The Pwn2Own Ireland 2026 hacking competition concluded with security researchers earning a total of $1,262,000 for demonstrating 98 unique zero-day vulnerabilities across various products. The three-day event, organized by Trend Micro's Zero Day Initiative (ZDI), saw 29 research teams targeting devices in seven categories, including mobile phones, AI infrastructure, and smart home devices.
Ikotas Labs emerged as the top contender, securing 42.5 Master of Pwn points and $361,000 in prize money. Their successful exploits included the Samsung Galaxy S26, OpenAI Codex, and the Oracle Autonomous AI Database. On the final day of the competition, Ikotas Labs also claimed the highest single reward of $300,000 by chaining multiple zero-days to compromise the Google Pixel 10.
Xint placed second with $240,000 and 27.5 Master of Pwn points, while Team ZyGoat took third, earning $125,000 and 27.5 Master of Pwn points.
The first day of the contest saw competitors disclose 32 zero-day flaws, resulting in $388,500 in rewards. Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security successfully exploited the Samsung Galaxy S26. However, Samsung had prior knowledge of some of the vulnerabilities used in these initial exploits.
On the second day, 45 unique zero-day vulnerabilities were demonstrated, with researchers collecting $232,500. Notably, PetoWorks, Kyeongmin Kim from KAIST Hacking Lab, and a team comprising Dimitrios Valsamaras, Ken Gannon, and Tenia Valsamara from CENSUS Labs, successfully compromised the Galaxy S26 an additional three times.
The final day of the event was the most lucrative, with 21 zero-days exploited for $641,000 in cash. This included further successful attacks on the Samsung Galaxy S26 and three instances of the Google Pixel 10 being rooted.
This year's competition featured target categories such as mobile phones (Samsung Galaxy S26 and Google Pixel 10), AI infrastructure, AI coding applications, messaging applications, smart home devices, printers, and a new category for wellness healthcare devices. Although Apple's iPhone 17 was a potential target with a $300,000 reward for a remote hack, no teams registered to attempt an exploit.
The Pwn2Own competition mandates that all targeted devices run the latest firmware versions and requires contestants to achieve arbitrary code execution. The disclosed zero-day vulnerabilities are reported to the respective vendors, who are then given 90 days to release patches before ZDI publicly releases the details.
The 2026 event surpassed the previous year's Pwn2Own Ireland, where hackers demonstrated 73 zero-day flaws and earned $1,024,750. In 2025, Summoning Team won the contest, collecting $187,500 for exploits against the Samsung Galaxy S25, Home Assistant Green, QNAP TS-453E NAS, and various Synology devices.






