This Is How They Tell Me the World Ends - Perlroth
Book: This Is How They Tell Me the World Ends: The Cyberweapons Arms Race
Author: Nicole Perlroth (New York Times cybersecurity journalist)
In one line: A years-long investigation into the secret trade in unknown software flaws - and how the government that bought the most of them left its own citizens the most exposed.
A zero-day is a software flaw the vendor does not know exists, so there is no patch and defenders have had zero days to prepare. Weaponised into an exploit, it can quietly break into almost any system running that code. That secrecy is exactly what makes it valuable - and what turned a hacker’s bug into a six- and seven-figure product.
2 · The US chose offense and hoarded
The NSA became the market’s biggest buyer, stockpiling flaws to spy and sabotage rather than telling vendors to fix them. Every bug kept secret for attack is a bug left open in the buyer’s own hospitals, grid, and elections. Perlroth calls this the central moral hazard of the whole enterprise.
3 · The arsenal got loose
When NSA tools leaked through the Shadow Brokers, the EternalBlue exploit escaped into the wild and powered WannaCry and NotPetya - global attacks costing billions. The country that wrote the offensive playbook proved least able to defend against it, and there are still almost no rules.
Perlroth spent roughly seven years reporting a trade that most people never hear about: the buying and selling of zero-day exploits, previously unknown flaws in the software the world runs on. What began with lone hackers quietly reporting bugs grew into a shadow market where a single working exploit could sell for hundreds of thousands or millions of dollars. The buyers with the deepest pockets were governments, and the biggest of all was the US, whose intelligence agencies stockpiled vulnerabilities as an offensive arsenal instead of disclosing them to be patched.
That choice is the book’s engine. A flaw hoarded for attack is, by definition, a flaw left unpatched everywhere - including in the buyer’s own power plants, water systems, hospitals, and voting machines. The US built both the market and the offensive doctrine, then watched its own cyberweapons leak and boomerang back as WannaCry and NotPetya. This is the paradox Perlroth keeps returning to: the nation most capable of attacking through software is also, because it is the most wired and most dependent, the one with the most to lose. Her closing argument is a plea to rebalance toward defense, disclosure, and restraint before the next weapon comes home.
This is investigative narrative, not a framework. The argument unfolds as a chain of consequences.
A market is born. Hackers who once reported bugs for free, or for a T-shirt, discovered that governments and contractors would pay real money for the same flaws kept secret. Brokers and boutique firms sprang up to match finders with buyers, and prices climbed from a few thousand dollars into the millions - a whole economy built on secrecy rewarding no one who fixed anything.
The government becomes the biggest buyer. The NSA and allied agencies moved to the front of the queue, purchasing and stockpiling zero-days for espionage and sabotage. Disclosure to vendors - the defensive option - was consistently the road not taken, because a patched flaw is a spent weapon.
Offense gets proven in the wild.Stuxnet, the US-Israeli operation against Iran’s Natanz enrichment plant, showed code could physically destroy centrifuges. It was a demonstration that cyberweapons work - and, once discovered, a template every rival began to copy.
The weapons escape. The Shadow Brokers dumped the NSA’s own hacking tools online. EternalBlue and others escaped into the open, and within weeks criminals and nation-states repurposed them into WannaCry and NotPetya, freezing hospitals, ports, and multinationals worldwide.
The asymmetry bites. Russia, China, Iran, and North Korea now routinely probe critical infrastructure, and the US - the most connected, most automated society - turns out to be the softest, widest target. The most capable attacker is also the most exposed defender.
A flaw unknown to the vendor means defenders have had zero days to prepare - no patch exists. That head start is the entire value, which is why disclosing a bug and weaponising it are opposite acts. Matters because the same secrecy that makes an exploit useful also guarantees millions of systems stay defenceless.
The zero-day market
A bug became a product: hackers sold to brokers, brokers to governments, and prices ran from thousands into the millions. Firms like the ones Perlroth profiles turned exploitation into a business with NDAs and no oversight. Matters because a market that pays only for secrecy structurally starves defense.
Stuxnet - the proof of concept
The US-Israeli worm sabotaged Iran’s Natanz centrifuges using chained zero-days, the first cyberweapon to cause physical destruction. It worked - and then it leaked, teaching every adversary what was possible. Matters because it opened the door the US now cannot close.
Shadow Brokers and EternalBlue
A mysterious group leaked the NSA’s own toolkit, freeing the EternalBlue exploit into public hands. The agency’s secret weapons became everyone’s. Matters because it proved a hoarded arsenal cannot be reliably kept - and stole is worse than spent.
WannaCry and NotPetya
WannaCry ransomware crippled the UK’s NHS and systems in 150-plus countries; NotPetya, launched at Ukraine, spread globally and cost an estimated 10 billion dollars. Both rode leaked NSA code. Matters because it showed a stockpiled flaw becomes indiscriminate blowback.
Grid, water, and election risk
Nation-states have been found inside power utilities, water treatment, and election infrastructure - probing, mapping, pre-positioning. Matters because these systems are old, connected, and lightly defended, and a society this automated has the most to lose.
The stockpiling moral hazard
Hoarding flaws for offense means deliberately leaving your own citizens exposed to the same holes. Defense - patching, disclosure, bounties - was the neglected half of the strategy. Matters because it is the book’s core ethical charge against the NSA’s posture.
Asymmetry of exposure
The US leads in offensive capability yet, being the most digitised nation, is the least defensible. Matters because it inverts the usual logic of strength: here, being most advanced makes you most vulnerable.
Perlroth opens with her own arrival on the beat and the disorienting secrecy of the trade, then reconstructs the market’s origins - from hobbyist hackers to the boutique brokers who put price tags on bugs. The middle moves to governments as buyers, the NSA’s dominance, and Stuxnet as the moment offense was proven. The back half is the blowback: the Shadow Brokers leak, EternalBlue in the wild, WannaCry and NotPetya, and the widening probing of Russia, China, Iran, and North Korea. It closes on the US as the most exposed player and her argument for a defensive turn.
Treat patching as strategy, not chores. Most real breaches exploit known, unpatched flaws - not exotic zero-days. Apply updates fast and everywhere, and hardest on infrastructure that cannot easily be replaced.
Reward disclosure over hoarding. Bug-bounty programmes and responsible-disclosure channels turn finders into allies rather than sellers on the grey market. Make reporting a flaw easier and better-paid than weaponising it.
Assume the supply chain is the way in. The soft attack surface runs through vendors, contractors, and connected devices. Map dependencies and demand security guarantees from suppliers, because their weakness is your breach.
Understand the hoarding trade-off. Know that a government stockpiling zero-days is accepting risk on your behalf. As a citizen or leader, weigh offense against the domestic exposure it creates.
Push for norms and transparency. The arms race will not self-regulate. Back rules that limit offensive stockpiling, require breach disclosure, and treat critical infrastructure as off-limits.
Shrink and segment what is exposed. Fewer internet-facing systems, strong basics, and network segmentation limit how far any single exploit can travel once it is loose.
Fund defense as if it were the mission. Perlroth’s central practical takeaway: shift money and talent toward defending systems, not just breaking into them.
The title comes from a warning Perlroth heard about how the world might end. The book is deliberately alarming, and some critics found it heavy on dread and light on solutions, or noted that a reporter cannot fully verify a secret market’s numbers. Perlroth also writes herself into the story, which some readers love and others find distracting. Read it as an accessible, urgent map of the terrain rather than a technical or policy manual - its value is naming a hidden system and its incentives, not settling every operational detail.