Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own
Pwn2Own Ireland 2026 awarded over $1.2 million; three teams earned $560,000 for Google Pixel 10 exploits, including Ikotas Labs' full $300,000 zero-day chain.
Pwn2Own Ireland 2026 concluded with more than $1.2 million paid for exploits against phones, printers, smart speakers, smart home hubs, AI infrastructure, and cloud databases. Ikotas Labs earned the full $300,000 for chaining multiple bugs to remotely hack a Google Pixel 10; Tim Becker and Yves Bieri received $150,000, and Dimitrios Valsamaras and Ken Gannon earned $112,500 for chaining a zero-day with a known flaw. Other rewarded targets included the Sonos Era 300 ($50,000), Oracle Autonomous AI Database, OpenAI Codex, Nvidia Dynamo, LiteLLM, Philips Hue Bridge Pro, Samsung Galaxy S26, Lexmark/Brother printers, and Garmin Index BPM. Vendors receive full exploit details; the iPhone 17 and WhatsApp prizes went unclaimed.
- Total payouts exceeded $1.2 million; Pixel 10 exploits alone earned $560,000.
- Ikotas Labs claimed the full $300,000 for a chained remote Pixel hack.
- AI targets included OpenAI Codex, Nvidia Dynamo, LiteLLM, and Oracle Autonomous AI Database.
- iPhone 17 and WhatsApp ($300,000 max) were left untargeted.
Full article373 words · extracted from securityweek.com · click to collapse
Pwn2Own Ireland 2026 has come to an end, and participants earned more than $1.2 million for exploits targeting phones, printers, smart speakers, smart home hubs, a wellness device, AI infrastructure and coding tools, and cloud databases.
The highest rewards were paid out for Google Pixel 10 exploits, which were demonstrated by three teams. They collectively earned more than $560,000 for their work.
The Ikotas Labs team earned the full $300,000 payout by chaining multiple bugs to remotely hack a Pixel phone.
Tim Becker and Yves Bieri received $150,000 for their Pixel exploit — they did not get the full payout because their exploit involved a previously known flaw.
The third Pixel hack was demonstrated by Dimitrios Valsamaras and Ken Gannon, who earned $112,500 for an exploit that chained a zero-day with a previously known vulnerability.
Last year, Valsamaras and Gannon earned $50,000 for hacking a Samsung Galaxy S25 device. They later showed how they exploited vulnerabilities in Samsung software, including the virtual assistant Bixby, to hack mobile devices.
Advertisement. Scroll to continue reading.
In addition to the Pixel exploits, a significant reward, $50,000, was earned by a researcher for a Sonos Era 300 smart speaker hack.
Rewards of $40,000 were paid out for several exploits, including ones targeting Oracle Autonomous AI Database, OpenAI Codex, Nvidia’s Dynamo AI inference framework, the LiteLLM AI gateway, and the Philips Hue Bridge Pro smart lighting hub.
Researchers received roughly $30,000 for exploits targeting the Samsung Galaxy S26 and the Home Assistant Green smart home hub.
Pwn2Own participants earned $20,000 for hacking Lexmark and Brother printers, and the Garmin Index BPM blood pressure monitor.
Rewards ranging from $4,250 to $17,500 were paid out for exploits involving Sonos Era, Galaxy S26, LiteLLM, Philips Hue Bridge Pro, Lexmark CX532adwe, Oracle Autonomous AI Database, Home Assistant Green, Chroma, Garmin Index BPM, and Canon imageFORCE 1643F.
Affected vendors will be provided with the full details of all exploits.
No one targeted the iPhone 17 and WhatsApp, both of which had a maximum prize of $300,000.
Related: TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws
Related: Android’s October 2026 Updates Patch 25 Vulnerabilities
Related: Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports