# Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland

> Source: <https://www.bleepingcomputer.com/news/security/hackers-earn-1262000-for-98-zero-days-at-pwn2own-ireland/>
> Published: 2026-10-09 16:03:24+00:00

The Pwn2Own Ireland 2026 hacking contest has concluded, with hackers collecting $1,262,000 in rewards after exploiting 98 zero-day flaws.

Ikotas Labs security researchers won this year's Pwn2Own Ireland edition with 42.5 Master of Pwn points and $361,000 earned over the three-day contest after hacking the Samsung Galaxy S26, OpenAI Codex, and the Oracle Autonomous AI Database.

They also collected the competition's top reward of $300,000 on the third day after [chaining multiple zero-days](https://bsky.app/profile/thezdi.bsky.social/post/3mlvhf6iock2z) to hack the Google Pixel 10.

Xint took second place with $240,000 and 27.5 Master of Pwn points, while Team ZyGoat secured third with $125,000 in prizes and 27.5 Master of Pwn points.

Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security hacked Samsung's Galaxy S26 flagship [on the first day](https://www.bleepingcomputer.com/news/security/windows-11-and-microsoft-edge-hacked-on-first-day-of-pwn2own-berlin-2026/), but the vendor [already knew](http://bsky.app/profile/thezdi.bsky.social/post/3mx7mvxinoc2d) some of [the exploited bugs](https://bsky.app/profile/thezdi.bsky.social/post/3mx7fa7pk2c2h). In all, competitors collected $388,500 after demonstrating 32 zero-day flaws.

[On the second day](https://www.bleepingcomputer.com/news/security/samsung-galaxy-s26-hacked-three-more-times-at-pwn2own-ireland/), competitors earned $232,500 in cash awards for 45 unique zero-day vulnerabilities, with the highlight being PetoWorks, KAIST Hacking Lab's Kyeongmin Kim, and a team including Dimitrios Valsamaras, Ken Gannon, and Tenia Valsamara from CENSUS Labs, who took down the Galaxy S26 three more times.

[On the third day](https://www.zerodayinitiative.com/blog/2026/10/8/pwn2own-ireland-2026-day-three-results-amp-master-of-pwn), hackers rooted the Samsung Galaxy S26 again and took down the Google Pixel 10 three times. In total, today security researchers exploited 21 zero-days for $641,000 in cash on the final day of the contest.

This year, 29 research teams [targeted products across seven categories](https://www.zerodayinitiative.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories): mobile phones (Samsung Galaxy S26 and Google Pixel 10), AI infrastructure, AI coding apps, messaging apps, smart home devices, printers, and a new category focused on wellness healthcare devices.

Apple's iPhone 17 was also a potential target, with a maximum award of $300,000 for a remote hack, but no contestant registered for an attempt.

Trend Micro's Zero Day Initiative (ZDI) organizes the competition to identify zero-day flaws before attackers exploit them in the wild. [Pwn2Own rules require](https://www.zerodayinitiative.com/Pwn2OwnIreland2026Rules.html) all devices and products to run the latest firmware versions, and contestants to compromise the target and demonstrate arbitrary code execution.

Vendors must patch zero-days disclosed during the Pwn2Own competition within 90 days before ZDI publicly shares details.

During Pwn2Own Ireland 2025, hackers demoed 73 zero-day flaws to [earn $1,024,750](https://www.bleepingcomputer.com/news/security/hackers-earn-1-024-750-for-73-zero-days-at-pwn2own-ireland/). Summoning Team won the contest and collected $187,500 after hacking the Samsung Galaxy S25, the Home Assistant Green, the QNAP TS-453E NAS, and multiple Synology devices.

## 
[Build your security blueprint for AI-powered attacks](https://hubs.li/Q04x67m50)

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

[Save your seat](https://hubs.li/Q04x67m50)
