What does it take to break into a brand-new Samsung Galaxy S26? At Pwn2Own Ireland 2026, one team says the answer was a single email. Over three days in Cork, from October 6 to 8, researchers broke into phones, printers, smart speakers, smart home hubs, a blood pressure monitor and AI coding tools, and they were paid for every working attack.
Here’s the short version of the pwn2own ireland 2026 results. Day one produced 32 unique zero-days and $388,500 in awards. Day two added 45 more zero-days and $232,500, and day three ended with Japan’s Ikotas Labs crowned Master of Pwn after a $300,000 remote hack of the Google Pixel 10.
So what does that mean if you own one of these gadgets? These bugs now go to the vendors, who get a patch window before details go public. The rest of this guide covers what got hacked, how the money added up, and what you should update this week.
| Key fact | Details |
|---|---|
| Event | Pwn2Own Ireland 2026, run by Trend Micro’s Zero Day Initiative (ZDI) |
| Dates and venue | October 6–8, 2026 (rules window ran to Oct 9), Cork, Ireland |
| Day one | 32 unique zero-days, $388,500 awarded |
| Day two | 45 unique zero-days, $232,500 awarded |
| Running total after day two | 77 zero-days, $621,000 (per CyberInsider) |
| Master of Pwn | Ikotas Labs, Inc. |
| Biggest single payout | $300,000 for a Google Pixel 10 remote exploit |
| Most-hacked phone | Samsung Galaxy S26 (seven successful entries across three days) |
| Patch window | Vendors get 90 days before ZDI publishes details |
What is Pwn2Own, and why should you care?
Let’s back up a little. Pwn2Own is a hacking contest where the Zero Day Initiative pays researchers to break fully patched, off-the-shelf products live on stage. Every exploit has to work against the latest software in its default setup, launch with a single command and finish within a 10-minute attempt.
Why does that matter to you? Because winning exploits aren’t sold to criminals. They go to ZDI with a written breakdown, and ZDI passes them to the vendors to fix.
How the 2026 rules worked
This year’s rules tightened who could enter. Contestants needed at least $15,000 in lifetime ZDI bounty payments (with up to 10 exceptions), and registration was capped at 80 entries. Each person could get three tries, 10 minutes apiece, inside a 30-minute window.
ZDI also reshaped the target list. It cut most consumer smart home gear in favor of “pro-sumer” hubs, trimmed the printers and added a brand-new Wellness category for health devices.
| Category | Targets | Top prize |
|---|---|---|
| Mobile phones | Galaxy S26, Pixel 10, iPhone 17 | $300,000 (Pixel 10 or iPhone 17, remote) |
| Messaging | WhatsApp on all three phones | $300,000 (zero-click) |
| Smart home | Philips Hue Bridge Pro, Home Assistant Green, Sonos Era 300 | $50,000 (Sonos) |
| Wellness (new) | Dexcom Stelo, Garmin Index BPM, Oura Ring 5 | $20,000 each |
| Printers | Lexmark CX532adwe, Canon imageFORCE 1643F, Brother MFC-L8970CDW | $20,000 each |
| AI infrastructure | Chroma, pgvector, Oracle Autonomous AI Database, LiteLLM, Dynamo | $40,000 |
| Coding agents | Claude Code, OpenAI Codex | $40,000 each |
One more rule explains a lot of the smaller payouts below. When a chain uses a bug that’s already known to the vendor or was used by an earlier team, ZDI calls it a “collision” and pays less. That’s why some successful hacks earned $40,000 while others earned $4,500.
Pwn2Own Ireland 2026 results, day by day
Day one brought the most cash, day two the most bugs and day three the biggest single payouts.
| Day | Date | Unique zero-days | Awarded | Headline moment |
|---|---|---|---|---|
| Day one | Tue, Oct 6 | 32 | $388,500 | Galaxy S26 hacked three times; 7-bug Philips Hue chain |
| Day two | Wed, Oct 7 | 45 | $232,500 | Galaxy S26 hacked three more times; DOOM on a Lexmark printer |
| Day three | Thu, Oct 8 | Not yet totaled by ZDI | About $635,000 in posted payouts | Pixel 10 falls three times; Ikotas Labs wins |
Day one: phones, speakers and a seven-bug smart home chain
The contest opened with McCaulay Hudson taking $50,000 for hacking the Sonos Era 300 with an out-of-bounds write and a format string bug. VinSOC then chained seven zero-days to take over a Philips Hue Bridge Pro for $40,000, and another VinSOC team used five bugs against the Oracle Autonomous AI Database for another $40,000.
AI tools didn’t escape either. Xint broke LiteLLM and Ikotas Labs took down OpenAI’s Codex with a single argument injection bug, each for $40,000. Interrupt Labs landed the first-ever full win in the Wellness category, hacking the Garmin Index BPM blood pressure monitor for $20,000.
Printers proved stubborn, with two teams running out of time. That said, Lexmark still fell twice.
Day two: 45 zero-days and a printer running DOOM
Day two was a volume game. Out of Bounds’ HaeJung Yang earned $40,000 for hacking the Dynamo AI inference framework, Xint’s Yves Bieri took $30,000 for the Home Assistant Green hub, and RET2 Systems’ Jack Dates reportedly ran a Sonos Era 300 exploit chain in under a minute.
The fun moment? Interrupt Labs hacked a Lexmark CX532adwe and put DOOM on its screen, according to CyberInsider. Home Assistant Green was also broken five times that day.
By the end of day two, CyberInsider counted $621,000 paid for 77 unique zero-days, with Xint and Ikotas Labs tied at 12.5 Master of Pwn points.
Day three: the Pixel 10 finally cracks
Day three is where the big money landed. The Google Pixel 10, which nobody had beaten on day one, fell three times. Xint earned $150,000, a team from Mobile Hacking Lab and CENSUS Labs took $112,500, and Ikotas Labs claimed the full $300,000 and 30 points.
FuzzingLabs also beat the Brother printer with a single zero-day for $20,000, and Team MAMMOTH closed the show with a six-zero-day chain against Home Assistant Green.
“$300,000!!!!! and 30 Master of Pwn points officially makes Ikotas Labs, Inc. the Master of Pwn” — ZDI’s day three results post
The Samsung Galaxy S26 had a rough week
If you own a Galaxy S26, this is the part you care about most. Samsung’s flagship was successfully attacked seven times across the three days: three times on day one, three times on day two and once more on day three by BunkyoWesterns.
Sounds alarming, right? Not quite. Many of those chains reused bugs Samsung already knew about. Viettel’s day one entry used four bugs, three of them already known to the vendor, and Interrupt Labs’ chain had three collisions and one fresh zero-day.
The single-email attack
The headline grabber came from Ikotas Labs. According to Cybernews, the company said it ran code remotely on the Galaxy S26 using a single email, through a four-bug chain where only one bug was already known to Samsung. Ikotas CEO Satoki Tsuji reportedly said the same flaw works on recent Pixel 10 and Galaxy S26 models, and Ikotas used it again for its $300,000 Pixel 10 win on day three.
Here’s the catch. ZDI hasn’t published CVEs, affected components or technical details, and Samsung hadn’t commented in that report. So you can’t tell yet exactly which app or service is involved.
The key takeaway here is simple: if your phone was on that stage, the fix will arrive as an ordinary security update, so make sure you actually install it.
Who won Master of Pwn at Pwn2Own Ireland 2026?
Ikotas Labs, Inc. took the title. The Japanese firm had 12.5 points after day two, then jumped to the top of the leaderboard with the 30-point Pixel 10 exploit on the final day.
The prize for Master of Pwn is 65,000 ZDI reward points, which the rules value at about $25,000, plus Platinum status in ZDI’s program for 2027.
“Every collision on that stage is a bug someone already found. The question is whether it got patched.”
What these results mean for you
Here’s the thing. None of these exploits were used against real people. They ran on contest hardware, and the details now go to vendors.
According to BleepingComputer and Infosecurity Magazine, vendors have 90 days to release fixes before ZDI publicly discloses the flaws. Counting from October 6–8, that points to roughly early January 2027 as the outer limit, though many vendors patch much sooner.
Which devices were hit
Check this list against what’s in your home or office:
- Phones: Samsung Galaxy S26 and Google Pixel 10. The iPhone 17 was a listed target, but no iPhone result appeared in ZDI’s posts.
- Smart home: Philips Hue Bridge Pro, Home Assistant Green and Sonos Era 300.
- Printers: Lexmark CX532adwe, Canon imageFORCE 1643F and Brother MFC-L8970CDW.
- Health: Garmin Index BPM blood pressure monitor.
- AI tools: LiteLLM, Dynamo, Chroma, Oracle Autonomous AI Database and OpenAI Codex.
Notice what’s missing? Routers and NAS boxes weren’t on this year’s target list. That doesn’t mean yours are safe, only that they weren’t tested here.
What to do now
You don’t need to panic, but you should get ahead of the patches.
1. Turn on automatic updates for your phone
On a Galaxy S26 or Pixel 10, open Settings and make sure system and security updates install automatically. Fixes for Pwn2Own bugs usually arrive in a regular monthly security patch, not a special release. If your phone already feels off, the guide on how to know if your phone is hacked walks you through the warning signs.
2. Update your smart home hubs and speakers
Open the Philips Hue, Home Assistant or Sonos app and check for firmware updates. Hubs matter most because ZDI picked them precisely for controlling other devices and services.
3. Patch your printer’s firmware
Printers are the most forgotten devices on any network. Visit Lexmark, Canon or Brother’s support page, or the printer’s own web settings, and install the latest firmware.
4. Lock down your router and NAS anyway
Even though they weren’t targets this year, routers and NAS boxes are prime attack surfaces. Update their firmware, change default passwords and disable remote admin access. The same lesson came up in recent business-grade flaws like FortiBleed and the Citrix NetScaler vulnerability.
5. Keep AI tools on a short leash
If your team runs LiteLLM, Chroma, Dynamo or a coding agent like Codex, watch for vendor advisories over the next 90 days. Keep these services off the open internet and require authentication. Recent enterprise bugs such as the Atlassian vulnerability CVE-2026-21589 show how quickly exposed tools get targeted once details go public.
Looking ahead
Every connected device is software, and all software has bugs. The good news? These bugs were found by people paid to report them, not sell them.
Over the next few months, expect a steady trickle of patches from Samsung, Google, Sonos, Philips, the printer makers and the AI vendors. Your job is easy: install those updates when they arrive and don’t let your printer or smart hub sit on firmware from 2024.
Source: ZDI’s official Pwn2Own Ireland 2026 results blog.
Frequently asked questions
Pwn2Own is a live hacking competition run by Trend Micro’s Zero Day Initiative. Security researchers try to break fully patched consumer and enterprise products within a strict time limit.
ZDI holds its fall consumer-device event in Cork, and 2026 was its third year there. It focuses on phones, smart home gear, printers, wellness devices and AI tools.
The Zero Day Initiative is a bug bounty program that buys vulnerability research from independent researchers. It then works with vendors to get those flaws fixed before details become public.
Each exploit had to work against the latest, fully patched software in its default configuration. Contestants got up to three attempts of 10 minutes each, inside a 30-minute window, and every attack had to be fully automated. Bugs already known to the vendor still counted, but paid less.
The exploits were shown only on contest devices, and the details are private while vendors work on fixes. Vendors have 90 days before ZDI publishes details. Keep automatic updates on and install monthly security patches as soon as they land.
Day one paid $388,500 and day two paid $232,500, for $621,000 across 77 zero-days. ZDI’s day three post lists about $635,000 in further payouts, which would put the event at roughly $1.26 million. ZDI hadn’t posted an official final total at the time of writing.

