Thursday, 8 October 2026

Researchers earned six-figure payouts for Galaxy S26 hacks

Three separate demonstrations at Pwn2Own Ireland 2026 show off six-figure payouts for Galaxy S26 zero-day exploits.

Samsung Galaxy S26, related to: Researchers earned six-figure payouts for Galaxy S26 hacks
Photo: Striker9498 / CC0 (modified)

The short version

  • At Pwn2Own Ireland 2026, the Galaxy S26 was hacked in three separate demos, earning security researchers six-figure awards.
  • A total of 45 unique zero-day vulnerabilities were exploited across devices and categories.
  • The event underlines ongoing security risks in fully patched devices and the need for rapid vendor responses.
Quick read · 1 min

During Pwn2Own Ireland 2026, security researchers hacked the Samsung Galaxy S26 three times, earning a share of cash awards totaling over $232,500. The event showcased 45 zero-day exploits across seven categories, underscoring ongoing security challenges even on up-to-date devices.

What it means for you: keep devices updated, enable automatic updates, and practice good security hygiene. Vendors typically patch flaws in the weeks after disclosure.

What happens next: patches will roll out in the following weeks; monitor your device’s security notices and apply updates promptly.

The Galaxy S26 was hacked three times on the second day of Pwn2Own Ireland 2026, with researchers walking away with a share of $232,500 in cash awards. The Galaxy S26 was targeted by KAIST Hacking Lab’s Kyeongmin Kim, PetoWorks, and Mobile Hacking Lab’s Dimitrios Valsamaras and Ken Gannon. The demos came as part of a broader showcase where 45 unique zero-day vulnerabilities were exploited across seven product categories.

Zero-day exploits are flaws that vendors don’t yet have patched. In the competition, researchers must demonstrate arbitrary code execution on the target device while it runs the latest firmware. After disclosure, vendors typically have a window (often 90 days) to fix the vulnerability before it’s publicly disclosed by the organizers. That timing matters for real-world users who expect patches quickly after such findings surface.

Other notable moments from day two included a quick hack of a Sonos Era 300 by the RET2 Systems team and a separate AI infrastructure hack that netted a large payout for the Out of Bounds team. Home devices and AI systems remain attractive targets at Pwn2Own Ireland, reflecting the growing attack surface in connected homes and enterprise-grade AI tools.

01

What is Pwn2Own Ireland and why does it matter?

Pwn2Own Ireland is part of a global security contest where researchers try to break widely used consumer devices and software to reveal how attackers might exploit them. The goal is to uncover bugs before criminals do and push vendors to patch promptly. The competition covers phones, smart home devices, printers, and AI infrastructure, among other targets.

Padlock
02

Which devices were hacked and how serious were the flaws?

The Galaxy S26 was among several devices targeted. The competition also saw attempts on the Google Pixel 10 and the Home Assistant Green smart home hub, among others. The hacks demonstrated across multiple categories suggest that even the latest devices can still be vulnerable in surprising ways, especially when complex chains of flaws are chained together to achieve full control.

03

What this means for ordinary users

For everyday users, the takeaway is simple: even premium devices with current firmware can have undisclosed flaws. No single hack means users should panic, but it does mean you should keep your devices up to date and install patches as soon as they’re released. It also highlights the importance of a layered security approach, regular OS updates, app updates, strong device passwords or biometrics, and cautious behavior with third-party apps and links.

Server room
04

What happens next

After Pwn2Own Ireland, vendors typically review the disclosed flaws and release patches over the following weeks. If you own a Galaxy S26, ensure you have automatic updates turned on so you don’t miss crucial security fixes. Researchers and vendors will continue to monitor and respond as new flaws surface in ongoing security efforts.

05

Quick answers

What happened at Pwn2Own Ireland 2026?

Researchers hacked the Galaxy S26 three times, and 45 zero-day vulnerabilities were exploited across the event, earning substantial cash prizes.

Should I worry about my Galaxy S26 right now?

There’s no indication of an active exploit in the wild. Stay current with updates and follow best security practices to minimize risk.

You're reading the quick version.