www.securityweek.com 9 Oct 2026, 06:39 UTC

Hackers Win $1.2 Million at Pwn2Own, With Pixel 10 Bugs Leading the Payouts

Hackers Win $1.2 Million at Pwn2Own, With Pixel 10 Bugs Leading the Payouts
CyberSIXT Evidence Panel Source marked as original reporting

PWN 2Own Ireland 2026 concluded with hackers earning more than $1.2 million from exploits across phones, printers, smart speakers, smart home hubs, wellness devices, AI infrastructure and coding tools, and cloud databases. The standout prize went to Google Pixel 10 exploits, demonstrated by three teams and collectively worth more than $560,000.

The Ikotas Labs team claimed the largest Pixel payout of $300,000 by chaining multiple bugs to remotely compromise a Pixel phone. A second Pixel entry by Tim Becker and Yves Bieri won $150,000, though it did not receive the full amount because some flaws were previously known. The third Pixel demonstration by Dimitrios Valsamaras and Ken Gannon earned $112,500 for a chain combining a zero-day with a prior vulnerability.

In total, the event highlighted several high-value exploits, with other rewards including a $50,000 prize for a Sonos Era 300 hack and $40,000 across exploits targeting Oracle Autonomous AI Database, OpenAI Codex, Nvidia’s Dynamo AI inference framework, the LiteLLM AI gateway, and the Philips Hue Bridge Pro.

Vendors were to receive full details of all exploits, and organisers noted that some prizes remained for other devices, while iPhone 17 and WhatsApp did not see exploitation despite a $300,000 maximum prize. The report underscores the breadth of targets and the varied motivation and impact of modern bug chains. 9 October 2026.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline