Skip to content

Security2 publishersIndependently confirmed2 min readPublished Updated

Pwn2Own Ireland zero-days put Samsung, Google, OpenAI and Oracle on a 90-day patch deadline

Researchers at Pwn2Own Ireland 2026 collected $1,262,000 for exploiting 98 zero-day flaws across seven product categories in three days. Every exploit had to work on current firmware, so owners of those products have to wait for vendor fixes.

The Watch · Security desk

How we use AISend a correction

What happened

  • Ikotas Labs won with 42.5 Master of Pwn points and $361,000 after hacking the Samsung Galaxy S26, OpenAI Codex and the Oracle Autonomous AI Database.
  • Ikotas also took the largest single award, $300,000, on day three for chaining multiple zero-days to hack the Google Pixel 10.
  • Xint finished second with $240,000 and Team ZyGoat third with $125,000, each on 27.5 Master of Pwn points.
  • Twenty-nine teams entered across seven categories, including AI infrastructure, AI coding apps and a new category for wellness healthcare devices.
  • Apple's iPhone 17 carried a maximum award of $300,000 for a remote hack, but no contestant registered to attempt it.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Patch planning for Galaxy S26, Pixel 10, Codex and Oracle AI database deployments now has a hard outer date from the 90-day rule, with fixes able to land at any point before it.
  • constraint Samsung already knew some of the bugs used against the Galaxy S26 on day one, so the 98 figure overstates how many new fixes patch teams will receive.
  • precedent With AI coding apps and AI infrastructure scored beside phones, OpenAI and Oracle now face the same fixed disclosure deadline as handset makers.

Trend Micro's Zero Day Initiative runs Pwn2Own to find zero-days before attackers exploit them in the wild [13]. To count, an entry had to compromise the target and demonstrate arbitrary code execution [14]. So far the public record is the target list, the bug counts and the payouts [1][7]. BleepingComputer's report does not break the 98 down by vendor or list CVEs, so the size of any one product's patch queue cannot be worked out from it [1].

The daily totals add up: 32 bugs for $388,500 on day one, 45 for $232,500 on day two and 21 for $641,000 on day three [4][5][6][10]. Day two produced the most bugs and the least money, about $5,170 a bug [16]. Day three paid about $30,520 a bug [17]. The Pixel 10 chain alone was 47% of that day's payout [18].

Samsung's Galaxy S26 fell at least seven times [19]. Interrupt Labs, Ikotas Labs and Nguyen Thanh Dat of Viettel Cyber Security broke it on day one [3]. PetoWorks, Kyeongmin Kim of KAIST Hacking Lab and a CENSUS Labs team took it down three more times on day two, and it was rooted again on day three [5][6]. Six of the entrants who broke it are named [20]. The Pixel 10 went down three times on the final day [6].

Pwn2Own Ireland 2025 produced 73 zero-days and $1,024,750 in awards, and Summoning Team won it with $187,500 [15]. This year's 98 is 25 more, an increase of about 34%, while the purse grew about 23% [21][22]. The average award per bug fell from about $14,040 to about $12,880 [23]. Ikotas Labs' winning total is close to double Summoning Team's [24].

What to watch

  • Samsung and Google security bulletins crediting Pwn2Own Ireland 2026 entrants, the first count of how many Galaxy S26 and Pixel 10 bugs were new.
  • OpenAI and Oracle statements on the Codex and Autonomous AI Database fixes, including whether customers must take any action.
  • ZDI advisories at the end of the 90-day window, the first public detail on bug classes and on any vendor that missed the deadline.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence70
Adoption
Insufficient
Hype gap+10
Incentives45
Confidence72
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Pwn2Own Ireland 2026 concluded with hackers collecting $1,262,000 in rewards after exploiting 98 zero-day flaws.

  2. [2]

    Ikotas Labs collected the competition's top reward of $300,000 on the third day after chaining multiple zero-days to hack the Google Pixel 10.

  3. [3]

    Interrupt Labs, Ikotas Labs and Nguyen Thanh Dat of Viettel Cyber Security hacked the Samsung Galaxy S26 on the first day, but the vendor already knew some of the exploited bugs.

Sources

2 independent publishers whose own reporting we read for this story.

  1. bleepingcomputer.com

    1 article · October 8, 2026

    Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland
  2. securityweek.com

    1 article · October 8, 2026

    Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories