The Pwn2Own Ireland 2026 hacking contest has concluded, with hackers collecting $1,262,000 in rewards after exploiting 98 zero-day flaws.
Ikotas Labs security researchers won this year’s Pwn2Own Ireland edition with 42.5 Master of Pwn points and $361,000 earned over the three-day contest after hacking the Samsung Galaxy S26, OpenAI Codex, and the Oracle Autonomous AI Database.
They also collected the competition’s top reward of $300,000 on the third day after chaining multiple zero-days to hack the Google Pixel 10.
Xint took second place with $240,000 and 27.5 Master of Pwn points, while Team ZyGoat secured third with $125,000 in prizes and 27.5 Master of Pwn points.
Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security hacked Samsung’s Galaxy S26 flagship on the first day, but the vendor already knew some of the exploited bugs. In all, competitors collected $388,500 after demonstrating 32 zero-day flaws.
On the second day, competitors earned $232,500 in cash awards for 45 unique zero-day vulnerabilities, with the highlight being PetoWorks, KAIST Hacking Lab’s Kyeongmin Kim, and a team including Dimitrios Valsamaras, Ken Gannon, and Tenia Valsamara from CENSUS Labs, who took down the Galaxy S26 three more times.
On the third day, hackers rooted the Samsung Galaxy S26 again and took down the Google Pixel 10 three times. In total, today security researchers exploited 21 zero-days for $641,000 in cash on the final day of the contest.

This year, 29 research teams targeted products across seven categories: mobile phones (Samsung Galaxy S26 and Google Pixel 10), AI infrastructure, AI coding apps, messaging apps, smart home devices, printers, and a new category focused on wellness healthcare devices.
Apple’s iPhone 17 was also a potential target, with a maximum award of $300,000 for a remote hack, but no contestant registered for an attempt.
Trend Micro’s Zero Day Initiative (ZDI) organizes the competition to identify zero-day flaws before attackers exploit them in the wild. Pwn2Own rules require all devices and products to run the latest firmware versions, and contestants to compromise the target and demonstrate arbitrary code execution.
Vendors must patch zero-days disclosed during the Pwn2Own competition within 90 days before ZDI publicly shares details.
During Pwn2Own Ireland 2025, hackers demoed 73 zero-day flaws to earn $1,024,750. Summoning Team won the contest and collected $187,500 after hacking the Samsung Galaxy S25, the Home Assistant Green, the QNAP TS-453E NAS, and multiple Synology devices.

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

