Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished Updated

Pwn2Own Ireland's second day pays $232,500 for 45 zero-days in fully patched devices

Researchers exploited 45 unique zero-days on day two of Pwn2Own Ireland 2026 for $232,500, hacking Samsung's Galaxy S26 three times. Every target ran its latest firmware, so each win is a working code-execution bug in the build owners run today.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Pwn2Own Ireland's second day pays $232,500 for 45 zero-days in fully patched devices
Generated illustration

What happened

  • Ikotas Labs breached Oracle's Autonomous AI Database with a seven-chain zero-day exploit.
  • Out of Bounds team's HaeJung Yang won $40,000 for hacking Dynamo in the AI infrastructure category.
  • PetoWorks, Xint's Yves Bieri, Kyeongmin Kim, _McCaulay and Doyensec's Yassine Bengana and Maxence Schmitt all hacked the Home Assistant Green smart-home hub.
  • RET2 Systems' Jack Dates ran an exploit chain against the Sonos Era 300 in under a minute.

Why it matters

  • cost Oracle now owes fixes for two separate chains against the same database, since VinSOC's team won $40,000 for a five-zero-day chain against it on day one.
  • constraint Until vendor advisories or ZDI's eventual publication supply vectors and bug classes, defenders cannot rank these bugs by how reachable they are.
  • precedent The Galaxy S25 and Home Assistant Green also fell at the 2025 event, so owners of both product lines should expect contest-driven fixes after each Irish edition.

Pwn2Own rules put every device on its latest firmware. A win requires compromising the target and demonstrating arbitrary code execution [8]. Trend Micro's Zero Day Initiative runs the contest to find such flaws in fully patched devices before attackers exploit them in the wild [9].

Disclosure runs on a fixed clock. Once a zero-day is exploited and disclosed at Pwn2Own, the vendor has 90 days to patch before ZDI publishes it [10]. BleepingComputer's report does not include CVE numbers, bug classes, attack vectors or any report of these bugs in use outside the contest.

The attack vector decides how much of this matters to an operator, and the contest prices it. The iPhone 17's top award was $300,000 for a remote hack, and no contestant registered to try [12]. The only vector named for day two belongs to an attempt that never ran. Kyeongmin Kim withdrew a USB-based attack on the Google Pixel 10 before play began [11].

Day two paid an average of about $5,167 per bug [17]. Its 45 bugs equal about 62 percent of the 73 zero-days demonstrated across the whole of Pwn2Own Ireland 2025, a contest that paid out $1,024,750 [18][15].

The Galaxy S26 has now been hacked six times in two days [16]. Part of that count was not news to Samsung. On day one, Interrupt Labs, Ikotas Labs and Viettel Cyber Security's Nguyen Thanh Dat all broke the phone, but some of the bugs they used were already known to the vendor, BleepingComputer reported [2]. BleepingComputer counts day two's 45 bugs as unique [3].

What to watch

  • Day three, when the Galaxy S26 and Google Pixel 10 come back alongside more smart-home, AI infrastructure and printer targets.
  • Advisories from Samsung, Oracle and Home Assistant crediting the contest, the first public source of CVEs and attack vectors for these bugs.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence58
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence60
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    On day two the Samsung Galaxy S26 was hacked three times, by KAIST Hacking Lab's Kyeongmin Kim, PetoWorks, and Mobile Hacking Lab's Dimitrios Valsamaras and Ken Gannon.

  2. [2]

    Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security hacked the Galaxy S26 on day one, but some of the bugs exploited were already known to the vendor.

  3. [3]

    On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. bleepingcomputer.com

    1 article · October 7, 2026

    Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories