Day one of Pwn2Own Ireland 2026 is over, and the scoreboard says it all: on October 6, 2026, security researchers earned $388,500 in prizes after exploiting 32 zero-day vulnerabilities across smartphones, smart home gear, printers, and AI systems. Samsung’s brand-new Galaxy S26 flagship was hacked twice before the day ended.
Pwn2Own Ireland is the annual hacking competition run by Trend Micro’s Zero Day Initiative (ZDI). Teams compete to break into real, fully patched devices across seven categories: mobile phones, printers, smart home devices, messaging apps, AI infrastructure, AI coding apps, and a new wellness healthcare device category. After the contest, vendors get 90 days to release security updates before ZDI publicly discloses the flaws.
Samsung Galaxy S26 Falls Twice on Day One
The biggest headline of the day belonged to Samsung. Three separate teams — Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security — all successfully compromised the Galaxy S26, Samsung’s newest flagship phone. Each team exploited a distinct set of vulnerabilities to break the device’s security within the contest’s time limits.
There is one important caveat: BleepingComputer, reporting from the ZDI leaderboard, notes that some of the bugs exploited in the mobile challenges were already known to the vendor. That is a reminder that contest tallies and real-world risk are not exactly the same thing — a bug a vendor already knows about may already have a fix in the pipeline.
On the other side of the mobile category, the Google Pixel 10 survived its first attempt. A team from White Noise Club (Mikhail Evdokimov, Polina Smirnova, and Mate Zombor) targeted the Pixel 10 but could not get their exploit working within the allotted time. They get another shot on the remaining days.
The $80,000 Leaderboard: Philips Hue Bridge Pro and Oracle AI
The day’s top earners were Vũ Chí Thành and Huỳnh Đức Tin of VinSOC, who walked away with $80,000 — the largest single-day haul of the competition so far.
Their first prize: $40,000 for chaining together seven zero-day vulnerabilities to take over a Philips Hue Bridge Pro smart lighting hub. Their second: another $40,000 for a five-zero-day exploit chain against the Oracle Autonomous AI Database. Those complex, multi-step chains are exactly what Pwn2Own rewards most: one bug might get you a footnote, but a full working chain through seven of them earns top dollar.
Other Notable Day-One Hacks
Beyond the phones and the leaderboard-toppers, researchers compromised a wide spread of targets:
- OpenAI Codex — the cloud-based AI coding agent fell to a single argument-injection bug. No long chain, no elaborate setup: one well-placed flaw was enough.
- LiteLLM — the popular LLM routing platform was hit with zero-day exploits, putting the AI infrastructure category firmly in the spotlight.
- Lexmark CX532adwe and Canon imageFORCE 1643F — two multifunction printers fell, continuing Pwn2Own’s long tradition of embarrassing office hardware.
- Sonos Era 300 — the smart speaker was compromised using four vulnerabilities chained together.
AI Systems Are the New Favorite Target
Look closely at the day-one list and a pattern jumps out: the Oracle Autonomous AI Database, OpenAI Codex, and LiteLLM all sit in the AI categories. AI infrastructure and AI coding apps are no longer side events — they are among the most contested targets in the competition.
That reflects what is happening in the real world, where AI services are being deployed faster than their security is being hardened. For more on how quickly flaws are turning up in AI platforms, see our coverage of the GitLab AI Gateway critical flaw (CVE-2026-90970), another AI-focused vulnerability disclosed this month.
Why Pwn2Own Matters for Regular Users
It is easy to read these headlines and worry. A few things keep the risk in perspective:
- Nothing here is malicious. Every exploit was demonstrated in a controlled contest setting by researchers who report their findings through ZDI.
- Vendors get a head start. The standard 90-day coordinated disclosure window means patches are already in development before technical details go public.
- Contests find the bugs before attackers do. A zero-day demonstrated on stage is a zero-day that will get fixed — the alternative is leaving it for criminals to find.
That said, the contest is a reminder of the same advice that applies after any major vulnerability disclosure: keep your devices updated and install security patches promptly, as explained in our write-ups of the Apple zero-day (CVE-2026-86950) and the FortiMail zero-day (CVE-2026-104286).
What Comes Next: Days Two and Three
The contest is not over. On October 7 (today), researchers are again targeting AI infrastructure, printers, smart home, and wellness devices, with the Galaxy S26 and Pixel 10 back in the mobile category. On the third day, the Pixel 10 and Galaxy S26 face more attempts alongside smart home, AI infrastructure, and printer targets.
For comparison, last year’s Pwn2Own Ireland paid out $1,024,750 across 73 zero-day flaws — so the remaining days could still add up to a record-breaking total.
FAQ
What is Pwn2Own Ireland?
Pwn2Own Ireland is an annual hacking competition organized by Trend Micro’s Zero Day Initiative. Security researchers compete for cash prizes by exploiting zero-day vulnerabilities in real consumer and enterprise devices. Vendors are given 90 days to release patches before the flaws are publicly disclosed.
How much did researchers win on day one of Pwn2Own Ireland 2026?
Researchers earned a combined $388,500 on the first day (October 6, 2026) after exploiting 32 zero-day vulnerabilities. The top earners, VinSOC’s Vũ Chí Thành and Huỳnh Đức Tin, collected $80,000 between two complex exploit chains.
Was the Samsung Galaxy S26 really hacked twice?
Yes. Three teams — Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security — all successfully compromised Samsung’s new Galaxy S26 flagship on day one. Note that some of the bugs used were reportedly already known to Samsung.
When will the Pwn2Own vulnerabilities be disclosed publicly?
ZDI’s standard policy gives vendors 90 days to release security updates after the competition before the technical details are publicly disclosed. That puts public disclosure roughly in early January 2027.
Should I be worried about my own devices right now?
There is no indication that any of these flaws are being exploited in the wild. The standard advice applies: keep your phone, smart home devices, and other gear updated, and install security patches as soon as your vendor releases them.
For background on how enterprise infrastructure flaws get handled after disclosure, see our explainer on the KVM zero-day VM escape confirmed by Vercel.
