Close Menu

    Subscribe to Updates

    Get the latest tech news, how-to guides and quick fixes from Technology Ripple, delivered straight to your inbox.

    ← Back

    Thank you for your response. ✨

    By signing up, you agree to our terms and our Privacy Policy.

    What's Hot

    Fitbit Not Syncing? 12 Fixes for the Google Health App

    October 11, 2026

    Venmo Payment Declined? Why It Happens and How to Fix It

    October 11, 2026

    Roomba Not Connecting to WiFi? 11 Fixes to Get It Online

    October 11, 2026
    Technology RippleTechnology Ripple
    Subscribe
    • Latest News
    • AI
    • Apple
    • Smart Tech
    • Startups
    • Gaming
    • Phones
    • Cybersecurity
    • Fintech
    Technology RippleTechnology Ripple
    Home » Blog » Pwn2Own Ireland 2026: Results, Zero-Days and What Got Hacked
    Cybersecurity

    Pwn2Own Ireland 2026: Results, Zero-Days and What Got Hacked

    TR EditorBy TR EditorOctober 9, 202611 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Pwn2Own Ireland 2026 results graphic showing hacked phones, printers and smart home devices
    Share
    Facebook Twitter LinkedIn Pinterest Email

    What does it take to break into a brand-new Samsung Galaxy S26? At Pwn2Own Ireland 2026, one team says the answer was a single email. Over three days in Cork, from October 6 to 8, researchers broke into phones, printers, smart speakers, smart home hubs, a blood pressure monitor and AI coding tools, and they were paid for every working attack.

    Here’s the short version of the pwn2own ireland 2026 results. Day one produced 32 unique zero-days and $388,500 in awards. Day two added 45 more zero-days and $232,500, and day three ended with Japan’s Ikotas Labs crowned Master of Pwn after a $300,000 remote hack of the Google Pixel 10.

    So what does that mean if you own one of these gadgets? These bugs now go to the vendors, who get a patch window before details go public. The rest of this guide covers what got hacked, how the money added up, and what you should update this week.

    Key factDetails
    EventPwn2Own Ireland 2026, run by Trend Micro’s Zero Day Initiative (ZDI)
    Dates and venueOctober 6–8, 2026 (rules window ran to Oct 9), Cork, Ireland
    Day one32 unique zero-days, $388,500 awarded
    Day two45 unique zero-days, $232,500 awarded
    Running total after day two77 zero-days, $621,000 (per CyberInsider)
    Master of PwnIkotas Labs, Inc.
    Biggest single payout$300,000 for a Google Pixel 10 remote exploit
    Most-hacked phoneSamsung Galaxy S26 (seven successful entries across three days)
    Patch windowVendors get 90 days before ZDI publishes details

    What is Pwn2Own, and why should you care?

    Let’s back up a little. Pwn2Own is a hacking contest where the Zero Day Initiative pays researchers to break fully patched, off-the-shelf products live on stage. Every exploit has to work against the latest software in its default setup, launch with a single command and finish within a 10-minute attempt.

    Why does that matter to you? Because winning exploits aren’t sold to criminals. They go to ZDI with a written breakdown, and ZDI passes them to the vendors to fix.

    How the 2026 rules worked

    This year’s rules tightened who could enter. Contestants needed at least $15,000 in lifetime ZDI bounty payments (with up to 10 exceptions), and registration was capped at 80 entries. Each person could get three tries, 10 minutes apiece, inside a 30-minute window.

    ZDI also reshaped the target list. It cut most consumer smart home gear in favor of “pro-sumer” hubs, trimmed the printers and added a brand-new Wellness category for health devices.

    CategoryTargetsTop prize
    Mobile phonesGalaxy S26, Pixel 10, iPhone 17$300,000 (Pixel 10 or iPhone 17, remote)
    MessagingWhatsApp on all three phones$300,000 (zero-click)
    Smart homePhilips Hue Bridge Pro, Home Assistant Green, Sonos Era 300$50,000 (Sonos)
    Wellness (new)Dexcom Stelo, Garmin Index BPM, Oura Ring 5$20,000 each
    PrintersLexmark CX532adwe, Canon imageFORCE 1643F, Brother MFC-L8970CDW$20,000 each
    AI infrastructureChroma, pgvector, Oracle Autonomous AI Database, LiteLLM, Dynamo$40,000
    Coding agentsClaude Code, OpenAI Codex$40,000 each

    One more rule explains a lot of the smaller payouts below. When a chain uses a bug that’s already known to the vendor or was used by an earlier team, ZDI calls it a “collision” and pays less. That’s why some successful hacks earned $40,000 while others earned $4,500.

    Pwn2Own Ireland 2026 results, day by day

    Day one brought the most cash, day two the most bugs and day three the biggest single payouts.

    DayDateUnique zero-daysAwardedHeadline moment
    Day oneTue, Oct 632$388,500Galaxy S26 hacked three times; 7-bug Philips Hue chain
    Day twoWed, Oct 745$232,500Galaxy S26 hacked three more times; DOOM on a Lexmark printer
    Day threeThu, Oct 8Not yet totaled by ZDIAbout $635,000 in posted payoutsPixel 10 falls three times; Ikotas Labs wins

    Day one: phones, speakers and a seven-bug smart home chain

    The contest opened with McCaulay Hudson taking $50,000 for hacking the Sonos Era 300 with an out-of-bounds write and a format string bug. VinSOC then chained seven zero-days to take over a Philips Hue Bridge Pro for $40,000, and another VinSOC team used five bugs against the Oracle Autonomous AI Database for another $40,000.

    AI tools didn’t escape either. Xint broke LiteLLM and Ikotas Labs took down OpenAI’s Codex with a single argument injection bug, each for $40,000. Interrupt Labs landed the first-ever full win in the Wellness category, hacking the Garmin Index BPM blood pressure monitor for $20,000.

    Printers proved stubborn, with two teams running out of time. That said, Lexmark still fell twice.

    Day two: 45 zero-days and a printer running DOOM

    Day two was a volume game. Out of Bounds’ HaeJung Yang earned $40,000 for hacking the Dynamo AI inference framework, Xint’s Yves Bieri took $30,000 for the Home Assistant Green hub, and RET2 Systems’ Jack Dates reportedly ran a Sonos Era 300 exploit chain in under a minute.

    The fun moment? Interrupt Labs hacked a Lexmark CX532adwe and put DOOM on its screen, according to CyberInsider. Home Assistant Green was also broken five times that day.

    By the end of day two, CyberInsider counted $621,000 paid for 77 unique zero-days, with Xint and Ikotas Labs tied at 12.5 Master of Pwn points.

    Day three: the Pixel 10 finally cracks

    Day three is where the big money landed. The Google Pixel 10, which nobody had beaten on day one, fell three times. Xint earned $150,000, a team from Mobile Hacking Lab and CENSUS Labs took $112,500, and Ikotas Labs claimed the full $300,000 and 30 points.

    FuzzingLabs also beat the Brother printer with a single zero-day for $20,000, and Team MAMMOTH closed the show with a six-zero-day chain against Home Assistant Green.

    “$300,000!!!!! and 30 Master of Pwn points officially makes Ikotas Labs, Inc. the Master of Pwn” — ZDI’s day three results post

    The Samsung Galaxy S26 had a rough week

    If you own a Galaxy S26, this is the part you care about most. Samsung’s flagship was successfully attacked seven times across the three days: three times on day one, three times on day two and once more on day three by BunkyoWesterns.

    Sounds alarming, right? Not quite. Many of those chains reused bugs Samsung already knew about. Viettel’s day one entry used four bugs, three of them already known to the vendor, and Interrupt Labs’ chain had three collisions and one fresh zero-day.

    The single-email attack

    The headline grabber came from Ikotas Labs. According to Cybernews, the company said it ran code remotely on the Galaxy S26 using a single email, through a four-bug chain where only one bug was already known to Samsung. Ikotas CEO Satoki Tsuji reportedly said the same flaw works on recent Pixel 10 and Galaxy S26 models, and Ikotas used it again for its $300,000 Pixel 10 win on day three.

    Here’s the catch. ZDI hasn’t published CVEs, affected components or technical details, and Samsung hadn’t commented in that report. So you can’t tell yet exactly which app or service is involved.

    The key takeaway here is simple: if your phone was on that stage, the fix will arrive as an ordinary security update, so make sure you actually install it.

    Who won Master of Pwn at Pwn2Own Ireland 2026?

    Ikotas Labs, Inc. took the title. The Japanese firm had 12.5 points after day two, then jumped to the top of the leaderboard with the 30-point Pixel 10 exploit on the final day.

    The prize for Master of Pwn is 65,000 ZDI reward points, which the rules value at about $25,000, plus Platinum status in ZDI’s program for 2027.

    “Every collision on that stage is a bug someone already found. The question is whether it got patched.”

    What these results mean for you

    Here’s the thing. None of these exploits were used against real people. They ran on contest hardware, and the details now go to vendors.

    According to BleepingComputer and Infosecurity Magazine, vendors have 90 days to release fixes before ZDI publicly discloses the flaws. Counting from October 6–8, that points to roughly early January 2027 as the outer limit, though many vendors patch much sooner.

    Which devices were hit

    Check this list against what’s in your home or office:

    • Phones: Samsung Galaxy S26 and Google Pixel 10. The iPhone 17 was a listed target, but no iPhone result appeared in ZDI’s posts.
    • Smart home: Philips Hue Bridge Pro, Home Assistant Green and Sonos Era 300.
    • Printers: Lexmark CX532adwe, Canon imageFORCE 1643F and Brother MFC-L8970CDW.
    • Health: Garmin Index BPM blood pressure monitor.
    • AI tools: LiteLLM, Dynamo, Chroma, Oracle Autonomous AI Database and OpenAI Codex.

    Notice what’s missing? Routers and NAS boxes weren’t on this year’s target list. That doesn’t mean yours are safe, only that they weren’t tested here.

    What to do now

    You don’t need to panic, but you should get ahead of the patches.

    1. Turn on automatic updates for your phone

    On a Galaxy S26 or Pixel 10, open Settings and make sure system and security updates install automatically. Fixes for Pwn2Own bugs usually arrive in a regular monthly security patch, not a special release. If your phone already feels off, the guide on how to know if your phone is hacked walks you through the warning signs.

    2. Update your smart home hubs and speakers

    Open the Philips Hue, Home Assistant or Sonos app and check for firmware updates. Hubs matter most because ZDI picked them precisely for controlling other devices and services.

    3. Patch your printer’s firmware

    Printers are the most forgotten devices on any network. Visit Lexmark, Canon or Brother’s support page, or the printer’s own web settings, and install the latest firmware.

    4. Lock down your router and NAS anyway

    Even though they weren’t targets this year, routers and NAS boxes are prime attack surfaces. Update their firmware, change default passwords and disable remote admin access. The same lesson came up in recent business-grade flaws like FortiBleed and the Citrix NetScaler vulnerability.

    5. Keep AI tools on a short leash

    If your team runs LiteLLM, Chroma, Dynamo or a coding agent like Codex, watch for vendor advisories over the next 90 days. Keep these services off the open internet and require authentication. Recent enterprise bugs such as the Atlassian vulnerability CVE-2026-21589 show how quickly exposed tools get targeted once details go public.

    Looking ahead

    Every connected device is software, and all software has bugs. The good news? These bugs were found by people paid to report them, not sell them.

    Over the next few months, expect a steady trickle of patches from Samsung, Google, Sonos, Philips, the printer makers and the AI vendors. Your job is easy: install those updates when they arrive and don’t let your printer or smart hub sit on firmware from 2024.

    Source: ZDI’s official Pwn2Own Ireland 2026 results blog.

    Frequently asked questions

    What kind of contest is Pwn2Own, and who runs it?

    Pwn2Own is a live hacking competition run by Trend Micro’s Zero Day Initiative. Security researchers try to break fully patched consumer and enterprise products within a strict time limit.

    Why is the Ireland edition held in Cork?

    ZDI holds its fall consumer-device event in Cork, and 2026 was its third year there. It focuses on phones, smart home gear, printers, wellness devices and AI tools.

    What does the Zero Day Initiative do outside the contest?

    The Zero Day Initiative is a bug bounty program that buys vulnerability research from independent researchers. It then works with vendors to get those flaws fixed before details become public.

    What did contestants have to follow to win at Pwn2Own Ireland 2026?

    Each exploit had to work against the latest, fully patched software in its default configuration. Contestants got up to three attempts of 10 minutes each, inside a 30-minute window, and every attack had to be fully automated. Bugs already known to the vendor still counted, but paid less.

    Is my Galaxy S26 or Pixel 10 at risk right now?

    The exploits were shown only on contest devices, and the details are private while vendors work on fixes. Vendors have 90 days before ZDI publishes details. Keep automatic updates on and install monthly security patches as soon as they land.

    How much money was paid out in total?

    Day one paid $388,500 and day two paid $232,500, for $621,000 across 77 zero-days. ZDI’s day three post lists about $635,000 in further payouts, which would put the event at roughly $1.26 million. ZDI hadn’t posted an official final total at the time of writing.

    Cybersecurity Google Pixel 10 Pwn2Own Samsung Galaxy S26 smart home security Zero-Day
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleGalaxy S27 Price Leak: Good News, With a Big Catch
    Next Article Manus Funding: AI Agent Raises $500M+ After Meta Exit
    TR Editor

    Related Posts

    Cybersecurity

    Apple Pay Scam Text: How to Spot It and What to Do Next

    October 10, 2026
    Cybersecurity

    Atlassian Vulnerability CVE-2026-21589: How to Patch Now

    October 8, 2026
    Cybersecurity

    FortiBleed: FBI Warning, Who’s at Risk & How to Lock Down

    October 8, 2026
    Top Posts

    10 Simple Ways to Charge Your Phone Without a Charger

    August 8, 2025

    Why are iPhones more Expensive in Europe?

    November 20, 2024

    M3 vs M4 Chip: Is Apple’s M4 really better?

    May 11, 2025
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news, how-to guides and quick fixes from Technology Ripple, delivered straight to your inbox.

    ← Back

    Thank you for your response. ✨

    By signing up, you agree to our terms and our Privacy Policy.

    Most Popular

    10 Simple Ways to Charge Your Phone Without a Charger

    August 8, 2025

    Why are iPhones more Expensive in Europe?

    November 20, 2024

    M3 vs M4 Chip: Is Apple’s M4 really better?

    May 11, 2025
    Our Picks

    Fitbit Not Syncing? 12 Fixes for the Google Health App

    October 11, 2026

    Venmo Payment Declined? Why It Happens and How to Fix It

    October 11, 2026

    Roomba Not Connecting to WiFi? 11 Fixes to Get It Online

    October 11, 2026

    Subscribe to Updates

    Get the latest tech news, how-to guides and quick fixes from Technology Ripple, delivered straight to your inbox.

    ← Back

    Thank you for your response. ✨

    By signing up, you agree to our terms and our Privacy Policy.

    Technology Ripple
    • Home
    • About
    • Contact
    • Editorial Policy
    • Privacy Policy
    © 2026 Technology Ripple. Tech news, how-to guides and fixes.

    Type above and press Enter to search. Press Esc to cancel.