
In 2018, the Chinese government banned Chinese security researchers from participating in hacking in foreign countries in an effort to keep vulnerability-finding knowledge within the country’s borders. The decision had an impact on popular hacking competitions like Pwn2Own, where Chinese participants were among the top competitors.
However, as compensation for this ban, the Chinese government organized the TianfuCup, a hacking competition, for Chinese security.
Since the very first day of the TianfuCup competition, Chinese security researchers have successfully discovered zero-day vulnerabilities in Microsoft Edge, Google Chrome, Safari, Office365, D-Link DIR-878 router, Adobe PDF Reader, and quemu-kvm + Ubuntu.
The 360Vulcan team, which in 2016 managed to win Pwn2Own after hacking Google Chrome in 11 minutes, is so far the champion in TianfuCup 2019.
On the second day of the competition, hackers discovered vulnerabilities in the D-Link DIR-878 router, Adobe PDF Reader, and VMWare Workstation. The 360Vulcan team was expected to be able to hack iOS, but they abandoned the attempt before that could happen.
However, 360Vulcan won the $382,500 cash prize for hacking Microsoft Office 365, VMWare Workstation, Microsoft Edge, qemu + Ubuntu, and Adobe PDF Reader.
Most of the money earned by the 360Vulcan team came from the discovery of vulnerabilities in VMWare and qemu + Ubuntu which were valued at $200,000 and $80,000 respectively.
Many companies, including Google, sent representatives to the contest to collect reports of vulnerabilities so they could issue a patch as soon as possible.
