Pwn2Own Ireland 2026 has concluded, with security researchers collecting $1,262,000 in prize money after exploiting 98 zero-day vulnerabilities across phones, AI infrastructure, printers, smart-home devices, and more over three days. The contest, organized by Trend Micro's Zero Day Initiative (ZDI), drew 29 research teams competing across seven target categories.
The Numbers
| Metric | Value |
|---|---|
| Total prizes awarded | $1,262,000 |
| Zero-day vulnerabilities exploited | 98 |
| Contest duration | 3 days |
| Participating teams | 29 |
Daily Breakdown
- Day 1: Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security hacked the Samsung Galaxy S26, among other targets; competitors collected $388,500 after demonstrating 32 zero-days.
- Day 2: Researchers collected $232,500 after exploiting 45 unique zero-day vulnerabilities.
- Day 3: Hackers rooted the Galaxy S26 again and took down the Google Pixel 10 three times, closing out the contest with 21 zero-days for $641,000 in the final day alone.
Who Won
Ikotas Labs topped the Pwn2Own Ireland leaderboard with 42.5 Master of Pwn points and $361,000 earned over the three days, after successfully hacking the Samsung Galaxy S26, OpenAI Codex, and the Oracle Autonomous AI Database. Xint took second place with $240,000 and 27.5 points, while Team ZyGoat took third, also with 27.5 points and $125,000 in winnings.
What Was Targeted
This year's contest spanned seven categories, reflecting how far the attack surface has expanded beyond traditional enterprise software:
- Mobile phones — Samsung Galaxy S26 and Google Pixel 10, both rooted multiple times across the contest
- AI infrastructure and coding tools — including OpenAI Codex and the Oracle Autonomous AI Database, underscoring how AI tooling has become a first-class target category
- Printers and smart-home devices — long-standing categories where embedded firmware continues to yield exploitable bugs
- Messaging apps
- Wellness and healthcare devices — a new category added for 2026, testing the security of consumer health hardware
The inclusion of AI coding tools and AI databases as explicit, successfully-exploited targets is notable: it signals that AI-integrated products are now mature enough — and exposed enough — to be treated as a serious category at a contest historically dominated by browsers, hypervisors, and operating systems.
What Happens to the Bugs
As with every Pwn2Own event, all 98 vulnerabilities demonstrated are disclosed to their respective vendors under ZDI's coordinated disclosure process. Vendors have 90 days to ship patches before ZDI publishes technical details publicly. Affected vendors — including Samsung, Google, OpenAI, and Oracle — now have active vulnerability reports on file, with the disclosure clock already running.
Why This Matters for Security Teams
- Watch vendor advisories over the next 90 days — patches tied to Pwn2Own Ireland findings should be treated as priority updates the moment they ship, since technical details become public on the same clock.
- Don't treat mobile as a solved problem — both the Galaxy S26 and Pixel 10 fell multiple times across the contest, reinforcing that flagship phone security is an ongoing arms race, not a settled baseline.
- Reassess AI tooling exposure — if your organization runs AI coding assistants or AI-backed databases in production, confirm whether the specific products demonstrated at this contest are in your stack, and prioritize their patches once published.
- Expect embedded-device bugs to linger — printer and smart-home vulnerabilities disclosed at Pwn2Own historically see slower vendor patch cycles than mainstream software; plan compensating network segmentation accordingly.
Sources
- Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland — BleepingComputer
- Zero Day Initiative — Pwn2Own Ireland 2026