Competitors at Pwn2Own Ireland 2026 took home more than $1.2 million this week, and the Google Pixel 10 proved the richest target on the floor. Three separate teams demonstrated remote compromises of the fully patched handset, collectively earning over $560,000.
Ikotas Labs claimed the full $300,000 bounty by chaining several bugs into a remote hijack. Tim Becker and Yves Bieri collected $150,000 for a Pixel exploit that leaned on a previously known flaw and so missed the top payout.
Where the money went
A third Pixel hack came from Dimitrios Valsamaras and Ken Gannon, who banked $112,500 by pairing a fresh zero-day with an older vulnerability. The duo earned $50,000 last year for breaking a Samsung Galaxy S25, and later showed how flaws in Samsung software, including the Bixby assistant, could be turned against mobile devices.
Beyond phones, a researcher earned $50,000 for a Sonos Era 300 smart speaker attack. Several other exploits drew $40,000 apiece, hitting Oracle Autonomous AI Database, OpenAI Codex, Nvidia’s Dynamo AI inference framework, the LiteLLM AI gateway and the Philips Hue Bridge Pro hub.
Roughly $30,000 went to researchers targeting the Samsung Galaxy S26 and the Home Assistant Green hub. Lexmark and Brother printers, plus the Garmin Index BPM blood pressure monitor, fetched $20,000 each.
The targets nobody touched
Notably, no one attempted the iPhone 17 or WhatsApp, both of which carried a maximum prize of $300,000. Vendors will receive full exploit details, and the affected products now head into coordinated patching.
The results underline how AI infrastructure and coding agents have become first-class targets, sitting alongside consumer hardware in the same contest.
