Pwn2Own Ireland Researchers Earn $1.262 Million for Demonstrating 98 Zero-Days

· Original article ↗

Summary

Researchers earned $1.262 million after demonstrating 98 zero-day flaws across products at Pwn2Own Ireland 2026. ZDI says vendors must patch disclosed flaws within 90 days before details are made public.

Key points

  • The three-day contest ended with researchers demonstrating 98 zero-day flaws and earning $1,262,000 in total.
  • Ikotas Labs placed first with 42.5 Master of Pwn points and $361,000 in prizes.
  • Researchers repeatedly compromised the Samsung Galaxy S26; teams also demonstrated attacks against the Google Pixel 10.
  • Twenty-nine teams targeted products across seven categories, including mobile devices, AI systems, messaging apps, printers, and wellness healthcare devices.
  • The contest requires targets to run the latest firmware and contestants to demonstrate arbitrary code execution.
  • Vendors have 90 days to patch flaws disclosed during the contest before ZDI publicly shares details.

Article Details

Event Type
Pwn2Own Ireland 2026 hacking contest concluded, with competitors demonstrating zero-day vulnerabilities against products across multiple categories.
Impact
Competitors exploited 98 zero-day flaws and received $1,262,000 in rewards. Demonstrations included attacks on the Samsung Galaxy S26, Google Pixel 10, OpenAI Codex, and Oracle Autonomous AI Database. Vendors are required to patch disclosed flaws within 90 days before ZDI publicly shares details.

People

Vendors

Products

Industries

Related Articles