SecurityNot yet confirmed elsewhere1 publisher2 min readPublished Updated
Pwn2Own Ireland's second day pays $232,500 for 45 zero-days in fully patched devices
Researchers exploited 45 unique zero-days on day two of Pwn2Own Ireland 2026 for $232,500, hacking Samsung's Galaxy S26 three times. Every target ran its latest firmware, so each win is a working code-execution bug in the build owners run today.
The Watch · Security desk

What happened
- Ikotas Labs breached Oracle's Autonomous AI Database with a seven-chain zero-day exploit.
- Out of Bounds team's HaeJung Yang won $40,000 for hacking Dynamo in the AI infrastructure category.
- PetoWorks, Xint's Yves Bieri, Kyeongmin Kim, _McCaulay and Doyensec's Yassine Bengana and Maxence Schmitt all hacked the Home Assistant Green smart-home hub.
- RET2 Systems' Jack Dates ran an exploit chain against the Sonos Era 300 in under a minute.
Why it matters
- cost Oracle now owes fixes for two separate chains against the same database, since VinSOC's team won $40,000 for a five-zero-day chain against it on day one.
- constraint Until vendor advisories or ZDI's eventual publication supply vectors and bug classes, defenders cannot rank these bugs by how reachable they are.
- precedent The Galaxy S25 and Home Assistant Green also fell at the 2025 event, so owners of both product lines should expect contest-driven fixes after each Irish edition.
Pwn2Own rules put every device on its latest firmware. A win requires compromising the target and demonstrating arbitrary code execution [8]. Trend Micro's Zero Day Initiative runs the contest to find such flaws in fully patched devices before attackers exploit them in the wild [9].
Disclosure runs on a fixed clock. Once a zero-day is exploited and disclosed at Pwn2Own, the vendor has 90 days to patch before ZDI publishes it [10]. BleepingComputer's report does not include CVE numbers, bug classes, attack vectors or any report of these bugs in use outside the contest.
The attack vector decides how much of this matters to an operator, and the contest prices it. The iPhone 17's top award was $300,000 for a remote hack, and no contestant registered to try [12]. The only vector named for day two belongs to an attempt that never ran. Kyeongmin Kim withdrew a USB-based attack on the Google Pixel 10 before play began [11].
Day two paid an average of about $5,167 per bug [17]. Its 45 bugs equal about 62 percent of the 73 zero-days demonstrated across the whole of Pwn2Own Ireland 2025, a contest that paid out $1,024,750 [18][15].
The Galaxy S26 has now been hacked six times in two days [16]. Part of that count was not news to Samsung. On day one, Interrupt Labs, Ikotas Labs and Viettel Cyber Security's Nguyen Thanh Dat all broke the phone, but some of the bugs they used were already known to the vendor, BleepingComputer reported [2]. BleepingComputer counts day two's 45 bugs as unique [3].
What to watch
- Day three, when the Galaxy S26 and Google Pixel 10 come back alongside more smart-home, AI infrastructure and printer targets.
- Advisories from Samsung, Oracle and Home Assistant crediting the contest, the first public source of CVEs and attack vectors for these bugs.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence60
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
On day two the Samsung Galaxy S26 was hacked three times, by KAIST Hacking Lab's Kyeongmin Kim, PetoWorks, and Mobile Hacking Lab's Dimitrios Valsamaras and Ken Gannon.
- [2]
Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security hacked the Galaxy S26 on day one, but some of the bugs exploited were already known to the vendor.
- [3]
On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities.
- [4]
Out of Bounds team's HaeJung Yang was awarded $40,000 for hacking Dynamo in the AI Infrastructure category.
- [5]
Ikotas Labs breached the Oracle Autonomous AI Database using a seven-chain zero-day exploit.
- [6]
PetoWorks, Yves Bieri of Xint, Kyeongmin Kim, _McCaulay, and Doyensec's Yassine Bengana and Maxence Schmitt hacked the Home Assistant Green smart home hub.
- [7]
Jack Dates of RET2 Systems demoed a Sonos Era 300 exploit chain in under a minute.
- [8]
According to Pwn2Own rules, all devices run the latest firmware versions, and contestants must compromise the target and demonstrate arbitrary code execution.
- [9]
Trend Micro's Zero Day Initiative (ZDI) organizes the competition to identify zero-day flaws in fully patched devices before attackers exploit them in the wild.
- [10]
After zero-days are exploited and disclosed at Pwn2Own, vendors have 90 days to patch their software before ZDI publicly discloses them.
- [11]
Before day two began, Kyeongmin Kim withdrew his attempt at a USB-based attack targeting the Google Pixel 10.
- [12]
Apple's iPhone 17 was a potential target with a maximum award of $300,000 for a remote hack, but no contestant registered for an attempt.
- [13]
VinSOC's team, which topped the day-one leaderboard, won $40,000 for a five-zero-day exploit chain targeting the Oracle Autonomous AI Database, plus $40,000 for chaining seven zero-days against a Philips Hue Bridge Pro.
- [14]
On day three, researchers will attempt to hack multiple smart home, AI infrastructure and printer devices, as well as the Samsung Galaxy S26 and Google Pixel 10 again.
- [15]
At Pwn2Own Ireland 2025, hackers demoed 73 zero-day flaws to earn $1,024,750; Summoning Team won with $187,500 after hacking the Samsung Galaxy S25, the Home Assistant Green, the QNAP TS-453E NAS and multiple Synology devices.
- [16]
The Galaxy S26 has been hacked six times across the first two days of Pwn2Own Ireland 2026.
- [17]
Day two of Pwn2Own Ireland 2026 paid about $5,167 per zero-day on average.
- [18]
Day two's 45 zero-days equal about 62 percent of the 73 demonstrated across all of Pwn2Own Ireland 2025.
Sources
1 independent publisher whose own reporting we read for this story.
- bleepingcomputer.comSamsung Galaxy S26 hacked three more times at Pwn2Own Ireland
1 article · October 7, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Zero-Day VulnerabilitiesFollow
- Hacking competitionsFollow
- AI Infrastructure SecurityFollow
- Mobile securityFollow
- Smart Home SecurityFollow
Entities
- Pwn2OwnFollow
- Zero Day InitiativeFollow
- Trend MicroFollow
- Samsung Galaxy S26Follow
- Pixel 10Follow
- iPhone 17Follow
- Oracle Autonomous AI DatabaseFollow
- Home Assistant GreenFollow
- Sonos Era 300Follow
- Philips Hue Bridge ProFollow
- BleepingComputerFollow