Pwn2Own Ireland 2026 has concluded with impressive results, as exploits targeting the Google Pixel 10 brought researchers a total of $560,000 in prizes. The competition, organized by Trend Micro ’s Zero Day Initiative (ZDI) , is one of the most important events in the cybersecurity space, as it highlights unknown vulnerabilities in commercial devices before they are exploited by malicious actors. According to SecurityWeek, the total amount distributed in the competition amounted to $1,262,000 for 98 zero-day vulnerabilities across all categories.

Pwn2Own is a controlled vulnerability disclosure competition in which researchers attack designated products using only previously unknown vulnerabilities — so-called zero -days . Judges verify each exploit and its impact, and successful demonstrations are reported to manufacturers, who have 90 days to develop patches before ZDI proceeds with a public disclosure. This model of coordinated disclosure is at the core of the competition’s value to the entire security ecosystem.
See also: Google Pixel: Hackers exploit critical vulnerability in cellular modem
This year’s competition in Ireland included categories such as mobile phones, AI infrastructure, AI coding applications, messaging platforms, smart home devices, printers and health devices. In the mobile category, targets included the Google Pixel 10, Samsung Galaxy S26 and Apple iPhone 17, with a maximum prize of $300,000 for remote hacking. Notably, no contestants attempted to target the iPhone 17 or WhatsApp, despite the high prizes on offer.
Pwn2Own: Results for Google Pixel 10 and other devices
The Ikotas Labs team took home the top prize of $300,000 in the Pwn2Own competition, combining multiple vulnerabilities to remotely compromise a Google Pixel smartphone . Tim Becker and Yves Bieri won $150,000 for their own attack method, while Dimitrios Valsamaras and Ken Gannon received $112,500 for combining a zero-day vulnerability with a known security flaw.
See also: Pwn2Own Ireland 2025 – Day 2: 56 zero-day exploits & $792,750 in prizes
Significant cash prizes were also awarded for the breach of the Sonos Era 300 smart speaker, as well as vulnerabilities in products and services from Oracle, OpenAI, Nvidia, LiteLLM, and Philips Hue. Researchers also managed to identify ways to attack Samsung Galaxy S26 devices, Lexmark and Brother printers, as well as smart home systems and medical devices.

Pwn2Own once again demonstrates the importance of coordinated vulnerability disclosure: exploit details are provided to manufacturers before public release, giving Google and other companies the opportunity to patch their devices before the technical details become widely available .
See also: Pwn2Own Ireland 2025 – Day 1: 34 zero-day exploits and $522,500 in prizes
This model of responsible disclosure is a key element of modern cybersecurity and serves as a reminder that even the most secure devices can present vulnerabilities that require constant vigilance.
