Back to Feed
VulnerabilitiesOct 9, 2026

Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own

Hackers earned over $1.2M at Pwn2Own Ireland 2026 for exploits, with Pixel 10 hacks netting $560K.

Summary

Pwn2Own Ireland 2026 concluded with over $1.2 million awarded for exploiting various devices and AI tools. The most lucrative targets were Google Pixel 10 phones, with three teams collectively earning over $560,000 for demonstrating remote hacking capabilities. Other significant payouts included exploits for smart speakers, AI infrastructure, and cloud databases.

Full text

Pwn2Own Ireland 2026 has come to an end, and participants earned more than $1.2 million for exploits targeting phones, printers, smart speakers, smart home hubs, a wellness device, AI infrastructure and coding tools, and cloud databases. The highest rewards were paid out for Google Pixel 10 exploits, which were demonstrated by three teams. They collectively earned more than $560,000 for their work. The Ikotas Labs team earned the full $300,000 payout by chaining multiple bugs to remotely hack a Pixel phone. Tim Becker and Yves Bieri received $150,000 for their Pixel exploit — they did not get the full payout because their exploit involved a previously known flaw. The third Pixel hack was demonstrated by Dimitrios Valsamaras and Ken Gannon, who earned $112,500 for an exploit that chained a zero-day with a previously known vulnerability. Last year, Valsamaras and Gannon earned $50,000 for hacking a Samsung Galaxy S25 device. They later showed how they exploited vulnerabilities in Samsung software, including the virtual assistant Bixby, to hack mobile devices.Advertisement. Scroll to continue reading. In addition to the Pixel exploits, a significant reward, $50,000, was earned by a researcher for a Sonos Era 300 smart speaker hack. Rewards of $40,000 were paid out for several exploits, including ones targeting Oracle Autonomous AI Database, OpenAI Codex, Nvidia’s Dynamo AI inference framework, the LiteLLM AI gateway, and the Philips Hue Bridge Pro smart lighting hub. Researchers received roughly $30,000 for exploits targeting the Samsung Galaxy S26 and the Home Assistant Green smart home hub. Pwn2Own participants earned $20,000 for hacking Lexmark and Brother printers, and the Garmin Index BPM blood pressure monitor. Rewards ranging from $4,250 to $17,500 were paid out for exploits involving Sonos Era, Galaxy S26, LiteLLM, Philips Hue Bridge Pro, Lexmark CX532adwe, Oracle Autonomous AI Database, Home Assistant Green, Chroma, Garmin Index BPM, and Canon imageFORCE 1643F. Affected vendors will be provided with the full details of all exploits. No one targeted the iPhone 17 and WhatsApp, both of which had a maximum prize of $300,000. Related: TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws Related: Android’s October 2026 Updates Patch 25 Vulnerabilities Related: Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router FlawsOracle Health Data Breach Tally Climbs to Nearly 20 MillionGeorgia Power, Alabama Power Data Breach Hits 400,000 AccountsAdvantest Discloses Data Breach Months After Ransomware AttackAnthropic Introduces 3-Tier Cyber Verification Program for AI AccessWikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into ProxiesFBI Blames Contractor’s Missed Patch for ShinyHunters BreachCybersecurity M&A Roundup: 39 Deals Announced in September 2026 Latest News Citrix Urges Immediate Patching of Critical NetScaler VulnerabilityFormula Predicts When AI Chatbots Are at Risk of Turning BadCisco Patches a Dozen Critical VulnerabilitiesSecurity Awareness Training Isn’t Dead, but It Needs a RethinkAttackers Target Critical Atlassian Vulnerability Within Hours of PoC PublicationUS Seeks Alleged Chinese Hafnium Hacker With $10 Million RewardSonicWall and Splunk Patch Critical VulnerabilitiesRein Security Raises $25 Million to Guard AI Agents at Runtime Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveRapid7 has named Rik Ferguson as VP of Security Intelligence.Cytactic has appointed Tim Brown as CSO.Scott Simkin has joined Vega as CMO.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email

Entities

Google Pixel 10 (product)Sonos Era 300 (product)Oracle Autonomous AI Database (product)OpenAI Codex (product)Nvidia Dynamo (product)LiteLLM (product)