Skip to content

TechToRev

Menu
  • Home
  • Contact
Menu
Pwn2Own Ireland 2026 illustration: smartphone, smart speaker, printer and smart home hub under security scan lines

Pwn2Own Ireland 2026: Hackers Earned $388,500 on Day One With 32 Zero-Days

Posted on October 7, 2026 by saudshoukat199@gmail.com

Day one of Pwn2Own Ireland 2026 is over, and the scoreboard says it all: on October 6, 2026, security researchers earned $388,500 in prizes after exploiting 32 zero-day vulnerabilities across smartphones, smart home gear, printers, and AI systems. Samsung’s brand-new Galaxy S26 flagship was hacked twice before the day ended.

Pwn2Own Ireland is the annual hacking competition run by Trend Micro’s Zero Day Initiative (ZDI). Teams compete to break into real, fully patched devices across seven categories: mobile phones, printers, smart home devices, messaging apps, AI infrastructure, AI coding apps, and a new wellness healthcare device category. After the contest, vendors get 90 days to release security updates before ZDI publicly discloses the flaws.

Samsung Galaxy S26 Falls Twice on Day One

The biggest headline of the day belonged to Samsung. Three separate teams — Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security — all successfully compromised the Galaxy S26, Samsung’s newest flagship phone. Each team exploited a distinct set of vulnerabilities to break the device’s security within the contest’s time limits.

There is one important caveat: BleepingComputer, reporting from the ZDI leaderboard, notes that some of the bugs exploited in the mobile challenges were already known to the vendor. That is a reminder that contest tallies and real-world risk are not exactly the same thing — a bug a vendor already knows about may already have a fix in the pipeline.

On the other side of the mobile category, the Google Pixel 10 survived its first attempt. A team from White Noise Club (Mikhail Evdokimov, Polina Smirnova, and Mate Zombor) targeted the Pixel 10 but could not get their exploit working within the allotted time. They get another shot on the remaining days.

The $80,000 Leaderboard: Philips Hue Bridge Pro and Oracle AI

The day’s top earners were Vũ Chí Thành and Huỳnh Đức Tin of VinSOC, who walked away with $80,000 — the largest single-day haul of the competition so far.

Their first prize: $40,000 for chaining together seven zero-day vulnerabilities to take over a Philips Hue Bridge Pro smart lighting hub. Their second: another $40,000 for a five-zero-day exploit chain against the Oracle Autonomous AI Database. Those complex, multi-step chains are exactly what Pwn2Own rewards most: one bug might get you a footnote, but a full working chain through seven of them earns top dollar.

Other Notable Day-One Hacks

Beyond the phones and the leaderboard-toppers, researchers compromised a wide spread of targets:

  • OpenAI Codex — the cloud-based AI coding agent fell to a single argument-injection bug. No long chain, no elaborate setup: one well-placed flaw was enough.
  • LiteLLM — the popular LLM routing platform was hit with zero-day exploits, putting the AI infrastructure category firmly in the spotlight.
  • Lexmark CX532adwe and Canon imageFORCE 1643F — two multifunction printers fell, continuing Pwn2Own’s long tradition of embarrassing office hardware.
  • Sonos Era 300 — the smart speaker was compromised using four vulnerabilities chained together.

AI Systems Are the New Favorite Target

Look closely at the day-one list and a pattern jumps out: the Oracle Autonomous AI Database, OpenAI Codex, and LiteLLM all sit in the AI categories. AI infrastructure and AI coding apps are no longer side events — they are among the most contested targets in the competition.

That reflects what is happening in the real world, where AI services are being deployed faster than their security is being hardened. For more on how quickly flaws are turning up in AI platforms, see our coverage of the GitLab AI Gateway critical flaw (CVE-2026-90970), another AI-focused vulnerability disclosed this month.

Why Pwn2Own Matters for Regular Users

It is easy to read these headlines and worry. A few things keep the risk in perspective:

  • Nothing here is malicious. Every exploit was demonstrated in a controlled contest setting by researchers who report their findings through ZDI.
  • Vendors get a head start. The standard 90-day coordinated disclosure window means patches are already in development before technical details go public.
  • Contests find the bugs before attackers do. A zero-day demonstrated on stage is a zero-day that will get fixed — the alternative is leaving it for criminals to find.

That said, the contest is a reminder of the same advice that applies after any major vulnerability disclosure: keep your devices updated and install security patches promptly, as explained in our write-ups of the Apple zero-day (CVE-2026-86950) and the FortiMail zero-day (CVE-2026-104286).

What Comes Next: Days Two and Three

The contest is not over. On October 7 (today), researchers are again targeting AI infrastructure, printers, smart home, and wellness devices, with the Galaxy S26 and Pixel 10 back in the mobile category. On the third day, the Pixel 10 and Galaxy S26 face more attempts alongside smart home, AI infrastructure, and printer targets.

For comparison, last year’s Pwn2Own Ireland paid out $1,024,750 across 73 zero-day flaws — so the remaining days could still add up to a record-breaking total.

FAQ

What is Pwn2Own Ireland?

Pwn2Own Ireland is an annual hacking competition organized by Trend Micro’s Zero Day Initiative. Security researchers compete for cash prizes by exploiting zero-day vulnerabilities in real consumer and enterprise devices. Vendors are given 90 days to release patches before the flaws are publicly disclosed.

How much did researchers win on day one of Pwn2Own Ireland 2026?

Researchers earned a combined $388,500 on the first day (October 6, 2026) after exploiting 32 zero-day vulnerabilities. The top earners, VinSOC’s Vũ Chí Thành and Huỳnh Đức Tin, collected $80,000 between two complex exploit chains.

Was the Samsung Galaxy S26 really hacked twice?

Yes. Three teams — Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security — all successfully compromised Samsung’s new Galaxy S26 flagship on day one. Note that some of the bugs used were reportedly already known to Samsung.

When will the Pwn2Own vulnerabilities be disclosed publicly?

ZDI’s standard policy gives vendors 90 days to release security updates after the competition before the technical details are publicly disclosed. That puts public disclosure roughly in early January 2027.

Should I be worried about my own devices right now?

There is no indication that any of these flaws are being exploited in the wild. The standard advice applies: keep your phone, smart home devices, and other gear updated, and install security patches as soon as your vendor releases them.

For background on how enterprise infrastructure flaws get handled after disclosure, see our explainer on the KVM zero-day VM escape confirmed by Vercel.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Mistral Large 4 Le Chonk 1 trillion parameter open-weight AI model illustration over a European data center
    Mistral Large 4 Explained: Le Chonk, 1 Trillion Parameters and When the Open Weights Land
    by saudshoukat199@gmail.com
    October 7, 2026
  • Illustration of a smartphone banking app surrounded by email envelopes with security warning icons, representing the Revolut data breach
    Revolut Hack Explained: What Happened, What Was Exposed and What to Do Next
    by saudshoukat199@gmail.com
    October 7, 2026
  • Pwn2Own Ireland 2026 illustration: smartphone, smart speaker, printer and smart home hub under security scan lines
    Pwn2Own Ireland 2026: Hackers Earned $388,500 on Day One With 32 Zero-Days
    by saudshoukat199@gmail.com
    October 7, 2026
  • Smart video doorbell, deadbolt lock, thermostat and security camera on a modern home at dusk, illustrating the reported Apple and LG smart home lineup
    Apple and LG Smart Home Lineup Explained: Smart Lock, Doorbell, Thermostat, Cameras and Everything We Know
    by saudshoukat199@gmail.com
    October 7, 2026
  • Illustration of a Mac with a security shield stopping an AI agent from accessing files, mail, and messages
    Apple Is Tightening macOS Full Disk Access Over AI Agent Risks: What Changes
    by saudshoukat199@gmail.com
    October 7, 2026
© 2026 TechToRev | Powered by Superbs Personal Blog theme