
Pwn2Own Ireland 2026 Results: 98 Zero-Days, AI Tools Tested
Pwn2Own Ireland 2026 paid researchers $1,262,000 for 98 zero-days in phones, smart home gear and AI tools, all reported to vendors under a 90-day deadline.
Pwn2Own Ireland 2026 wrapped on October 8, and the scoreboard is a good-news story for anyone who uses a phone, a smart speaker or an AI coding tool. Over three days, security researchers earned $1,262,000 for demonstrating 98 previously unknown vulnerabilities, and every one of them was handed to the vendor to fix before details go public.
- Total: $1,262,000 awarded for 98 zero-days across three days, per BleepingComputer.
- Winner: Ikotas Labs took Master of Pwn with 42.5 points and $361,000.
- AI targets: OpenAI Codex and Oracle Autonomous AI Database were among the products successfully tested.
- Disclosure: vendors get 90 days to patch before Trend Micro's Zero Day Initiative publishes details.
What Is Pwn2Own and Why Is It Good for Security?
Pwn2Own is a contest run by Trend Micro's Zero Day Initiative (ZDI). Researchers bring working exploits for fully updated products and demonstrate them live. If the exploit works, the researcher is paid, the vendor receives the full technical details on the spot, and a 90-day clock starts for a patch.
That structure is the point. A zero-day is a flaw the vendor does not yet know about. Each one found here is one that gets fixed through coordinated disclosure. Ninety-eight findings means ninety-eight fixes in the pipeline for products people use every day.
What Did Researchers Find at Pwn2Own Ireland 2026?
BleepingComputer's tally by day: 32 zero-days and $388,500 on day one, 45 and $232,500 on day two, and 21 and $641,000 on day three. Twenty-nine teams competed across seven categories: mobile phones, AI infrastructure, AI coding apps, messaging apps, smart home devices, printers, and a new category for wellness and healthcare devices.
Ikotas Labs won the overall title with 42.5 Master of Pwn points and $361,000 in awards. Its biggest single payout was $300,000 on day three for chaining multiple bugs into a remote attack on the Google Pixel 10. Xint finished second with $240,000 and Team ZyGoat third with $125,000.
SecurityWeek reports that Pixel 10 research alone earned more than $560,000 across three successful entries, and the Samsung Galaxy S26 was also tested successfully on all three days. No team attempted the iPhone 17, which carried a maximum award of $300,000.
The event keeps growing. Last year's edition produced 73 zero-days and $1,024,750 in awards, so 2026 added 25 findings and more than $237,000.
Why Do the AI Categories Matter?
The AI infrastructure and AI coding categories are what make this year's contest relevant to our beat. Ikotas Labs demonstrated working exploits against OpenAI Codex and Oracle Autonomous AI Database on its way to the title.
Here is why that is healthy. AI coding agents and model-serving systems now sit inside development pipelines with access to source code and credentials. They deserve the same adversarial testing browsers and phones have had for years. Putting them on the Pwn2Own stage means skilled researchers are paid to find the weak points first, and vendors get a private, detailed report.
It also complements vendor-run programs. Microsoft's Zero Day Quest awarded $2.3 million for cloud and AI bugs earlier this year, and independent contests add a second set of eyes.
What Should Users Do Now?
Nothing urgent. The technical details stay private during the 90-day window, which is how responsible disclosure is designed to work. The practical step is the usual one: keep automatic updates on for your phone, smart home devices, printers and developer tools, so the fixes from this contest reach you as soon as vendors ship them.
Pwn2Own turns vulnerability research into a public, well-paid sport with a constructive ending. More in our AI security coverage.
Sources: BleepingComputer — Hackers earn $1,262,000 for 98 zero-days at Pwn2Own Ireland — October 9, 2026; Zero Day Initiative — Pwn2Own Ireland 2026 day three results — October 8, 2026; SecurityWeek — Google Pixel 10 exploits earned hackers $560,000 at Pwn2Own — October 9, 2026.
More Ai Security Stories

Anthropic OSS Scanner: Free AI Bug Scans for Open Source
Anthropic's OSS Scanner gives open-source maintainers free AI vulnerability scans with fixes; 85 of 97 tested severe findings met its disclosure bar.

What Is Prompt Injection? A Plain-English Defense Guide
What is prompt injection? Learn direct vs indirect attacks, 9 real scenarios, and the 7 OWASP-backed defenses that keep AI assistants and agents safe.

GitHub AI Secret Detection: How Push Protection Gets Smarter
GitHub is adding a ModernBERT classifier to push protection that spots unstructured passwords in under 2 ms and could more than double blocked secrets.
