Pwn2Own Ireland 2026 concluded with participants pocketing over $1.2 million for identifying vulnerabilities in various digital devices and platforms. The competition showcased exploits targeting smartphones, printers, smart speakers, smart home hubs, wellness devices, AI infrastructure, and cloud databases.
Google Pixel 10 Commands Top Payouts
The event’s top earnings came from exploits on the Google Pixel 10, with three teams collectively securing more than $560,000. The most significant reward, $300,000, was claimed by Ikotas Labs, who skillfully chained multiple bugs to remotely compromise a Pixel phone.
Meanwhile, Tim Becker and Yves Bieri received $150,000 for their Pixel exploit. Their payout was slightly reduced because it involved a flaw that was already known. Another notable hack was presented by Dimitrios Valsamaras and Ken Gannon, who earned $112,500 by combining a zero-day exploit with a previously identified vulnerability.
Award-Winning Exploits Beyond Smartphones
In addition to smartphone hacks, a significant prize of $50,000 was awarded for an innovative exploit targeting a Sonos Era 300 smart speaker. Numerous other exploits secured $40,000 each, focusing on systems like Oracle’s Autonomous AI Database, OpenAI Codex, Nvidia’s Dynamo AI framework, the LiteLLM AI gateway, and the Philips Hue Bridge Pro lighting hub.
Other participants earned around $30,000 for identifying vulnerabilities in the Samsung Galaxy S26 and the Home Assistant Green smart home hub. Additionally, exploits affecting Lexmark and Brother printers, as well as the Garmin Index BPM blood pressure monitor, brought in $20,000.
Smaller Rewards and Untargeted Devices
Various exploits, ranging from $4,250 to $17,500, were awarded for vulnerabilities in the Sonos Era, Galaxy S26, LiteLLM, Philips Hue Bridge Pro, Lexmark CX532adwe, Oracle’s Autonomous AI Database, Home Assistant Green, Chroma, Garmin Index BPM, and Canon imageFORCE 1643F. Vendors will receive detailed reports on all identified flaws.
Interestingly, despite high stakes, the iPhone 17 and WhatsApp remained untargeted, both offering a maximum prize of $300,000. This year’s Pwn2Own highlighted critical weaknesses and provided valuable insights for vendors to enhance their security frameworks.
