The headline numbers
- Total: $1,262,000 for 98 zero-days, according to BleepingComputer. The reported daily figures add up to that total: $388,500 on day one, $232,500 on day two and $641,000 on day three.
- Winner: Ikotas Labs won with 42.5 Master of Pwn points and $361,000 over the three days, after hacking the Samsung Galaxy S26, OpenAI Codex and the Oracle Autonomous AI Database.
- Runners-up: Xint took second with $240,000 and 27.5 points, and Team ZyGoat took third with $125,000 and the same 27.5 points.
- Scale: The Zero Day Initiative's contest page lists 29 research teams. Its running tally at the time of the snapshot showed 59 of 61 attempts complete, with $1,142,000 awarded and 90 unique zero-days. That snapshot was taken before the final results were in, so it shows a different total from the wrap-up. I'd treat BleepingComputer's closing figures as the final word, but the gap is a reminder that "98" is a tally that moved during the event.
What the final-day Pixel results show
ZDI's day-three log says Ikotas Labs' Google Pixel 10 exploit earned $300,000 and 30 Master of Pwn points. That made Ikotas the Master of Pwn. It is the contest's biggest single payout.
BleepingComputer says researchers took down the Pixel three times on the last day. ZDI's detailed log shows the three attempts paid very differently:
| Attempt | Outcome | Payout |
|---|---|---|
| Xint (remote) | Success, flagged as a collision | $150,000 |
| Ikotas Labs (remote) | Success, multi-bug chain | $300,000 |
| Valsamaras / Gannon / Valsamara | Two-bug chain: one collision, one zero-day | $112,500 |
Each of these paid out as a successful exploit, but only one got the headline amount. The $300,000 figure was the listed ceiling for a remote Pixel attempt, not a guaranteed payout for each success.
Collisions: why "98 zero-days" needs a footnote
Many of the successes were marked "collision". That means at least one bug in the chain was already known to the vendor or to others. ZDI's day-one log has several examples:
- On the Galaxy S26, one team used four bugs but three were already known to the vendor, and it still earned its reduced payout and points.
- On the Sonos Era 300, two bugs were used and one was publicly known, which still paid $17,500.
- On the Philips Hue Bridge Pro, one chain included a five-bug "full collision" that paid $5,000.
The contest rules explain the pay structure. Only the first demonstration in a category takes the full cash award, but each successful entry claims the full Master of Pwn points. That is why late-drawn teams can still win the title on points while taking less cash.
Read the headline tally as the event's reported count of zero-days. It is not 98 flaws that no vendor had ever heard of. The Galaxy S26 shows this clearly: it fell repeatedly, but many of those payouts were small. Day three's BunkyoWesterns remote exploit, for example, paid only $8,250 against a listed maximum of $50,000.
Why Windows and IT readers should care
No Microsoft product was in the published target list. Several targets matter to the people who run Windows estates, though.
- AI coding agents. OpenAI Codex fell on day one to a single argument-injection bug, according to ZDI. The Codex target was among the coding agents (alongside Anthropic's Claude Code) in the category ZDI introduced. ZDI's rules put the focus on agents interacting with attacker-controlled resources such as web pages, repositories or media files, which is how developers use them every day. If your developers run coding agents on Windows workstations, this is the threat model to think about.
- AI infrastructure. Teams exploited LiteLLM, Dynamo, Chroma and the Oracle Autonomous AI Database. In the AI Infrastructure category, attempts had to be launched from the contestant's laptop, which means over the network. These components increasingly sit behind internal apps and Copilot-style integrations.
- Printers. ZDI describes printers as an often overlooked attack surface in your office in its category announcement. Brother, Canon and Lexmark models fell. Printers were also harder than expected: several teams hit the time limit on day one.
- Phones. Samsung's Galaxy S26 and Google's Pixel 10 are the devices most likely to be enrolled in your MDM or Intune fleet.
Apple's iPhone 17 was listed as a potential target, but BleepingComputer says no contestant registered an attempt.
What happens next
BleepingComputer says vendors have 90 days to patch disclosed flaws before ZDI publishes details. No CVE numbers, firmware versions or patch builds were established in the sources I reviewed, so there is nothing specific to deploy today. Nothing here shows in-the-wild exploitation either. These were demonstrations under contest conditions, and ZDI's rules require the latest firmware and updates on every target.
Practical steps:
- Make sure phones, printers and smart-home or AI tooling in your inventory are on their latest firmware, since that is the baseline the contest used.
- Watch vendor security bulletins from Samsung, Google, Oracle, OpenAI, Brother, Canon, Lexmark, Sonos and Philips over the next three months.
- Check ZDI advisories as they publish after the 90-day window.
- Treat coding agents like any privileged developer tool. Don't run them in permissionless modes on machines that hold secrets.
- Segment printers and IoT devices away from critical servers.
Year-over-year comparison
BleepingComputer reports that last year's Ireland event paid $1,024,750 for 73 zero-days, with Summoning Team winning. By those figures, 2026 paid about $237,000 more and found 25 more zero-days. That is a comparison of contest totals. It doesn't show that the products are less secure than last year, because the target list and payout rules changed. This year the contest dropped most consumer devices and added AI categories and a wellness category.
Bottom line
Pwn2Own Ireland 2026 delivered a record-sized payout. For enterprise IT, the useful signal isn't the dollar figure. AI coding tools, AI infrastructure, printers and flagship phones were all breakable by skilled teams within the time limit. Expect patches inside the 90-day window, and keep an eye on advisories for the products you actually run.
References
- Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland BleepingComputer · 2026-10-09T01:41:04-04:00
- Hackers exploit 32 zero-days on first day of Pwn2Own Ireland bleepingcomputer.com
- Zero Day Initiative — Pwn2Own Ireland 2026 - Day Three Results & Master of Pwn zerodayinitiative.com