Protect.Computer
NEWS

Pwn2Own Ireland 2026: 98 Zero-Days Earn Hackers $1.26 Million

· 1 min read · Device safety
Pwn2Own Ireland 2026: 98 Zero-Days Earn Hackers $1.26 Million

The Pwn2Own Ireland 2026 hacking contest has ended with researchers collecting $1,262,000 in rewards for exploiting 98 zero-day flaws. Ikotas Labs won with 42.5 Master of Pwn points and $361,000 after hacking the Samsung Galaxy S26, OpenAI Codex and the Oracle Autonomous AI Database, and also collected the contest’s top $300,000 reward on day three by chaining several zero-days to hack the Google Pixel 10. Xint came second with $240,000 and Team ZyGoat third with $125,000.

Twenty-nine research teams targeted seven categories: mobile phones (Galaxy S26 and Pixel 10), AI infrastructure, AI coding apps, messaging apps, smart home devices, printers and a new wellness-healthcare-device category. Day one produced 32 zero-days and $388,500, including a Galaxy S26 compromise (some of the bugs were already known to Samsung); day two added 45 unique zero-days and $232,500, with the Galaxy S26 taken down three more times; and the final day brought 21 zero-days and $641,000, with the S26 rooted again and the Pixel 10 hacked three times. Apple’s iPhone 17 was a possible target at up to $300,000 for a remote hack, but no contestant registered an attempt.

Trend Micro’s Zero Day Initiative (ZDI) runs the event so flaws are fixed before attackers find them. Contestants must compromise fully patched, latest-firmware targets and demonstrate arbitrary code execution, and vendors have 90 days to patch before ZDI publishes the details. For comparison, Pwn2Own Ireland 2025 saw 73 zero-days and $1,024,750 in awards.

Sources

Related reading