Pwn2Own Ireland 2026 Showcases 98 Zero-Day Vulnerabilities
The three-day Pwn2Own Ireland 2026 event transformed the latest smartphones, artificial intelligence services, and smart home devices into a testing ground for 98 zero-day vulnerabilities. The final tally revealed massive payouts totaling $1.262 million. Ikotas Labs emerged as the grand champion after successfully breaching products from Samsung, Google, OpenAI, and Oracle.
Google Pixel 10 Determines the Finale
A decisive attack on the Google Pixel 10 ultimately determined the finale. Ikotas Labs chained multiple vulnerabilities together to achieve a remote exploit. Consequently, they earned $300,000, which stood as the largest single payout of the tournament. The Zero Day Initiative confirmed that this triumph secured 30 points for the team, propelling them to first place in the Master of Pwn standings.
In total, Ikotas Labs accumulated 42.5 points and garnered $361,000. Previously, the team had already compromised Codex utilizing a single argument injection flaw. They also attacked the Samsung Galaxy S26 and breached the Oracle Autonomous AI Database. Xint secured second place with $240,000, while Team ZyGoat claimed third with $125,000.
Record-Breaking Single Day Payouts
On the final day, three separate teams targeted the Google Pixel 10. Xint received $150,000 for a remote exploit leveraging a bug that partially overlapped with a known issue. Another group earned $112,500 by exploiting a chain of two distinct vulnerabilities. Throughout that single day, participants disclosed 21 vulnerabilities and collected $641,000, representing more than half of the entire tournament prize pool.
Samsung Galaxy S26 Under Heavy Fire
The Samsung Galaxy S26 also emerged as a highly prominent target. During the first two days, hackers breached the smartphone six times, even though the device operated on the most recent firmware. In the finale, BunkyoWesterns executed another remote attack by combining two flaws. Because one was novel while the other was already documented, the reward was reduced to $8,250.
Diverse Categories and Vendor Responses
The competition spanned seven categories. These encompassed mobile devices, artificial intelligence infrastructure, programming tools, smart home systems, printers, and medical gadgets. A total of 29 teams participated in the hacking event. The iPhone 17 was also listed among the targets, offering a reward of up to $300,000 for a remote exploit. However, no team registered for such an attempt.
Organizers utilize Pwn2Own to report discovered vulnerabilities to manufacturers prior to publishing technical details. Vendors subsequently receive a 90-day window to develop and deploy essential patches. The previous year concluded with 73 vulnerabilities and payouts reaching $1.024 million. Therefore, the 2026 tournament demonstrated substantial growth in both the volume of discoveries and the total compensation awarded.









