
A group of hackers just pocketed a whopping $1,262,000 in rewards by showcasing their skills at the Pwn2Own Ireland 2026 contest, where they exploited 98 zero-day vulnerabilities. It’s the kind of event where the more you break, the more you make.
Ikotas Labs came out on top, earning $361,000 and 42.5 Master of Pwn points. Their impressive trophy case included hacks on the Samsung Galaxy S26, OpenAI Codex, and the Oracle Autonomous AI Database. Who knew hacking could be so profitable?
On the final day, they grabbed the largest single award of $300,000 by chaining multiple zero-days to breach the Google Pixel 10. Because why settle for one hack when you can collect them all like Pokémon?
In second place was Xint, cashing in $240,000, while Team ZyGoat tied for third with a respectable $125,000. Clearly, hackers are the new rock stars, just without the long hair and screaming fans.
During the event, numerous teams demonstrated their prowess on the first day alone, exploiting 32 vulnerabilities worth a total of $388,500. Samsung, meanwhile, might want to take a long, hard look in the mirror since some of the exploited flaws were already on their radar.
The second day offered even more chaos as participants racked up $232,500 for 45 unique zero-day vulnerabilities. The hacks kept coming like a bad sequel, with competitors taking down the Galaxy S26 time after time.
By the end, a total of 21 zero-days were exploited for a grand finale payout of $641,000. Seems like some of these hackers might just need a new bank account to hold all their cash.
This year's event saw 29 research teams targeting products across seven charmingly vague categories like mobile phones and wellness devices—because nothing screams "advanced technology" quite like a device that tells you to drink more water.
Interestingly, Apple’s iPhone 17 was available for a potential hack with a $300,000 reward, but it turns out no one was daring enough to take that leap. Maybe they heard the old adage, “why poke the bear?”
Organized by Trend Micro's Zero Day Initiative, this contest is a glorious parade of vulnerabilities that vendors now have 90 days to patch before the rest of the world finds out just how fragile their beloved technology really is. In the meantime, hackers will keep laughing all the way to the bank, while users just hope their devices aren’t the next one on the chopping block.
