Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland Security researchers collected $1,262,000 for exploiting 98 zero-day flaws at Pwn2Own Ireland 2026, organized by Trend Micro's Zero Day Initiative (ZDI). Ikotas Labs won the contest with 42.5 Master of Pwn points and $361,000 after hacking the Samsung Galaxy S26, OpenAI Codex, and the Oracle Autonomous AI Database, including a $300,000 top reward for chaining multiple zero-days against the Google Pixel 10. Xint placed second with $240,000 and Team ZyGoat third with $125,000, while Apple's iPhone 17 drew no registered attempts despite a $300,000 maximum award. The Pwn2Own Ireland 2026 hacking contest has concluded, with hackers collecting $1,262,000 in rewards after exploiting 98 zero-day flaws. Ikotas Labs security researchers won this year's Pwn2Own Ireland edition with 42.5 Master of Pwn points and $361,000 earned over the three-day contest after hacking the Samsung Galaxy S26, OpenAI Codex, and the Oracle Autonomous AI Database. They also collected the competition's top reward of $300,000 on the third day after chaining multiple zero-days https://bsky.app/profile/thezdi.bsky.social/post/3mlvhf6iock2z to hack the Google Pixel 10. Xint took second place with $240,000 and 27.5 Master of Pwn points, while Team ZyGoat secured third with $125,000 in prizes and 27.5 Master of Pwn points. Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security hacked Samsung's Galaxy S26 flagship on the first day https://www.bleepingcomputer.com/news/security/windows-11-and-microsoft-edge-hacked-on-first-day-of-pwn2own-berlin-2026/ , but the vendor already knew http://bsky.app/profile/thezdi.bsky.social/post/3mx7mvxinoc2d some of the exploited bugs https://bsky.app/profile/thezdi.bsky.social/post/3mx7fa7pk2c2h . In all, competitors collected $388,500 after demonstrating 32 zero-day flaws. On the second day https://www.bleepingcomputer.com/news/security/samsung-galaxy-s26-hacked-three-more-times-at-pwn2own-ireland/ , competitors earned $232,500 in cash awards for 45 unique zero-day vulnerabilities, with the highlight being PetoWorks, KAIST Hacking Lab's Kyeongmin Kim, and a team including Dimitrios Valsamaras, Ken Gannon, and Tenia Valsamara from CENSUS Labs, who took down the Galaxy S26 three more times. On the third day https://www.zerodayinitiative.com/blog/2026/10/8/pwn2own-ireland-2026-day-three-results-amp-master-of-pwn , hackers rooted the Samsung Galaxy S26 again and took down the Google Pixel 10 three times. In total, today security researchers exploited 21 zero-days for $641,000 in cash on the final day of the contest. This year, 29 research teams targeted products across seven categories https://www.zerodayinitiative.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories : mobile phones Samsung Galaxy S26 and Google Pixel 10 , AI infrastructure, AI coding apps, messaging apps, smart home devices, printers, and a new category focused on wellness healthcare devices. Apple's iPhone 17 was also a potential target, with a maximum award of $300,000 for a remote hack, but no contestant registered for an attempt. Trend Micro's Zero Day Initiative ZDI organizes the competition to identify zero-day flaws before attackers exploit them in the wild. Pwn2Own rules require https://www.zerodayinitiative.com/Pwn2OwnIreland2026Rules.html all devices and products to run the latest firmware versions, and contestants to compromise the target and demonstrate arbitrary code execution. Vendors must patch zero-days disclosed during the Pwn2Own competition within 90 days before ZDI publicly shares details. During Pwn2Own Ireland 2025, hackers demoed 73 zero-day flaws to earn $1,024,750 https://www.bleepingcomputer.com/news/security/hackers-earn-1-024-750-for-73-zero-days-at-pwn2own-ireland/ . Summoning Team won the contest and collected $187,500 after hacking the Samsung Galaxy S25, the Home Assistant Green, the QNAP TS-453E NAS, and multiple Synology devices. Build your security blueprint for AI-powered attacks https://hubs.li/Q04x67m50 Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat https://hubs.li/Q04x67m50