Cork, Ireland just hosted the most lucrative ethical-hacking showdown of the year β€” and the final scoreboard is staggering. Pwn2Own Ireland 2026, organized by Trend Micro's Zero Day Initiative, wrapped up on October 9, 2026 after researchers pulled off successful zero-day hacks against 98 unique vulnerabilities, earning $1,262,000 in prize money, according to BleepingComputer. The final leaderboard recorded 61 completed attempts across 29 research teams, according to CyberInsider.

That haul beats last year's total of seventy-three flaws, according to BleepingComputer β€” but the real story is where the researchers aimed. Phones still drew the biggest prizes, but the AI stack was the favorite playground: coding agents, AI databases, and an AI inference framework all got cracked alongside phones, printers, and smart-home gear. For a generation that hands AI tools its calendars, code, and permissions every day, these zero-day hacks hit uncomfortably close to home.

Day by day: how the zero-day hacks piled up

Day one, October 6, 2026, opened with a bang: $388,500 awarded for 32 unique vulnerabilities. Three separate teams took down Samsung's flagship phone β€” Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security β€” though BleepingComputer noted that the vendor already knew about some of the exploited bugs. Elsewhere on day one, Ikotas Labs popped OpenAI Codex with an argument-injection bug, while Taisic Yun of Xint landed a reverse shell on the LiteLLM AI gateway through an input-validation flaw chained with code injection. A VinSOC crew uncovered seven vulnerabilities in the Philips Hue Bridge Pro smart-lighting hub, and another VinSOC group chained five flaws to break Oracle's Autonomous AI Database. The day also saw a Sonos smart speaker, a Lexmark printer, and a Garmin blood-pressure monitor fall.

Day two, October 7, 2026, was the volume round: $232,500 for 45 unique vulnerabilities. The Samsung phone fell three more times β€” this round at the hands of PetoWorks, Kyeongmin Kim of the KAIST Hacking Lab, and a CENSUS Labs trio made up of Dimitrios Valsamaras, Ken Gannon, and Tenia Valsamara. Not every attempt landed: a White Noise Club trio failed to get a working exploit against the Google phone within the allotted time.

The final day's zero-day hacks were the most expensive of the week. On October 8, 2026, researchers exploited 21 vulnerabilities for $641,000 β€” and the Google Pixel phone was hacked three times for a combined $562,500. Ikotas Labs took the contest's top single prize, $300,000, for chaining multiple bugs to remotely hack the Pixel device, as reported by SecurityWeek. Tim Becker and Yves Bieri collected $150,000 for their Pixel exploit, which used an already-known flaw, while the CENSUS trio earned $112,500 for chaining one previously known bug with one fresh one. The final session also added another takedown of the Samsung handset, more smart-home controllers, printers, and a second successful hit on Oracle's AI database.

When the points were tallied, Ikotas Labs claimed Master of Pwn with 42.5 points and $361,000 in total winnings, turning zero-day hacks into the most decorated run of the week. Xint finished second with $240,000 and 27.5 points, while Team ZyGoat took third with $125,000 and a matching points total.

Why the AI stack drew the researchers' attention

A notable share of this year's zero-day hacks targeted AI tooling rather than classic consumer hardware. Beyond the coding agent and the AI gateway, researchers collected payouts for breaking Nvidia's Dynamo AI inference framework and Oracle's AI database, with rewards of $40,000 paid out for several of those AI-focused exploits, as reported by SecurityWeek. That shift matters because AI agents are no longer just chatbots β€” they run code, query databases, and act on your behalf with real permissions. Every cracked AI component is a potential foothold into the workflows people now trust with their work and personal data.

Then there's the twist everyone is talking about: nobody even tried to hack the iPhone 17. Apple's phone sat on the target list with the contest's maximum bounty β€” three hundred thousand dollars for a remote hack β€” yet no contestant registered an attempt, according to BleepingComputer. That is not proof the device is unhackable; it simply means no team signed up for that target this year. Still, the optics are delicious: the biggest single bounty of the week went to a Pixel hack while the iPhone watched from the sidelines.

What this means for your devices

For everyday users, these zero-day hacks are a reminder that the attack surface has moved. Your phone's lock screen is only part of the story now β€” the AI coding assistant in your workflow, the database behind your apps, and the smart-home hub on your shelf are all fair game. That is exactly why Apple has been tightening what AI agents are allowed to touch on its platforms, a crackdown we covered in our look at Apple's full disk access limits for AI agents. The practical takeaway is boring but effective: install updates promptly, because the flaws demonstrated in Cork are now on a clock.

The contest devices run the latest fully patched firmware, according to BleepingComputer, and researchers get dedicated devices and time β€” this is not a drive-by attack on your phone. One caveat is worth keeping in mind: some winning entries used bugs the vendors already knew about. The Zero Day Initiative calls these collisions and pays out at reduced prizes, which is why a few awards came in lower than the headline bounties. And the contest’s responsible-disclosure rules require that every flaw goes to the affected vendor first, with 90 days to ship a patch before the Zero Day Initiative publicly shares details, according to BleepingComputer. In other words, these zero-day hacks are how your future patches get made β€” the researchers get paid, the vendors get a deadline, and you get the fix before criminals can use the same tricks.

The zero-day hacks demonstrated in Cork will quietly become the software updates of the next few months. Keep an eye on our Tech & Games beat for what lands β€” and keep your devices updated when those patches arrive.