Pwn2Own Ireland 2026 opened on 6 October with researchers breaking a Samsung Galaxy S26 three times, a Sonos speaker, three AI platforms and two printers. The Zero Day Initiative’s published day-one results list 20 attempts, 15 of them successful, with awards totalling $368,500. No contestant has entered the iPhone 17 or WhatsApp categories, each worth up to $300,000.

What Researchers Broke on Day One

Fifteen of the 20 scheduled attempts on 6 October succeeded. The Zero Day Initiative, the Trend Micro bug bounty programme that runs the contest, publishes each result as it is judged; the table below lists every successful entry from its day-one post.

Researcher or teamTargetBugs usedAward
McCaulay HudsonSonos Era 3002$50,000
Taisic Yun (Xint)LiteLLM2$40,000
Vu Chi Thanh and Huynh Duc Tin (VinSOC)Philips Hue Bridge Pro7$40,000
Nam Nguyen, Thanh Vu and Tin Huynh (VinSOC)Oracle Autonomous AI Database5$40,000
Ikotas LabsOpenAI Codex1$40,000
Nguyen Thanh Dat (Viettel Cyber Security)Samsung Galaxy S264 (3 collisions)$31,250
Thanh Do (Team Confused)Lexmark CX532adwe1$20,000
Interrupt LabsGarmin Index BPM2$20,000
linhlhq and Son Dinh (VinSOC)Sonos Era 3002 (1 collision)$17,500
Interrupt LabsSamsung Galaxy S264 (3 collisions)$15,750
HaeJung Yang and ByungYoung Yi (Out of Bounds)LiteLLM4 (2 collisions)$15,000
ByungYoung Yi and KeunHo Kim (Out of Bounds)Philips Hue Bridge Pro5 (4 collisions)$12,000
Ikotas LabsSamsung Galaxy S264 (1 collision)$11,000
Sina Kheirkhah (Summoning Team)Lexmark CX532adwe1$10,000
Joohyun Park (Xint)Philips Hue Bridge Pro5 (4 collisions)$6,000

Five attempts failed outright and paid nothing: Ikotas Labs against a Brother MFC-L8970CDW printer, T-X Lab against a Lexmark CX532adwe, Aaron Christophel against a Garmin Index BPM blood pressure monitor, White Noise Club against a Google Pixel 10, and a VinSOC team against the Chroma vector database.

The single most efficient result was Ikotas Labs taking $40,000 for one bug in OpenAI Codex, the cloud coding agent. BleepingComputer reported that the flaw was an argument-injection bug.

Why the Day-One Totals Disagree

Three different day-one figures were published on 6 October, and all of them were accurate when written. The Zero Day Initiative posts results through the day, so the running total climbs as each attempt is judged.

  • $342,500 across 28 zero-days: reported by CyberInsider from an earlier snapshot of the scoreboard.
  • $368,500: the sum of the itemised awards in the Zero Day Initiative’s own day-one results, as published.
  • $388,500 across 32 zero-days: reported by BleepingComputer later the same day.

The bug counts diverge for a second reason. A single entry can chain several flaws, and some of those flaws are ones the vendor already knows about, so the number of distinct new vulnerabilities is lower than the number of bugs demonstrated.

What a Collision Means and Why It Cuts the Prize

A collision is a bug that someone has already reported to the vendor, and it reduces the award. Of the three Galaxy S26 entries, every one involved at least one collision, which is why none of them earned the full category prize.

Collisions matter to readers for a reason the scoreboard does not spell out: a collision means the vendor knew, not that the vendor has fixed it. A device can still be carrying a flaw that was reported months ago.

The Galaxy S26 Fell Three Times and the Pixel 10 Held

Three separate teams compromised a Samsung Galaxy S26 on day one. Nguyen Thanh Dat of Viettel Cyber Security earned $31,250 and 3.25 Master of Pwn points using four bugs; Interrupt Labs earned $15,750 and 3.25 points, also with four bugs; and Ikotas Labs earned $11,000 and 4.5 points, with only one collision among its four.

The one phone attempt that failed was White Noise Club’s against a Google Pixel 10. The S26 is the current Samsung flagship and received the One UI 9 rollout from September 2026; neither Samsung nor Google has published an advisory tied to these specific entries at the time of writing.

Why the Galaxy S26 Is the Cheapest Phone on the Board

The three phones are not worth the same to a contestant, and the gap is large enough to shape who attempts what. The Zero Day Initiative’s contest rules set these awards for a remote compromise.

TargetRemote exploit awardUSB exploit award
Apple iPhone 17$300,000$75,000
Google Pixel 10$300,000$75,000
Samsung Galaxy S26$50,000$35,000

A working remote chain against an iPhone 17 or a Pixel 10 is worth six times a Galaxy S26 chain. The award scale is set by the organiser rather than by any measure of how secure each phone is, but it does tell researchers where the contest wants effort spent.

No One Entered the iPhone 17 or WhatsApp Categories

Despite a $300,000 award for a remote iPhone 17 compromise and $300,000 for a zero-click WhatsApp exploit, neither target appears anywhere in the published three-day schedule. The Zero Day Initiative lists entries for the Galaxy S26, the Pixel 10, smart home devices, printers, wellness devices and AI platforms, and none for Apple’s phone or for the messaging category.

That is an absence of registered attempts, not a verdict on either product. Contestants must qualify and register in advance, and a team that cannot get a chain working reliably before the deadline simply does not appear on the schedule. Apple’s most recent patched zero-day arrived in iOS 26.7.1 in early October, which shows researchers are still finding iPhone flaws outside the contest.

What Is Scheduled for 7 and 8 October

The Zero Day Initiative’s schedule runs the contest from Tuesday 6 October to Thursday 8 October 2026 in Cork, Ireland, while its rules document gives the window as 6 to 9 October. Roughly 19 attempts are scheduled for day two and 17 for day three.

  • Tuesday 7 October: attempts against the Sonos Era 300, Samsung Galaxy S26, Lexmark CX532adwe, Home Assistant Green and several AI infrastructure platforms.
  • Wednesday 8 October: three separate Google Pixel 10 remote attempts, by Xint, Ikotas Labs and CENSUS Labs, plus one Galaxy S26 remote attempt by BunkyoWesterns.
  • Master of Pwn: the contestant with the most points takes 65,000 ZDI reward points, which the rules value at about $25,000.

What Device Owners Should Do Now

Nothing demonstrated at Pwn2Own is published in enough detail to be copied, and the flaws go to the vendors rather than to the public. BleepingComputer reports that vendors are given 90 days to ship a fix before the Zero Day Initiative discloses the details.

The practical consequence is that a patch for anything broken this week is months away, and the useful step is routine rather than urgent. Owners of a Galaxy S26, a Philips Hue Bridge Pro, a Sonos Era 300, a Home Assistant Green or a Garmin Index BPM should keep automatic updates switched on and install firmware updates when they appear.

As of 7 October 2026, no vendor has issued a security advisory naming a Pwn2Own Ireland 2026 entry, and days two and three have not yet been held.

Frequently Asked Questions

When Is Pwn2Own Ireland 2026 Taking Place?

It runs from 6 to 8 October 2026 in Cork, Ireland, according to the Zero Day Initiative’s published schedule. The contest rules document gives the window as 6 to 9 October.

How Much Was Won on Day One of Pwn2Own Ireland 2026?

The itemised awards in the Zero Day Initiative’s day-one post total $368,500 across 15 successful attempts. BleepingComputer reported $388,500 later the same day, and the figure rose through the day as results were judged.

Was the iPhone 17 Hacked at Pwn2Own Ireland 2026?

No attempt was made. No iPhone 17 entry appears anywhere in the published three-day schedule, even though the rules offer $300,000 for a remote compromise.

Does This Mean My Samsung Galaxy S26 Is Unsafe?

The flaws used are reported privately to Samsung rather than published. Keep automatic updates on and install security updates when Samsung releases them; the details are not public, so there is no known attack to defend against today.

What Does a Bug Collision Mean at Pwn2Own?

It means another researcher, or the vendor, already knew about that vulnerability, so the award is reduced. All three Galaxy S26 entries on day one involved at least one collision.