Security2 publishersIndependently confirmed2 min readPublished Updated
Pwn2Own Ireland zero-days put Samsung, Google, OpenAI and Oracle on a 90-day patch deadline
Researchers at Pwn2Own Ireland 2026 collected $1,262,000 for exploiting 98 zero-day flaws across seven product categories in three days. Every exploit had to work on current firmware, so owners of those products have to wait for vendor fixes.
The Watch · Security desk
What happened
- Ikotas Labs won with 42.5 Master of Pwn points and $361,000 after hacking the Samsung Galaxy S26, OpenAI Codex and the Oracle Autonomous AI Database.
- Ikotas also took the largest single award, $300,000, on day three for chaining multiple zero-days to hack the Google Pixel 10.
- Xint finished second with $240,000 and Team ZyGoat third with $125,000, each on 27.5 Master of Pwn points.
- Twenty-nine teams entered across seven categories, including AI infrastructure, AI coding apps and a new category for wellness healthcare devices.
- Apple's iPhone 17 carried a maximum award of $300,000 for a remote hack, but no contestant registered to attempt it.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Patch planning for Galaxy S26, Pixel 10, Codex and Oracle AI database deployments now has a hard outer date from the 90-day rule, with fixes able to land at any point before it.
- constraint Samsung already knew some of the bugs used against the Galaxy S26 on day one, so the 98 figure overstates how many new fixes patch teams will receive.
- precedent With AI coding apps and AI infrastructure scored beside phones, OpenAI and Oracle now face the same fixed disclosure deadline as handset makers.
Trend Micro's Zero Day Initiative runs Pwn2Own to find zero-days before attackers exploit them in the wild [13]. To count, an entry had to compromise the target and demonstrate arbitrary code execution [14]. So far the public record is the target list, the bug counts and the payouts [1][7]. BleepingComputer's report does not break the 98 down by vendor or list CVEs, so the size of any one product's patch queue cannot be worked out from it [1].
The daily totals add up: 32 bugs for $388,500 on day one, 45 for $232,500 on day two and 21 for $641,000 on day three [4][5][6][10]. Day two produced the most bugs and the least money, about $5,170 a bug [16]. Day three paid about $30,520 a bug [17]. The Pixel 10 chain alone was 47% of that day's payout [18].
Samsung's Galaxy S26 fell at least seven times [19]. Interrupt Labs, Ikotas Labs and Nguyen Thanh Dat of Viettel Cyber Security broke it on day one [3]. PetoWorks, Kyeongmin Kim of KAIST Hacking Lab and a CENSUS Labs team took it down three more times on day two, and it was rooted again on day three [5][6]. Six of the entrants who broke it are named [20]. The Pixel 10 went down three times on the final day [6].
Pwn2Own Ireland 2025 produced 73 zero-days and $1,024,750 in awards, and Summoning Team won it with $187,500 [15]. This year's 98 is 25 more, an increase of about 34%, while the purse grew about 23% [21][22]. The average award per bug fell from about $14,040 to about $12,880 [23]. Ikotas Labs' winning total is close to double Summoning Team's [24].
What to watch
- Samsung and Google security bulletins crediting Pwn2Own Ireland 2026 entrants, the first count of how many Galaxy S26 and Pixel 10 bugs were new.
- OpenAI and Oracle statements on the Codex and Autonomous AI Database fixes, including whether customers must take any action.
- ZDI advisories at the end of the 90-day window, the first public detail on bug classes and on any vendor that missed the deadline.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives45
- Confidence72
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Pwn2Own Ireland 2026 concluded with hackers collecting $1,262,000 in rewards after exploiting 98 zero-day flaws.
ReportedSupportedSource: BleepingComputer3 sources— create a free account to open themView cited source - [2]
Ikotas Labs collected the competition's top reward of $300,000 on the third day after chaining multiple zero-days to hack the Google Pixel 10.
ReportedSupportedSource: BleepingComputer2 sources— create a free account to open themView cited source - [3]
Interrupt Labs, Ikotas Labs and Nguyen Thanh Dat of Viettel Cyber Security hacked the Samsung Galaxy S26 on the first day, but the vendor already knew some of the exploited bugs.
ReportedSupportedSource: BleepingComputer2 sources— create a free account to open themView cited source - [4]
On day one, competitors collected $388,500 after demonstrating 32 zero-day flaws.
ReportedSupportedSource: BleepingComputer2 sources— create a free account to open themView cited source - [5]
On day two, competitors earned $232,500 for 45 unique zero-days; PetoWorks, KAIST Hacking Lab's Kyeongmin Kim and a CENSUS Labs team of Dimitrios Valsamaras, Ken Gannon and Tenia Valsamara took down the Galaxy S26 three more times.
ReportedSupportedSource: BleepingComputer2 sources— create a free account to open themView cited source - [6]
On day three, hackers rooted the Samsung Galaxy S26 again and took down the Google Pixel 10 three times, exploiting 21 zero-days for $641,000.
ReportedSupportedSource: BleepingComputer2 sources— create a free account to open themView cited source - [7]
29 research teams targeted products across seven categories: mobile phones (Samsung Galaxy S26 and Google Pixel 10), AI infrastructure, AI coding apps, messaging apps, smart home devices, printers, and a new wellness healthcare devices category.
ReportedSupportedSource: BleepingComputer2 sources— create a free account to open themView cited source - [8]
Apple's iPhone 17 was a potential target with a maximum award of $300,000 for a remote hack, but no contestant registered for an attempt.
ReportedSupportedSource: BleepingComputer2 sources— create a free account to open themView cited source - [9]
Vendors must patch zero-days disclosed during Pwn2Own within 90 days before ZDI publicly shares details.
ReportedSupportedSource: BleepingComputer2 sources— create a free account to open themView cited source - [10]
The three daily totals sum to the contest totals: 98 zero-days and $1,262,000.
- [11]
Ikotas Labs won Pwn2Own Ireland 2026 with 42.5 Master of Pwn points and $361,000 earned over the three-day contest after hacking the Samsung Galaxy S26, OpenAI Codex and the Oracle Autonomous AI Database.
- [12]
Xint took second place with $240,000 and 27.5 Master of Pwn points; Team ZyGoat was third with $125,000 and 27.5 Master of Pwn points.
- [13]
Trend Micro's Zero Day Initiative organizes Pwn2Own to identify zero-day flaws before attackers exploit them in the wild.
- [14]
Pwn2Own rules require all devices and products to run the latest firmware versions, and contestants must compromise the target and demonstrate arbitrary code execution.
- [15]
At Pwn2Own Ireland 2025, hackers demoed 73 zero-days to earn $1,024,750; Summoning Team won with $187,500.
- [16]
Day two paid about $5,170 per zero-day.
- [17]
Day three paid about $30,520 per zero-day.
- [18]
The $300,000 Pixel 10 award was about 47% of day three's $641,000 payout.
- [19]
The Galaxy S26 was compromised at least seven times over the three days.
- [20]
Six named entrants broke the Galaxy S26 across days one and two.
- [21]
The 2026 contest produced 25 more zero-days than 2025, about 34% more.
- [22]
Total awards rose about 23% from 2025 to 2026.
- [23]
Average award per zero-day fell from about $14,040 in 2025 to about $12,880 in 2026.
- [24]
Ikotas Labs' $361,000 winning total is about 1.9 times Summoning Team's $187,500 winning total in 2025.
Sources
2 independent publishers whose own reporting we read for this story.
- bleepingcomputer.comHackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland
1 article · October 8, 2026
- securityweek.comGoogle Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Zero-Day VulnerabilitiesFollow
- Hacking competitionsFollow
- AI Tooling SecurityFollow
- Coordinated Vulnerability DisclosureFollow
- Mobile securityFollow