Pwn2Own Ireland 2026 paid $1,262,000 for 98 zero-days
Pwn2Own Ireland 2026: 29 teams demonstrated 98 zero-days for $1,262,000, with Ikotas Labs taking Master of Pwn and a $300,000 Pixel 10 hack.
Over three days, 29 research teams at Pwn2Own Ireland 2026 demonstrated 98 zero-day vulnerabilities and collected $1,262,000. Trend Micro’s Zero Day Initiative runs the event under rules that leave little room for soft targets: every device runs the latest shipping firmware, and an entry only counts if the researcher achieves arbitrary code execution on it.
Ikotas Labs took Master of Pwn with 42.5 points and $361,000. Their haul spanned a Samsung Galaxy S26, OpenAI Codex, and the Oracle Autonomous AI Database, and closed with the contest’s largest single payout: $300,000 on day three for a chain of zero-days that hacked a Google Pixel 10. Xint finished second with $240,000 and 27.5 points; Team ZyGoat third with $125,000 and the same point total.
The Galaxy S26 was the punching bag of the week. Interrupt Labs, Ikotas Labs, and Viettel Cyber Security’s Nguyen Thanh Dat all landed exploits on it the first day, though Samsung already knew about some of the bugs used. Day one closed with $388,500 across 32 zero-days. On day two, PetoWorks, KAIST Hacking Lab’s Kyeongmin Kim, and a CENSUS Labs team of Dimitrios Valsamaras, Ken Gannon, and Tenia Valsamara took the S26 down three more times, part of 45 unique zero-days worth $232,500. Day three brought another S26 root and three separate Pixel 10 compromises, 21 zero-days for $641,000.
The target list shows where ZDI thinks the attack surface is moving. Alongside the two phones, this year’s seven categories included AI infrastructure, AI coding apps, messaging apps, smart home devices, printers, and a new wellness healthcare device category. The presence of OpenAI Codex and the Oracle Autonomous AI Database among the winning targets is the detail worth sitting with: these are the systems engineers are now wiring into production, and they fell to the same contest that routinely breaks NAS boxes and printers.
Apple’s iPhone 17 was on the board with a $300,000 bounty for a remote hack. No one registered to attempt it.
For anyone running these devices, the clock is the actionable part. ZDI gives vendors 90 days to ship fixes before it publishes technical details, so the bugs demonstrated this week are on a disclosure timer. The phones and the AI services here all ran current firmware, so the bugs land against shipping versions, not stale builds. Track the ZDI advisories for the products you depend on and plan for a patch wave over the next quarter, particularly on Galaxy S26 fleets given how many distinct bugs it absorbed.
For context, last year’s Pwn2Own Ireland produced 73 zero-days and $1,024,750, with Summoning Team winning on the back of the Galaxy S25, a Home Assistant Green, a QNAP TS-453E, and several Synology devices. This year’s totals are up on both counts.
Keep Reading
dellDell's Thursday patch closes a root-level DSU flaw
Dell patched CVE-2026-86360, a path traversal flaw in the System Update CLI that gives unauthenticated remote attackers root. Upgrade to DSU 2.3.0.0.
gitlabGitLab AI Gateway sandbox escape
GitLab's critical CVE-2026-90970 lets an authenticated Duo user escape the AI Gateway prompt sandbox and run arbitrary commands. Self-hosted operators must patch now.
kiteworksKiteworks patches max-severity EPG flaw in Wednesday advisory
Kiteworks patched CVE-2026-54154, a max-severity unauthenticated RCE in its Email Protection Gateway. Upgrade to 9.4.1 and check exposed appliances.
Latest on the Wire
Full wire →- 5.3M-year-old whale necropolis discovered in deep seaHacker News
- ADHD Linked to Circadian Rhythm Disruption: Evidence and ChronotherapyHacker News
- AhsayCBS Flaws Exploited for Webshells, Crypto MiningBleepingComputer
- AI Won't Replace Programmers but Will Change the RoleHacker News
New signal daily · RSS
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.