Pwn2Own Ireland wraps with $1.26M in payouts for 98 zero-day bugs

The Pwn2Own Ireland 2026 contest ended with researchers earning $1,262,000 for 98 zero-day vulnerabilities. Ikotas Labs took first place with $361,000 and 42.5 Master of Pwn points, including a $300,000 award for chaining bugs against the Google Pixel 10. Competitors targeted mobile phones, AI infrastructure and coding tools, messaging apps, smart home devices, printers, and wellness healthcare products, while no one entered an attempt against the iPhone 17.
Pwn2Own Ireland 2026 ran three days and awarded $1,262,000 for 98 zero-days. Ikotas Labs led with $361,000 and 42.5 Master of Pwn points, including $300,000 for a Google Pixel 10 exploit chain. Xint placed second; Team ZyGoat third. Targets spanned mobile phones, AI infrastructure and coding tools, messaging apps, smart home devices, printers, and wellness healthcare products. No one entered against Apple's iPhone 17, despite a potential $300,000 remote-hack prize.
Daily totals were $388,500 for 32 bugs, then $232,500 for 45, and $641,000 for 21. Samsung's Galaxy S26 was repeatedly compromised. ZDI requires current firmware and code-execution proof; vendors get 90 days to patch before public disclosure. In 2025, the event paid $1,024,750 for 73 zero-days.
The disclosed flaws could affect people who rely on smartphones, messaging apps, smart-home devices, printers, and health-related products, as well as organizations using AI infrastructure and coding tools. Vendors may face pressure to patch quickly within the 90-day window, while defenders could gain advance warning. If fixes lag, users might remain exposed to attacks that were demonstrated in a controlled contest.