Security researchers collected $792,750 in cashafter exploiting 56 unique zero-day vulnerabilities during the second day of the Pwn2Own Ireland 2025.

Pwn2Own Ireland 2025 – Day 2
The most significant moment was the targeted breach of the Samsung Galaxy S25 by Ken Gannon (Mobile Hacking Lab) and Dimitrios Valsamaras (Summoning Team) — a chain of five exploits that earned the researchers $50,000 and five points on the “Master of Pwn” list.
At the same time, groups such as PHP Hooligans, CyCraft Technology, Verichains Cyber Force and Synacktiv Team managed to "hit" NAS, printers and smart home devices and received significant amounts ($20,000 or more) for each successful attack with a single vulnerability.
See also: TARmageddon vulnerability in Rust's Async-Tar library allows remote code execution
Specifically, it took PHP Hooligans only a second to hack the QNAP TS-453E NAS device . The vulnerability they exploited had already been used in the competition.
Chumy Tsai of CyCraft Technology, Le Trong Phuc and Cao Ngoc Quy of Verichains Cyber Force, and Mehdi & Matthieu of Synacktiv Team also received $20,000 for breaching the QNAP TS-453E, Synology DS925+, and Phillips Hue Bridge.
Competitors also exploited zero-day flaws in the Canon imageCLASS MF654Cdw printer , Home Automation Green , Synology CC400W camera , Synology DS925+ NAS , Amazon Smart plug , and Lexmark CX532adwe printer .

Summoning Team still sits atop the “Master of Pwn” leaderboard with 18 points, having earned $167,500 over the first two days of the event.
As the first day of the competition had already set a record with 34 unique zero-days and $522,500 in prizes, it is clear that the level of research and exposure of systems has reached new heights.
See also: Hackers targeted over 250 Magento stores via Adobe Commerce vulnerability
Strategy and innovation — what's changing in the competition
This year, the competition is not limited to hacks that are done “over the Internet.” The organizers have expanded the “attack vectors” – now including physical connection via USB port for mobile phones : that is, a hacker must physically connect the phone and hack it.
At the same time, traditional protocols such as Wi-Fi, Bluetooth and NFC are still valid avenues of attack, which shows how the balance between “traditional” and “natural” attack vectors is changing.
In total, this year's competition program includes eight target categories: smartphones (e.g. Galaxy S25, Apple iPhone 16, Google Pixel 9), printers, storage systems (NAS), smart home devices, messaging applications, monitoring equipment, wearables and SOHO (smaller office/home office) equipment.
The event is being held in collaboration with Meta Platforms, Synology, and QNAP Systems, highlighting the importance they place on revealing vulnerabilities before the widespread release of products.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Why it matters for businesses and consumers
The intensity and scope of vulnerabilities identified in this year's competition sends two clear messages: first, modern devices – from smartphones to NAS – are not secure simply because they have advanced features; second, would-be attackers now have access to chronic flaws that they find a way to combine into complex exploit chains.

Companies whose products are affected by the vulnerabilities have 90 days to patch the flaws. After that period, the Zero Day Initiative (ZDI) will make the technical details public, increasing the chances of exploitation.
See also: LANSCOPE Endpoint Manager vulnerability allows remote code execution
For the end user, it’s a reminder that security isn’t limited to smartphones: NAS equipment, smart home devices, and even printers are targets. Keeping software up to date, using secure configurations, and constantly monitoring manufacturer support are becoming more critical than ever.
What to expect on day three – and why it’s worth watching
As we enter the third round of Pwn2Own Ireland, it’s clear that the stakes are rising. The Galaxy S25 is once again in the spotlight, as well as multiple NAS devices and printers. Most importantly, the Z3 team will be testing a zero-click exploit for WhatsApp — worth $1 million (if successful).
For those involved in cybersecurity, this day could reveal new exploit chains that will determine the future direction of attacks. For device and software manufacturers, it is a test of whether they can withstand the pressure of white-hat hackers and protect their users before global publicity carries the problem.
In other words, Pwn2Own Ireland 2025 is not just a competition – cybersecurity is coming to the fore for everyone: companies, researchers and end users. And this year it clearly showed that defenses need to evolve as fast as attacks.
Source: www.bleepingcomputer.com
