The world's most famous hacking competition, Pwn2Own Ireland (2025), has concluded with spectacular results. The world's top security researchers revealed 73 zero-day vulnerabilities and shared $1,024,750 in prize money. White hat hackers compromised everything from smartphones and NAS devices to smart glasses and routers.

Target categories and new challenges
Pwn2Own Ireland 2025, which took place from October 21 to 23 in Cork, featured eight main categories: printers, NAS systems, messaging apps, smart home devices, surveillance cameras, home routers, flagship smartphones and wearable technology.
See also: Multiple flaws in Oracle VM VirtualBox
This year's edition brought a new level of difficulty, as researchers were asked to compromise devices via USB ports - that is, through a physical connection, even on locked phones. At the same time, familiar protocols such as Bluetooth , Wi-Fi and NFC remained in the "game" , opening up new avenues for attacks reminiscent of a spy movie scenario.
The organization and the big winners
The competition was co-organized by Meta, QNAP , and Synology, with the goal of identifying new vulnerabilities before they fall into malicious hands. Among dozens of teams, Summoning Team emerged as the absolute champion, collecting 22 Master of Pwn points and a cash prize of $187,500.
The team managed to hack an impressive array of devices, including the Samsung Galaxy S25, Synology DiskStation DS925+ and QNAP TS-453E, and Home Assistant Green. This feat demonstrated the increasing complexity of IoT devices and the need for enhanced security practices.

In second place came the ANHTUD team with $76,750 and 11.5 points , while Synactiv came in third with $90,000 and 11 Master of Pwn points .
See also: Vulnerability in Lanscope Endpoint Manager allows cyberattacks
Zero-days record and the highlight of the event
The first day of the competition was a whirlwind: 34 zero-days were discovered and exploited, earning participants $522,500. The second day was followed by another 22 vulnerabilities for an additional $267,500.
The highlight, however, came on the third and final day, when the Interrupt Labs team breached a Samsung Galaxy S25 via an “improper input validation bug .” This exploit earned the team $50,000 and 5 Master of Pwn points .
The WhatsApp exploit that was not shown
Of particular interest was the departure of the Z3 team , which had planned to demonstrate a zero-click exploit in WhatsApp — a vulnerability that could have yielded up to $1 million . The researchers, however, chose to privately disclose their findings to the Zero Day Initiative (ZDI) and Meta , demonstrating that responsible disclosure remains the ethical choice in an ecosystem where information equals power.

The role of ZDI and the day after tomorrow
ZDI – which is owned by Trend Micro – continues to play a critical role in mapping and responsibly disclosing zero-day vulnerabilities. After each Pwn2Own, vendors have 90 days to fix vulnerabilities before they are made public.
See also: TARmageddon vulnerability in Rust's Async-Tar library allows remote code execution
The next big event is already set: Pwn2Own Automotive 2026, which will take place in January in Tokyo as part of the Automotive World – again sponsored by Tesla. Researchers will be invited to test the security of “smart” vehicles, confirming that the battle for cybersecurity never ends.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
With Pwn2Own uncovering dozens of zero-days every year, the event acts as a global crash test for technology. The faster vulnerabilities are identified, the more secure our digital future becomes.
Source: www.bleepingcomputer.com
