Pwn2Own Ireland 2026 Ends With 98 Zero-Days and $1.26 Million in Prize Money
The Pwn2Own Ireland 2026 hacking competition has concluded after security researchers exploited 98 zero-day vulnerabilities and earned a combined $1,262,000 in prize money.
A security researcher from Ikotas Labs won this year’s competition with 42.5 Master of Pwn points and $361,000 in winnings. Over the three-day event, the researcher hacked a Samsung Galaxy S26, OpenAI Codex, and Oracle Autonomous AI Database.
The researcher also claimed the contest’s top prize of $300,000 on the final day after chaining multiple zero-day vulnerabilities to hack a Google Pixel 10. Details were shared by the Zero Day Initiative.
Ikotas Labs takes first place at Pwn2Own Ireland 2026
Xint finished in second place with $240,000 in prize money and 27.5 Master of Pwn points. Team ZyGoat placed third with $125,000 and 27.5 Master of Pwn points.
Nguyen Thanh Dat from Interrupt Labs, Ikotas Labs, and Viettel Cyber Security hacked Samsung’s flagship Galaxy S26 on the first day. However, the vendor already knew part of the vulnerability that was used in the exploit.
Competitors earned $388,500 on the first day after demonstrating 32 zero-day vulnerabilities.
Researchers exploit Samsung Galaxy S26 and Google Pixel 10
On the second day, contestants earned $232,500 for demonstrating 45 unique zero-day vulnerabilities. PetoWorks, Kyungmin Kim of KAIST Hacking Lab, and a team consisting of Dimitrios Valsamaras, Ken Gannon, and Tenia Valsamaras from CENSUS Labs defeated the Samsung Galaxy S26 three additional times.
On the third and final day, hackers re-rooted the Samsung Galaxy S26 and compromised the Google Pixel 10 three times. Security researchers exploited 21 zero-day vulnerabilities on the final day, earning $641,000 in prize money. Read the Zero Day Initiative’s day-three results.

Seven target categories featured in the 2026 competition
A total of 29 research teams participated in Pwn2Own Ireland 2026. The event featured targets across seven categories, including mobile phones, AI infrastructure, AI coding applications, messaging apps, smart home devices, printers, and wellness and healthcare devices. The mobile phone targets were the Samsung Galaxy S26 and Google Pixel 10.
See the full list of Pwn2Own Ireland 2026 targets and categories.
Apple’s iPhone 17 was also available as a potential target. The contest offered a reward of up to $300,000 for a remote hack, but no challenger registered to target the device.
How Pwn2Own handles zero-day vulnerabilities
Trend Micro’s Zero Day Initiative (ZDI) organizes Pwn2Own competitions to identify zero-day vulnerabilities before attackers can exploit them. Under the Pwn2Own Ireland 2026 rules, all devices and products must run their latest firmware versions, and contestants must demonstrate arbitrary code execution by compromising a target.
Vendors must patch vulnerabilities disclosed during the Pwn2Own competition within 90 days before ZDI publishes technical details.
How Pwn2Own Ireland 2026 compares with 2025
At Pwn2Own Ireland 2025, hackers demonstrated 73 zero-day vulnerabilities and won $1,024,750. Summoning Team won that competition and collected $187,500 after hacking a Samsung Galaxy S25, Home Assistant Green, QNAP TS-453E NAS, and multiple Synology devices.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about how AI-speed attacks will change security, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



