The news
Security researchers collected $1,262,000 for demonstrating 98 zero-day vulnerabilities at Pwn2Own Ireland 2026, the hacking contest run by Trend Micro's Zero Day Initiative (ZDI), Bleeping Computer reported. The three-day event opened on October 6 and targeted phones, printers, smart home devices and AI platforms.
A zero-day is a flaw the vendor does not yet know about, so no patch exists when it is found. Pwn2Own pays researchers to show working attacks against current products on stage, then hands the bugs to the affected companies. Under the contest rules, vendors get 90 days to release security updates before ZDI publishes the details, according to Bleeping Computer.
The top performer was Ikotas Labs, which earned $361,000 and 42.5 Master of Pwn points. That total included the event's $300,000 top prize for chaining multiple zero-days to hack the Google Pixel 10, Bleeping Computer reported. Xint finished second with $240,000 and 27.5 points, and Team ZyGoat took third with $125,000, also on 27.5 points.
Payouts varied sharply by day. Researchers exploited 32 zero-days for $388,500 on day one, 45 zero-days for $232,500 on day two, and 21 zero-days for $641,000 on day three, when the Pixel 10 was hacked three times. Samsung's Galaxy S26 was hacked multiple times across all three days.
Day-one targets alone spanned the Philips Hue Bridge Pro smart lighting hub, Oracle Autonomous AI Database, the LiteLLM AI gateway, Lexmark and Canon printers, the Sonos Era 300 speaker and the OpenAI Codex cloud coding agent, according to Bleeping Computer. The team VinSOC earned $40,000 for a seven-zero-day chain against the Philips hub and another $40,000 for a five-zero-day chain against Oracle's database.
One flagship target went untested. Apple's iPhone 17, which carried a maximum $300,000 award, drew no contestant registrations, Bleeping Computer reported.
The numbers
- Total paid
- $1,262,000
- Zero-days demonstrated
- 98
- Top prize (Pixel 10 chain)
- $300,000
- Ikotas Labs winnings
- $361,000
- Vendor patch window
- 90 days
- Pwn2Own Ireland 2025
- $1,024,750 for 73 zero-days
Why CEOs should care
For technology buyers, the lesson is not that one phone or printer is weak. It is that almost every category on the target list fell, from flagship handsets to office printers to AI coding tools. Procurement teams should ask vendors how quickly they shipped fixes after past Pwn2Own events and whether they commit to patch timelines in contracts. A vendor that cannot answer has told you something.
For CISOs, the 90-day disclosure clock is a planning tool. Fixes for these 98 flaws should arrive over the coming three months, and details become public after that, which is when copycat attacks tend to follow. Track the affected product lines in your fleet now, from Samsung and Google phones to Lexmark and Canon printers, so updates can be pushed quickly. Printers and smart home gear in offices are often the last devices to be patched.
Boards and CFOs should note where the money went. AI platforms such as OpenAI Codex, LiteLLM and Oracle's AI database were on the target list, which means the tools companies are rushing to adopt are already being probed by skilled researchers. Ask whether AI tools in use have gone through the same security review as other software, and who owns patching them.
The bigger picture
The payout grew from last year. Pwn2Own Ireland 2025 paid $1,024,750 for 73 zero-days, according to Bleeping Computer, compared with $1,262,000 for 98 this year. Contests like this give vendors bugs before criminals find them, but the rising count also shows how many exploitable flaws sit in mainstream consumer and office products at any moment.
What’s next
Affected vendors, including Google, Samsung and the printer and smart home makers, have 90 days to release patches before ZDI publishes technical details. Security teams should watch vendor bulletins over that window and apply fixes as they land.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error









