$1,262,000 in rewards were handed out after hackers demonstrated 98 zero-day vulnerabilities over three days at Pwn2Own Ireland 2026, organizers reported.
Ikotas Labs took top prize with a Pixel 10 chain and $361,000 total
Ikotas Labs finished the contest with 42.5 Master of Pwn points and $361,000 in cash after three days of demonstrations. The team claimed the event's single largest individual reward — a $300,000 prize on the third day — by chaining multiple zero-days to compromise the Google Pixel 10. Over the event the team also exploited the Samsung Galaxy S26, OpenAI Codex, and the Oracle Autonomous AI Database, according to the event summary.
Daily tallies: how the $1,262,000 and 98 zero-days were earned
Organizers published a day-by-day accounting of results. On the first day, Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security all demonstrated exploits against the Samsung Galaxy S26; vendors already knew some of the bugs used. Competitors collected $388,500 that day after demonstrating 32 zero-day flaws. The second day produced $232,500 in awards for 45 unique zero-days, including multiple successful Galaxy S26 exploits by PetoWorks, KAIST Hacking Lab's Kyeongmin Kim, and a CENSUS Labs team composed of Dimitrios Valsamaras, Ken Gannon, and Tenia Valsamara. The third day saw researchers exploit 21 zero-days for $641,000 in cash, including rooting the Samsung Galaxy S26 again and taking down the Google Pixel 10 three times.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWinners, points and the field: who competed and what was targeted
Twenty-nine research teams participated across seven categories: mobile phones (Samsung Galaxy S26 and Google Pixel 10), AI infrastructure, AI coding apps, messaging apps, smart home devices, printers, and a new category focused on wellness healthcare devices. Xint finished second with $240,000 and 27.5 Master of Pwn points, and Team ZyGoat took third with $125,000 and 27.5 points. Apple’s iPhone 17 was listed as a potential target with a maximum award of $300,000 for a remote hack, but no contestant registered for an attempt.
Pwn2Own rules and vendor obligations enforced by ZDI
The event is organized by Trend Micro’s Zero Day Initiative (ZDI). Pwn2Own rules require all devices and products to run the latest firmware versions and require contestants to demonstrate a compromise that achieves arbitrary code execution. Under ZDI’s disclosure policy, vendors must patch zero-days disclosed during the competition within 90 days before ZDI publicly shares technical details.
What this means for technologists, vendors, and end users
- Technologists and security teams: The contest demonstrated active, repeatable exploit chains against flagship devices and AI services — including multiple successful compromises of the Samsung Galaxy S26 and targeted takeovers of the Google Pixel 10, OpenAI Codex, and Oracle Autonomous AI Database. Teams operating or defending these platforms will need to follow ZDI disclosures and vendors’ subsequent patches to address the demonstrated arbitrary-code-execution flaws.
- Vendors and procurement leaders: The requirement that targets run the latest firmware and the 90-day patch window set clear operational expectations for vendors who accept Pwn2Own disclosures. The fact that some exploited bugs were already known to a vendor in advance of their demonstration highlights the interplay between public contests and vendor patch-management timelines.
- End users and device owners: The contest spread across mobile phones, AI infrastructure and applications, smart home devices, printers and a new wellness healthcare device category. Owners of affected product lines should watch for vendor patches resulting from ZDI disclosures and apply updates once available, since Pwn2Own demonstrations proved arbitrary code execution is possible in current shipping firmware when exploited.
Pwn2Own Ireland 2026 represents a larger payout and more vulnerabilities than the prior year’s edition: in 2025 contestants demonstrated 73 zero-day flaws and earned $1,024,750, with Summoning Team winning that contest. The 2026 event’s $1,262,000 in rewards and 98 confirmed zero-days underline the continuing role of controlled public contests in surfacing high-impact vulnerabilities for vendor remediation.
Full coverage and the original event summary are available from BleepingComputer: https://www.bleepingcomputer.com/news/security/hackers-earn-1262000-for-98-zero-days-at-pwn2own-ireland/


