Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Pwn2Own Ireland 2026 wrapped on October 9, 2026 in Cork with $1.262 million awarded to 29 teams for 98 zero-day vulnerabilities demonstrated against targets the organizers certified as fully patched. The total tops the 2025 edition's $1,024,750, but the figure that distorts the narrative is the collision rate: at least two of the three successful exploits against the Google Pixel 10 were classified as collisions—bugs already known to the vendor or organizer but still present in shipping firmware.
- Ikotas Labs won the Master of Pwn title with $361,000, 42.5 points, and 13 unique bugs demonstrated during the competition.
- Researchers completed 61 of 63 scheduled exploit attempts, demonstrating 98 zero-day vulnerabilities in total.
- The Google Pixel 10 was compromised three times on the final day for a combined $562,500, but at least two exploits were classified as collisions.
- The Samsung Galaxy S26 was compromised in all seven attempts, with six victories including at least one collision.
Final Standings and Ikotas Labs' Dominance
CyberInsider published the definitive leaderboard confirming the aggregate numbers: 61 completed attempts, 29 participating teams, $1.262 million awarded. Ikotas Labs dominated with a clear margin, accumulating $361,000 and 42.5 points from 13 unique bugs. The runner-up remained distant, though sources do not specify the exact gap.
Ikotas Labs' victory was fueled in part by the maximum single-exploit payout on the Pixel 10: $300,000. However, the same source certifying the win—The Hacker News—documents that this exploit fell into the collision category. Chinese team Xint earned $150,000 for another collision on the same device, half the original listing. A third group, led by Dimitrios Valsamaras and collaborators, collected $112,500. The sum of the three payouts—$562,500—represents nearly half the competition's total purse.
The Collision Mechanic: Reduced Payouts, Real Impact
Pwn2Own rules stipulate that an exploit against a "fully patched" target earns the full reward only if the vulnerability is entirely new to both vendor and organizer. If the bug is already known—a collision—the reward is reduced, typically by half. The issue is not the rule, which organizers apply consistently, but the rule's very existence: a device delivered as fully updated contained flaws already cataloged but not remediated.
The starkest case involves the Samsung Galaxy S26. According to The Hacker News, the phone was exploited in all seven scheduled attempts. Six of those seven victories included at least one collision. The source does not specify whether the collisions were identical across teams or distinct bugs sharing the same classification, but the quantitative data paints a clear picture: Samsung's patch delivery chain, at least for this competition, left multiple known vectors exposed.
Target Categories and the Expanding Attack Surface
CyberInsider lists the categories featured in the 2026 edition: smartphones, messaging apps, smart home devices, printers, wellness devices, AI infrastructure, and coding agents. The inclusion of codex and autonomous databases signals a direction the industry is already pursuing: AI system security is no longer an appendix to research but a dedicated front with specific bounties and dedicated teams.
The Hacker News notes that similar trends emerged in the 2025 edition, but the 2026 expansion is quantifiable in the numbers. Total prize money grew 23% year over year. This is not conference inflation; it reflects greater sponsor availability—vendors themselves, putting their own devices up as targets—and the greater complexity of exploits required to compromise systems that are increasingly hardened, at least on paper.
"Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched." — The Hacker News
The 90-Day Embargo and the Current Information Vacuum
Coordinated disclosure is a pillar of the Pwn2Own model. Vendors and organizers agree that technical details remain under embargo for 90 days, during which manufacturers must release patches. At the end of that period, the Zero Day Initiative publishes full advisories. At time of writing, ZDI has not yet released the technical sheets for the 98 vulnerabilities. Sources concur: no evidence has emerged of in-the-wild exploitation of the flaws demonstrated in Cork.
This information vacuum is structural, not accidental. Organizers impose it to give vendors maneuvering room, but it has a significant side effect for users and system administrators: they cannot assess the real risk to their devices, nor apply specific countermeasures beyond generic updates. The competition demonstrates that those updates, moreover, are not enough.
Why It Matters
The dossier does not specify which teams attempted and failed, nor does it provide a complete map of the attack vectors used against the Pixel 10 and Galaxy S26—NFC, Wi-Fi, Bluetooth, baseband, or browser remain hypothetical routes. It is unknown whether vendors have already begun releasing corrective patches, nor is the reason documented for why Ikotas Labs received the full payout despite the collision: the source notes the fact but does not explain the technical or regulatory justification.
Sources also do not list the attempts that came up empty: iPhone 17 and WhatsApp carried $300,000 bounties, but no team showed up. That silence is data in itself: it may indicate greater target complexity, poor economic return relative to preparation time, or both.
What the dossier documents is sufficient to sketch a troubling picture. Mobile devices from two of the world's largest manufacturers—Google and Samsung—proved compromisable under controlled conditions with bugs that were, at least in part, already known. The Pwn2Own system functions as a controlled market for research, but the frequency of collisions suggests the remediation market functions less well. End users cannot act directly, but monitoring updates over the next 90 days is the only available indicator to verify whether vendors will close the gaps exposed in Cork.
Frequently Asked Questions
What does "collision" mean in the Pwn2Own context?
A collision occurs when the exploited bug is already known to the vendor or organizers at the time of demonstration. The reward is reduced, but the exploit is still valid and the device is compromised.
Why did Ikotas Labs receive $300,000 for an exploit classified as a collision?
The dossier does not clarify this point. Standard rules call for reduced payouts on collisions, but undocumented exceptions may exist.
When will technical details of the vulnerabilities be published?
Vendors have 90 days to release patches before ZDI publishes full details. At time of writing, the embargo is still in effect.
Sources
- https://thehackernews.com/2026/10/three-teams-demonstrate-remote-hacks-of.html
- https://www.infosecurity-magazine.com/news/pwn2own-hackers-32-zeroday/
- https://radar.offseq.com/threat/hackers-get-1262000-for-98-zero-days-at-pwn2own-ireland-4424813c4215e86f
- https://cyberinsider.com/google-pixel-10-hacked-as-pwn2own-ireland-wraps-with-1-26-million-in-rewards/
- https://thehackernews.com/
- https://thehackernews.com/p/upcoming-hacker-news-webinars.html
- https://thehackernews.com/search/label/Threat%20Intelligence
- https://thehackernews.com/search/label/Vulnerability
- https://thehackernews.com/search/label/Cyber%20Attack
Information verified against cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.