$1.26 Million in Rewards Handed Out at Pwn2Own Ireland Hacking Contest
The Pwn2Own Ireland 2026 hacking contest has wrapped up, with security researchers pocketing a substantial $1.26 million in rewards for exploiting 98 zero-day vulnerabilities in various products and devices. The competition, organized by Trend Micro’s Zero Day Initiative (ZDI), aims to identify and fix critical flaws before they are exploited in the wild.
Ikotas Labs’ team of security researchers took top honors at this year’s contest, earning 42.5 Master of Pwn points and a cool $361,000 for their exploits on the Samsung Galaxy S26, OpenAI Codex, and Oracle Autonomous AI Database. But it was their final-day performance that really earned them the big bucks – they successfully chained multiple zero-days to hack the Google Pixel 10, taking home the top prize of $300,000 in the process.
The competition saw a total of 29 research teams targeting products across seven categories, including mobile phones (Samsung Galaxy S26 and Google Pixel 10), AI infrastructure, and smart home devices. The stakes were high, with contestants vying for rewards totaling over $1 million. Interestingly, Apple’s iPhone 17 was also a potential target this year, but no contestant registered to attempt the remote hack.
One notable aspect of Pwn2Own is its focus on real-world exploits rather than theoretical vulnerabilities. Contestants are required to demonstrate arbitrary code execution on their targets, and vendors must patch disclosed zero-days within 90 days before ZDI publicly shares details. This approach not only helps identify critical flaws but also pushes vendors to prioritize security updates.
The sheer number of zero-day exploits demonstrated at Pwn2Own Ireland this year is staggering – a total of 98 vulnerabilities were discovered across the three-day contest. While some of these bugs may have been known to vendors in advance, others undoubtedly caught them off guard. This highlights the importance of ongoing security research and the need for vendors to stay vigilant.
So what does this mean for you? If you’re using any of the devices or products targeted by Pwn2Own contestants, it’s essential to ensure your systems are up-to-date with the latest firmware versions. Regularly updating your software can help mitigate the risk of exploitation. Additionally, be cautious when interacting with AI-powered applications and services – while they offer many benefits, they also introduce new attack surfaces that need to be considered.
As we move forward in an increasingly complex digital landscape, events like Pwn2Own will continue to play a crucial role in identifying vulnerabilities and pushing vendors to prioritize security. By staying informed about the latest threats and exploits, you can better protect yourself and your organization from emerging risks.
Source: Bleeping Computer — 2026-10-09