US Edition
Your source for latest news
TechnologyCybersecurity

Hackers Win $300,000 Pixel 10 Jackpot to Close Out Pwn2Own Ireland 2026

A team called Ikotas Labs claimed the contest's richest single prize and the Master of Pwn title on the third and final day of Pwn2Own Ireland, capping three days in which hundreds of thousands of dollars changed hands for undisclosed flaws in phones, smart-home hubs, an AI database and an OpenAI coding tool.

PT
By PressTemps Technology DeskPublished Today, 13:30 ET · 5 min read
Hackers Win $300,000 Pixel 10 Jackpot to Close Out Pwn2Own Ireland 2026
Illustrative photo of code on a laptop screen; it does not depict the Pwn2Own Ireland 2026 contest. Photo by markus119 via Flickr/Openverse, licensed CC BY 2.0.
What to know
Ikotas Labs won $300,000 and the Master of Pwn title for exploiting a Google Pixel 10 on the third and final day of Pwn2Own Ireland 2026 in Cork.
The contest, run by Trend Micro's Zero Day Initiative, saw roughly $388,500 paid out for 32 zero-days on day one alone, with more than $500,000 more confirmed on day three.
Exploited products included Samsung's Galaxy S26, Oracle's Autonomous AI Database, Philips' Hue Bridge Pro, Sonos's Era 300, a Home Assistant hub and OpenAI's Codex coding agent.
Affected vendors receive full technical details immediately and typically have 90 days to patch before ZDI publicly discloses the underlying bugs.

A three-day hacking contest in Cork, Ireland, closed out its main competition on Thursday with a researcher team called Ikotas Labs walking away with $300,000 for a single working exploit chain against a Google Pixel 10 — the richest single payday of the week and enough to crown the team Master of Pwn at Pwn2Own Ireland 2026. By Thursday afternoon, organizers had confirmed more than $500,000 in fresh awards on the contest's third day alone, on top of hundreds of thousands already paid out over the two days before it, for vulnerabilities in products from Samsung, Oracle, Philips, Home Assistant, Sonos, Brother, Canon, Lexmark and OpenAI.

Pwn2Own is run by Trend Micro's Zero Day Initiative (ZDI), which pays independent security researchers to find and privately disclose software flaws so vendors can patch them before criminals do. This year's Ireland edition, the contest's third in Cork, ran October 6 through 9 and is the last scheduled general-purpose Pwn2Own of the year, following smaller automotive- and enterprise-focused editions held earlier in 2026.

The numbers

On day one, teams including Interrupt Labs, Ikotas Labs and Viettel Cyber Security took turns breaking into a Samsung Galaxy S26, and BleepingComputer reported that the day's work produced 32 exploited zero-days worth roughly $388,500. ZDI's own recap of day one also credited a Vietnamese team called VinSOC with $40,000 for chaining seven separate zero-days into a single working attack on a Philips Hue Bridge Pro, and another $40,000 for breaking into Oracle's Autonomous AI Database.

Day two brought more of the same across a wider spread of targets. According to ZDI's day two results post, researchers collected payouts for exploits against the Galaxy S26 again, a Home Assistant Green smart-home hub (five separate teams), a Sonos Era 300 speaker, Oracle's AI database a second time, and a product called Chroma, an open-source vector database widely used to store data for AI applications.

Day three, the contest's finale, had roughly $1.33 million in potential prize money riding on 17 scheduled attempts, organizers wrote in Thursday's live results post. The marquee target was the Google Pixel 10, drawing three separate attempts through the day. A team called Xint claimed an early $150,000 for a working exploit chain, only to be overtaken hours later when Ikotas Labs chained several bugs together for the $300,000 top prize, instantly making it the event's points leader. Elsewhere on the day, a two-person team from FuzzingLabs earned $20,000 for a zero-day in a Brother office printer, and a group called Team DDOS collected $4,500 for a five-bug chain, including one zero-day, against Home Assistant Green.

How we got here

Pwn2Own began in 2007 at the CanSecWest security conference in Vancouver, where researchers won laptops by breaking into them through browser exploits, and has grown into a recurring series spanning categories from industrial control systems to cars. ZDI brought the contest to Cork for the first time in 2024 and has returned every year since; last year's edition, which paid out $1,024,750 for 73 confirmed zero-days, was won by a group called the Summoning Team.

This year's contest added two new categories, Wellness and AI Coding Agents, alongside returning categories for mobile phones, smart home devices, printers, messaging apps and AI infrastructure. In the rules it published ahead of the event, ZDI explained the new AI-focused category by pointing to how routinely developers now lean on AI coding tools:

"Let's face it. At some point or another, we've probably all vibe coded something. There's no shame in that, but how secure are the tools we use for vibe coding?"

That category was tested on day one, when Ikotas Labs — the same team that later won Master of Pwn — earned $40,000 for a single argument-injection bug in OpenAI's Codex coding agent. The Wellness category, ZDI's first venture into healthcare devices, saw Interrupt Labs claim the category's first full win against a Garmin Index BPM, an FDA-cleared smart blood-pressure monitor, on day one, worth $20,000.

Who is affected, and what comes next

Under ZDI's disclosure rules, every vendor whose product was successfully exploited receives full technical details immediately and typically has 90 days to ship a fix before the underlying bug is published. That list from this year's contest includes:

  • Google (Pixel 10) and Samsung (Galaxy S26), in the mobile phones category
  • Philips (Hue Bridge Pro), Home Assistant/Nabu Casa (Home Assistant Green) and Sonos (Era 300), in smart home
  • Oracle (Autonomous AI Database) and the Chroma vector database project, in AI infrastructure
  • OpenAI (Codex), in the new AI Coding Agents category
  • Brother, Canon and Lexmark, across several printer models
  • Garmin, in the new Wellness category

None of the affected companies had issued public statements about specific Pwn2Own findings as of Thursday afternoon; vendors typically stay quiet until patches are ready, consistent with the embargo built into ZDI's disclosure process. For users, the immediate practical effect is limited — Pwn2Own exploits are demonstrated under contest conditions designed by researchers, often requiring physical access, a malicious network, or the victim to open a crafted file, and are not released publicly until vendors have had the chance to patch them.

The bigger pattern organizers and researchers have pointed to is the growing share of entries aimed at AI software rather than traditional consumer hardware. Printers, phones and smart-home hubs have been Pwn2Own staples for years, but this year's contest devoted entire categories to an AI coding assistant and to the infrastructure — vector databases and AI-connected enterprise systems — that increasingly sits behind both consumer apps and corporate deployments of generative AI.

With day three's final attempts, including a last scheduled run from a team called Team MAMMOTH, still being tallied as this article was prepared, ZDI said final confirmed totals and a full list of Master of Pwn points would follow once every scheduled attempt had concluded. The disclosed bugs will not become public until the affected vendors patch them or the standard disclosure window lapses, whichever comes first.

More on this story

All Technology