Pwn2Own Ireland 2026 is over, and the hacking contest turned up 98 zero-days while paying out more than $1.2 million, according to its published results. The bugs showed up across smartphones, printers, smart speakers, smart-home hubs, coding tools, cloud databases, and even a connected wellness device.
Google’s Pixel 10 drew the most attention. Contest results show three successful attacks against it, worth more than $560,000 combined.
Ikotas Labs took home $300,000 for a remote exploit chain. Tim Becker and Yves Bieri earned $150,000 for a separate chain, though that payout was cut because part of it relied on a known bug. Dimitrios Valsamaras and Ken Gannon collected $112,500 for a third chain that mixed a zero-day with a known flaw, which is how Pwn2Own reduces rewards when researchers don’t bring a fully original set of bugs.
The rest of the board was busy too. The published results list a Samsung Galaxy S26 hack for about $30,000, a Home Assistant Green compromise for roughly the same amount, a Sonos Era 300 hit for $50,000, Lexmark and Brother printer hacks at $20,000 each, a Garmin Index BPM breach at $20,000, and coding and cloud database targets in the $40,000 range.
If you use any of those products, pay attention. Vendors now get the exploit details privately under the usual 90-day patch window. One other detail from the published results stands out: nobody took a shot at the $300,000 Apple iPhone 17 or WhatsApp targets.