them the additional sheet, and then:

```discord
nightmare-eclipse/emails-to-a-blocked-inbox
```

they'd asked for the documents in his work email, which they had already cut off a long time before. the court apparently called that a miscommunication, which is one word for it

then microsoft argued he'd threatened them, with a witness:

```discord
nightmare-eclipse/the-threat-witness
```

when i asked about their court position, he paraphrased it with a racial slur about himself, twice. guess that means "they had nothing"

thats where he stopped fighting, and a month later bluehammer happened:

```discord
nightmare-eclipse/then-bluehammer
```

# my questions

---

german employment law has a thing for this: under §626(2) BGB, if youre fired without notice and you request the reason, the employer has to give it to you in writing without delay. so i asked whether it was a fristlose kündigung (german for termination without notice) and whether he'd ever requested it:

```discord
nightmare-eclipse/my-626-question
```

the channel kept getting locked and unlocked so i dm'd him too, about whether he ever tried a neutral third party (cert/cc or similar) before any of this went public:

```discord
nightmare-eclipse/the-dm
```

in the thread he put it shorter - "If you go whine about it to anyone, no cares"

then the one i actually wanted. did microsoft ever name the third party in court?

```discord
nightmare-eclipse/never-named-the-third-party
```

so by his account microsoft privately accused him of handing vulnerability information to someone, then refused to say who or when. and then never brought it up in court, where you'd expect them to justify the firing. someone asked whether the court documents are public and he said "not yet"

# not the bounty

---

at 11:05 pm cest i asked whether microsoft ever produced any evidence for the leak claim:

```discord
nightmare-eclipse/not-about-the-bounty
```

if thats true then every article written about this had the motive wrong, and i'd only ever read the articles

so i asked the obvious follow up:

```discord
nightmare-eclipse/the-last-question
```

and then nothing. no answer, and a couple minutes later the server just wasnt in my sidebar anymore. turns out servers like this really dont tend to last. on twitter shortly after: "Closed, too much headache"

# fact checking

---

so how much of this can we actually check? not a lot. i was in the server, the invite came off the twitter account everyone attributes to him, and the exports are sitting on my disk, which is enough to say the q&a happened. who was doing the typing is beyond me

the ex employee thing was already the leading theory before any of this. [the verge had it on may 30th](https://www.theverge.com/tech/940416/microsoft-nightmare-eclipse-zero-day-vulnerability), [krebs on june 9th](https://krebsonsecurity.com/2026/06/a-record-breaking-patch-tuesday-for-june-2026/), and when [the register asked microsoft straight out](https://www.theregister.com/security/2026/05/28/microsoft-0-day-feud-escalates-as-researcher-threatens-another-windows-exploit-dump/5248085) on may 28th whether he was current or former staff, they just didnt answer. the new bit is that he said it himself, and gave a team and a job title

lots of write ups say he worked there from september 2022 to june 2025, and they all point at krebs and the register as the source. some add that it came off a linkedin profile and a hackerone account belonging to whoever microsoft credited those bugs to

so i went and read both. its not in there. all thats in there is him claiming to be an ex employee and microsoft refusing to comment, so i genuinely dont know where the dates came from

his own version (three years, ending 30 june 2025) lines up with them. but that could just as easily mean he read the same blogs everyone else did

some of it is just wrong though. he calls tom gallagher his CISO. gallagher is vp of engineering at msrc, and microsoft's global ciso is igor tsyganskiy (who took it over from bret arsenault). in the main channel he walked it back a bit, and somebody fact checked him live:

```discord
nightmare-eclipse/gallagher-title
```

so "CISO" appears to be shorthand for whoever sat at the top of his reporting line. microsoft has handed that title out to a few people since anyway (theres operating cisos and a deputy ciso for europe now), so it doesnt mean just one person. "new" is still odd for someone with about 25 years there, and c0z was right to pull the linkedin on him

his dates dont quite line up either. he says he gave up on the court thing "that March last year", then that bluehammer happened the april after. but bluehammer went out in april 2026, and he was saying this in august 2026, so "last year" would put march a full year before that. either he meant march 2026 or those two things are thirteen months apart rather than one

microsoft's lawyer told him he'd only been there six months, he says three years. both can be true. the visa sheet names "Microsoft Deutschland GMBH" specifically. so if he moved onto the german payroll partway through, that job would only be six months old, while microsoft as a whole is still three (?)

and then theres this, fourteen minutes before he started the story:

```discord
nightmare-eclipse/i-may-have-lied
```

so he told a channel full of strangers that some of what he posts publicly is made up, gave a reason for it, and an hour later told them a ninety minute first person story

everything else has no document attached to it, and he says the court file isnt public "yet"

# what i think

---

this is all guesswork

it doesnt look like money to me. he turned down 20,000€, then turned down 27,000€, and if this was about getting paid he'd have taken the second offer and gone. what he keeps coming back to is that nobody would tell him what he did, and two years on he's still saying "still don't understand wtf did i do wrong"

that explains the part i never got. hes been attacking microsoft for months and complaining they wont talk to him, at the same time. if all you wanted was to hurt them, why would you care if they answer

and look what the campaign gives him. he has something microsoft doesnt have, and he gets to decide when it lands. then they have to react. rogueplanet went out on june's patch tuesday, legacyhive right after july's, shieldbreak on august 11th. microsoft can move most dates around. it cant move patch tuesday

i dont buy "this is their decision not mine" though. he knew what dropping those would do, saying microsoft made him doesnt really change that. cisa has bluehammer, redsun and undefend on its known exploited list, and marks bluehammer as having known ransomware use. [huntress watched someone run all three](https://www.huntress.com/blog/nightmare-eclipse-intrusion) against a real company back in april, though none of them appears to have worked there

as for why he kept the firing quiet for five months, i genuinely dont know, and thats the question that got no answer. maybe "researcher who got screwed over by the bounty process" just sounds a lot better than "ex employee with a grudge". maybe the case was still live and someone told him to shut up. i dont know

im not putting the full exports up. theres a couple hundred people in there who just came to ask questions

hes also not doing great. he talked about a fiancee who left him days before the wedding, said he has no income, and mentioned being high on benzos at some point. and he still has no idea what he did wrong, two years later

i hope he gets his answer at some point, and that things start going better for him soon

# update

---

august 19th, 7:30 pm. i was finishing this article when he posted something on twitter suggesting that he had taken an overdose

![screenshot of a twitter post from him on august 19th saying he has taken an od](/blog/it-was-never-about-the-bounty/screenshot_twitter_post_2.png)

like i said above, he wasnt doing well, and it looks like its gotten worse since. ill update this if anything changes

august 20th and 21st. the follow-up posts suggest the august 19th incident was not fatal, though he was still in crisis:

![screenshot of twitter posts from him on august 20th saying the 30mg didnt work](/blog/it-was-never-about-the-bounty/screenshot_twitter_post_3.png)

![screenshot of twitter posts from him on august 21st saying he is going to swallow pills and then saying he is not going to die](/blog/it-was-never-about-the-bounty/screenshot_twitter_post_4.png)
