Pwn2Own Ireland day one: Galaxy S26, OpenAI Codex and LiteLLM hacked
Researchers earned $419,500 on the first day of Pwn2Own Ireland 2026 in Dublin, with 15 successful attempts against phones, printers, smart home devices and AI tools.
At a glance
- ZDI reports 15 successful attempts and 6 failures on day one, with $419,500 awarded.
- Samsung Galaxy S26 was compromised three times, though each attempt involved previously known bugs.
- AI targets fell too: OpenAI Codex, LiteLLM and Oracle Autonomous AI Database.
- Vendors have 90 days to release patches before ZDI publishes details.
Security researchers demonstrated working exploits against smartphones, printers, smart home devices and AI software on the first day of Pwn2Own Ireland 2026, held in Dublin on October 6. According to the Zero Day Initiative (ZDI), which organizes the contest, day one ended with 15 successful attempts, six failures and $419,500 in awards. BleepingComputer, reporting during the day, counted 32 unique zero-days and $388,500 at the time of its article.
What happened
ZDI's day-one results show that the Samsung Galaxy S26 was compromised three times, by Nguyen Thanh Dat of Viettel Cyber Security, Interrupt Labs and Ikotas Labs. All three attempts were classed as partial successes because some of the bugs used were already known, a situation ZDI calls a collision.
The VinSOC team had one of the strongest days. Vũ Chí Thành and Huỳnh Đức Tin chained seven bugs to take over the Philips Hue Bridge Pro for $40,000, while another VinSOC group used five bugs against Oracle Autonomous AI Database, also earning $40,000, according to ZDI.
AI products were a notable focus. ZDI reports that Ikotas Labs exploited OpenAI Codex with a single bug for $40,000, and Taisic Yun of Xint compromised LiteLLM with two bugs, also for $40,000. A team from Out of Bounds also succeeded against LiteLLM, partly with known bugs.
Technical details
Other successful entries listed by ZDI include McCaulay Hudson's two-bug exploit of the Sonos Era 300 speaker for $50,000, single-bug exploits of the Lexmark CX532adwe printer by Thanh Do of Team Confused and Sina Kheirkhah of Summoning Team, and a two-bug exploit of the Garmin Index BPM blood pressure monitor by Interrupt Labs. ZDI noted a high number of collisions on the first day.
Not every attempt landed. According to ZDI, attempts against the Brother MFC-L8970CDW printer, the Google Pixel 10, one Lexmark entry, a Garmin entry and the Chroma AI database ended in failure.
Who is affected
The affected vendors include Samsung, OpenAI, Oracle, Philips (Signify), Sonos, Lexmark and Garmin, as well as the open source LiteLLM project. Technical details of the bugs are not public. Under ZDI's rules, vendors have 90 days to release security updates before the details are disclosed.
What to do
There is no immediate action for users, as the vulnerabilities were reported privately and are not known to be exploited in the wild. Organizations using the affected products, particularly AI gateways such as LiteLLM and coding agents such as Codex, should watch for vendor advisories in the coming weeks and apply updates promptly. The contest continues for two more days with further attempts against mobile devices and other categories, BleepingComputer reports.
Sources
- Pwn2Own Ireland 2026 - Day One Results — Zero Day Initiative
- Hackers exploit 32 zero-days on first day of Pwn2Own Ireland — BleepingComputer
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



