Hackers Win $300,000 Pixel 10 Jackpot to Close Out Pwn2Own Ireland 2026
A team called Ikotas Labs claimed the contest's richest single prize and the Master of Pwn title on the third and final day of Pwn2Own Ireland, capping three days in which hundreds of thousands of dollars changed hands for undisclosed flaws in phones, smart-home hubs, an AI database and an OpenAI coding tool.

A three-day hacking contest in Cork, Ireland, closed out its main competition on Thursday with a researcher team called Ikotas Labs walking away with $300,000 for a single working exploit chain against a Google Pixel 10 — the richest single payday of the week and enough to crown the team Master of Pwn at Pwn2Own Ireland 2026. By Thursday afternoon, organizers had confirmed more than $500,000 in fresh awards on the contest's third day alone, on top of hundreds of thousands already paid out over the two days before it, for vulnerabilities in products from Samsung, Oracle, Philips, Home Assistant, Sonos, Brother, Canon, Lexmark and OpenAI.
Pwn2Own is run by Trend Micro's Zero Day Initiative (ZDI), which pays independent security researchers to find and privately disclose software flaws so vendors can patch them before criminals do. This year's Ireland edition, the contest's third in Cork, ran October 6 through 9 and is the last scheduled general-purpose Pwn2Own of the year, following smaller automotive- and enterprise-focused editions held earlier in 2026.
The numbers
On day one, teams including Interrupt Labs, Ikotas Labs and Viettel Cyber Security took turns breaking into a Samsung Galaxy S26, and BleepingComputer reported that the day's work produced 32 exploited zero-days worth roughly $388,500. ZDI's own recap of day one also credited a Vietnamese team called VinSOC with $40,000 for chaining seven separate zero-days into a single working attack on a Philips Hue Bridge Pro, and another $40,000 for breaking into Oracle's Autonomous AI Database.
Day two brought more of the same across a wider spread of targets. According to ZDI's day two results post, researchers collected payouts for exploits against the Galaxy S26 again, a Home Assistant Green smart-home hub (five separate teams), a Sonos Era 300 speaker, Oracle's AI database a second time, and a product called Chroma, an open-source vector database widely used to store data for AI applications.
Day three, the contest's finale, had roughly $1.33 million in potential prize money riding on 17 scheduled attempts, organizers wrote in Thursday's live results post. The marquee target was the Google Pixel 10, drawing three separate attempts through the day. A team called Xint claimed an early $150,000 for a working exploit chain, only to be overtaken hours later when Ikotas Labs chained several bugs together for the $300,000 top prize, instantly making it the event's points leader. Elsewhere on the day, a two-person team from FuzzingLabs earned $20,000 for a zero-day in a Brother office printer, and a group called Team DDOS collected $4,500 for a five-bug chain, including one zero-day, against Home Assistant Green.
How we got here
Pwn2Own began in 2007 at the CanSecWest security conference in Vancouver, where researchers won laptops by breaking into them through browser exploits, and has grown into a recurring series spanning categories from industrial control systems to cars. ZDI brought the contest to Cork for the first time in 2024 and has returned every year since; last year's edition, which paid out $1,024,750 for 73 confirmed zero-days, was won by a group called the Summoning Team.
This year's contest added two new categories, Wellness and AI Coding Agents, alongside returning categories for mobile phones, smart home devices, printers, messaging apps and AI infrastructure. In the rules it published ahead of the event, ZDI explained the new AI-focused category by pointing to how routinely developers now lean on AI coding tools:
"Let's face it. At some point or another, we've probably all vibe coded something. There's no shame in that, but how secure are the tools we use for vibe coding?"
That category was tested on day one, when Ikotas Labs — the same team that later won Master of Pwn — earned $40,000 for a single argument-injection bug in OpenAI's Codex coding agent. The Wellness category, ZDI's first venture into healthcare devices, saw Interrupt Labs claim the category's first full win against a Garmin Index BPM, an FDA-cleared smart blood-pressure monitor, on day one, worth $20,000.
Who is affected, and what comes next
Under ZDI's disclosure rules, every vendor whose product was successfully exploited receives full technical details immediately and typically has 90 days to ship a fix before the underlying bug is published. That list from this year's contest includes:
- Google (Pixel 10) and Samsung (Galaxy S26), in the mobile phones category
- Philips (Hue Bridge Pro), Home Assistant/Nabu Casa (Home Assistant Green) and Sonos (Era 300), in smart home
- Oracle (Autonomous AI Database) and the Chroma vector database project, in AI infrastructure
- OpenAI (Codex), in the new AI Coding Agents category
- Brother, Canon and Lexmark, across several printer models
- Garmin, in the new Wellness category
None of the affected companies had issued public statements about specific Pwn2Own findings as of Thursday afternoon; vendors typically stay quiet until patches are ready, consistent with the embargo built into ZDI's disclosure process. For users, the immediate practical effect is limited — Pwn2Own exploits are demonstrated under contest conditions designed by researchers, often requiring physical access, a malicious network, or the victim to open a crafted file, and are not released publicly until vendors have had the chance to patch them.
The bigger pattern organizers and researchers have pointed to is the growing share of entries aimed at AI software rather than traditional consumer hardware. Printers, phones and smart-home hubs have been Pwn2Own staples for years, but this year's contest devoted entire categories to an AI coding assistant and to the infrastructure — vector databases and AI-connected enterprise systems — that increasingly sits behind both consumer apps and corporate deployments of generative AI.
With day three's final attempts, including a last scheduled run from a team called Team MAMMOTH, still being tallied as this article was prepared, ZDI said final confirmed totals and a full list of Master of Pwn points would follow once every scheduled attempt had concluded. The disclosed bugs will not become public until the affected vendors patch them or the standard disclosure window lapses, whichever comes first.
Zero Day Initiative — Pwn2Own Ireland 2026: Day Three Results & Master of Pwn
Zero Day Initiative — Pwn2Own Ireland 2026: Day One Results
BleepingComputer — Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
Security Affairs — Summoning Team won Master of Pwn as Pwn2Own Ireland rewards $1,024,750
TSMC's September Sales Show AI Chip Demand Still Outrunning Supply

Microsoft and Nvidia open sales on first "agent-ready" Windows PCs, starting at $2,599

Anthropic Widens Access to AI Hacking Tools, Citing 129,000 Vulnerabilities Found
