Researchers Net $388,500 by Leveraging 32 Zero‑Days at Pwn2Own Ireland 2026
On the opening day of the 2026 Pwn2Own Ireland contest, a team of security researchers demonstrated a series of unprecedented exploits, compromising a Samsung Galaxy S26 device twice and claiming a prize pool of $388,500 after employing a total of 32 distinct zero‑day vulnerabilities.
The Pwn2Own series, organized by the Zero Day Initiative, pits professional hackers against the latest consumer hardware and software in a controlled environment. Participants are required to disclose their findings to vendors, who then have a limited window to develop patches before the vulnerabilities become public. The Irish edition, held for the first time this year, attracted teams from Europe and North America, all vying for the lucrative rewards tied to successful exploits.
According to the competition’s rules, each verified zero‑day earns a monetary award that scales with the difficulty and impact of the exploit. By chaining together 32 separate flaws, the winning team not only breached the device’s lock screen and user authentication mechanisms but also achieved persistent code execution, allowing them to maintain control after a reboot. The double compromise of the same Galaxy S26 model underscored the breadth of the attack chain, as the researchers demonstrated both a remote code execution path and a local privilege escalation.
Samsung, whose flagship S26 was released earlier this year, has pledged to work closely with the Zero Day Initiative to address the reported issues. The company’s security response team typically prioritizes patches for vulnerabilities that receive public disclosure through Pwn2Own, given the event’s reputation for surfacing high‑impact bugs that could be weaponized in the wild. Industry observers note that the sheer number of zero‑days uncovered in a single day is unusual, suggesting that the device’s software stack may have accumulated technical debt that attackers can now exploit.
Looking ahead, the competition’s organizers expect the remaining days of Pwn2Own Ireland to produce additional findings across a range of devices, from laptops to smart home hubs. The outcomes will likely feed into broader vulnerability‑management efforts, influencing patch cycles for manufacturers and informing security policies for enterprise users. For the hacking community, the $388,500 payout serves as both a financial incentive and a benchmark, highlighting the growing commercial value of responsibly disclosed zero‑day research.
Comments (0)
Be the first to comment.
Join the discussion