Three separate teams walked off the Pwn2Own Ireland stage on October 6, 2026 having taken over Samsung’s Galaxy S26, and each of them had to share the win with bugs that the vendor already knew about. Viettel Cyber Security, Interrupt Labs and Ikotas Labs each chained four bugs against the handset on the first day of the contest, and the Zero Day Initiative recorded all three as successes with collisions. Together the three entries earned $58,000.
The phone drew more attention than any other target on a day that mixed smartphones with printers, a smart speaker, a lighting hub and AI infrastructure. It was also the target where the contest’s prize structure showed most plainly: a device that attracts several teams pays less to each once its bugs start to overlap.
Three entries, three sets of four bugs
The Zero Day Initiative’s Day One results list the S26 entries in running order. Nguyen Thanh Dat of Viettel Cyber Security went first, using four bugs, three of which the vendor already knew about, for $31,250 and 3.25 Master of Pwn points. Interrupt Labs followed with four bugs of which three were collisions and one was a zero-day, taking $15,750 and 3.25 points. Ikotas Labs used four bugs as well, with one already known to the vendor and still unpatched, for $11,000 and 4.5 points.
The count is plain from ZDI’s list: the post says “multiple Samsung attempts” opened the day, and the itemised list shows no failed S26 entry. Interrupt Labs’ single zero-day is the only new S26 vulnerability the post states outright, and the post does not say which of the vulnerabilities the other two teams used were new.
The S26 results sat in the middle of a crowded schedule. VinSOC’s Vu Chi Thanh and Huynh Duc Tin chained seven zero-days against a Philips Hue Bridge Pro for 0,000, a second VinSOC team earned the same amount with five bugs against the Oracle Autonomous AI Database, and McCaulay Hudson took 0,000 for an out-of-bounds write and a format-string bug on a Sonos Era 300. Google’s Pixel 10 saw its first entry, from White Noise Club, which could not make its exploit work within the time allowed.
Ikotas Labs also returned to the stage later in the day to take down OpenAI Codex with a single argument-injection bug, which ZDI paid at $40,000.
Collisions and the shrinking payout
ZDI’s Pwn2Own Ireland 2026 rules explain the gap between the S26 payouts and the top listed prizes. Entries must use vulnerabilities that are unknown, unpublished or not previously reported to the vendor or the sponsor, and when a previously known bug turns up, the sponsor may still accept the entry but pay less than the category’s listed amount. The rules set the Galaxy S26 at $50,000 and 5 Master of Pwn points for a remote vector and $35,000 and 3.5 points for a USB vector.
That framework produces odd results. Ikotas Labs carried the fewest known bugs into the room and collected the smallest check, $11,000, though it picked up the most points, 4.5. Viettel’s entry, with the most overlap, paid the most, $31,250. The post does not attribute those differences to any single factor, and the rules leave the sponsor discretion over how much a collision costs.
Last year’s contest offers a benchmark for how much a clean S-series compromise pays. At Pwn2Own Ireland 2025, Interrupt Labs’ Ben R. and Georgi G. used an improper input validation bug to take over the Galaxy S25 for $50,000 and 5 Master of Pwn points, enabling the camera and location tracking in the process. The event as a whole paid $1,024,750 for 73 unique bugs, with the Summoning Team named Master of Pwn.
From the stage to a Samsung patch
BleepingComputer’s day-one tally put the first day at $388,500 for 32 zero-days across every target, and noted that vendors have 90 days to ship fixes before ZDI discloses the flaws publicly. It also reported that some bugs in each challenge were already known to the vendor, which is the same overlap ZDI records for the S26 entries. Day two repeats the Galaxy S26 category, and day three returns to it again.
Samsung publishes fixes on a monthly cycle. Its security update page shows the SMR-OCT-2026 bulletin, version 1.0, posted on October 6, the same day as the contest opened, and its summary covers Google and Samsung Semiconductor patches and 13 listed Samsung vulnerability entries without mentioning Pwn2Own.
The three S26 entries on day one added up to $58,000, only $8,000 more than the $50,000 ZDI’s rules assign to a single remote-vector compromise of the same phone.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Hurricane Hunter radar shows four warning signs that a tropical cyclone is about to strengthen, a University of Miami study found
- Tropical Storm Rachel is dumping up to 12 inches on four Mexican states on its way to major hurricane strength
- The FTC says Lens.com doubled the price shoppers saw in Google ads
- Common allergy, bladder and sleep pills tied to sharply higher dementia odds