RC RANDOM CHAOS

Pwn2Own Ireland 2026 paid $1,262,000 for 98 zero-days

Pwn2Own Ireland 2026: 29 teams demonstrated 98 zero-days for $1,262,000, with Ikotas Labs taking Master of Pwn and a $300,000 Pixel 10 hack.

· 2 min read
Pwn2Own Ireland 2026 paid $1,262,000 for 98 zero-days

Over three days, 29 research teams at Pwn2Own Ireland 2026 demonstrated 98 zero-day vulnerabilities and collected $1,262,000. Trend Micro’s Zero Day Initiative runs the event under rules that leave little room for soft targets: every device runs the latest shipping firmware, and an entry only counts if the researcher achieves arbitrary code execution on it.

Ikotas Labs took Master of Pwn with 42.5 points and $361,000. Their haul spanned a Samsung Galaxy S26, OpenAI Codex, and the Oracle Autonomous AI Database, and closed with the contest’s largest single payout: $300,000 on day three for a chain of zero-days that hacked a Google Pixel 10. Xint finished second with $240,000 and 27.5 points; Team ZyGoat third with $125,000 and the same point total.

The Galaxy S26 was the punching bag of the week. Interrupt Labs, Ikotas Labs, and Viettel Cyber Security’s Nguyen Thanh Dat all landed exploits on it the first day, though Samsung already knew about some of the bugs used. Day one closed with $388,500 across 32 zero-days. On day two, PetoWorks, KAIST Hacking Lab’s Kyeongmin Kim, and a CENSUS Labs team of Dimitrios Valsamaras, Ken Gannon, and Tenia Valsamara took the S26 down three more times, part of 45 unique zero-days worth $232,500. Day three brought another S26 root and three separate Pixel 10 compromises, 21 zero-days for $641,000.

The target list shows where ZDI thinks the attack surface is moving. Alongside the two phones, this year’s seven categories included AI infrastructure, AI coding apps, messaging apps, smart home devices, printers, and a new wellness healthcare device category. The presence of OpenAI Codex and the Oracle Autonomous AI Database among the winning targets is the detail worth sitting with: these are the systems engineers are now wiring into production, and they fell to the same contest that routinely breaks NAS boxes and printers.

Apple’s iPhone 17 was on the board with a $300,000 bounty for a remote hack. No one registered to attempt it.

For anyone running these devices, the clock is the actionable part. ZDI gives vendors 90 days to ship fixes before it publishes technical details, so the bugs demonstrated this week are on a disclosure timer. The phones and the AI services here all ran current firmware, so the bugs land against shipping versions, not stale builds. Track the ZDI advisories for the products you depend on and plan for a patch wave over the next quarter, particularly on Galaxy S26 fleets given how many distinct bugs it absorbed.

For context, last year’s Pwn2Own Ireland produced 73 zero-days and $1,024,750, with Summoning Team winning on the back of the Galaxy S25, a Home Assistant Green, a QNAP TS-453E, and several Synology devices. This year’s totals are up on both counts.

Share

Keep Reading

Latest on the Wire

Full wire →

New signal daily · RSS

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.