Galaxy S26 Hacked Six Times at Pwn2Own Ireland 2026

Six different research teams found working exploits against Samsung's flagship at Trend Micro's live hacking contest in Cork, Ireland — here's who did it, how, and for how much.

Close-up of the back of the Samsung Galaxy S26 and Galaxy S26 Plus showing their camera modules
The Samsung Galaxy S26 and Galaxy S26 Plus. Image: Samsung.

Samsung's new Galaxy S26 flagship was successfully hacked six separate times over two days at Pwn2Own Ireland 2026, the live hacking contest that Trend Micro's Zero Day Initiative (ZDI) runs each year in Cork, Ireland. Three independent teams broke into the phone on Day One (October 6) and three more did it again on Day Two (October 7), each walking away with cash and Master of Pwn points for bugs ZDI itself confirmed on its results pages.

The short version:

  • Event: Pwn2Own Ireland 2026, organized by Trend Micro's Zero Day Initiative (ZDI) in Cork, Ireland, October 6–9, 2026.
  • Galaxy S26 was successfully exploited 3 times on Day One and 3 times on Day Two — six total, by six different entries.
  • Day One's biggest single payout against the S26 was $31,250 (Viettel Cyber Security); Day Two's was $8,500 (KAIST Hacking Lab).
  • ZDI has not published a Day Three / Master of Pwn results post as of this writing, so no overall contest winner has been named yet.
  • Samsung is a standing target in Pwn2Own's contest rules, meaning any bugs used get reported to Samsung so they can be patched before public disclosure.

What happened to the Galaxy S26 at Pwn2Own Ireland 2026

Pwn2Own Ireland 2026 is ZDI's annual live hacking competition, where invited security researchers and teams attempt pre-registered, single-chained exploit attempts against a published list of consumer and enterprise devices on stage, live, in front of judges. This year's device categories include Mobile Phones, Smart Home Devices, Wellness, Printers, Messaging, AI Infrastructure and AI Coding Agents. The Samsung Galaxy S26 was one of the Mobile Phones category targets, alongside the Google Pixel 10 — and it was the phone that fell the most often.

Across the contest's first two days, ZDI's own results posts confirm six separate successful demonstrations against the Galaxy S26, each one a distinct entry by a distinct team, each one verified live on stage and then reported to Samsung under ZDI's responsible-disclosure rules.

Day One, October 6: three teams break the S26

According to ZDI's Day One results post, three entries against the Galaxy S26 succeeded:

  • Viettel Cyber Security (Nguyen Thanh Dat, @rewhiles, @vcslab) chained 4 bugs — ZDI notes 3 of the 4 were already known to the vendor — for a $31,250 payout and 3.25 Master of Pwn points.
  • Interrupt Labs used 4 bugs as well: 3 were collisions with previously reported issues and 1 was a genuine zero-day. The entry earned $15,750 and 3.25 points.
  • Ikotas Labs, Inc. used a 4-bug chain in which one bug was already known to Samsung but still unpatched at the time of the demo, which still qualified for an award: $11,000 and 4.5 Master of Pwn points — the highest point total of the three Day One S26 entries.

ZDI's Day One recap also lists successful entries against the Sonos Era 300, a Lexmark CX532adwe printer, the Philips Hue Bridge Pro, a Garmin Index BPM, an Oracle Autonomous AI Database and OpenAI Codex, alongside some failed attempts — including one against the Pixel 10, the S26's fellow mobile target that day.

Day Two, October 7: three more exploits land

The Galaxy S26 did not get a reprieve on Day Two. Per ZDI's Day Two results post, three more entries succeeded against the same phone:

  • Dimitrios Valsamaras, Ken Gannon and Tenia Valsamara — representing Mobile Hacking Lab and CENSUS Labs and using a tool the team calls Djini.ai — landed a single bug described by ZDI as a Confused Deputy flaw, tracked under CWE-441. Unlike the other five S26 entries, ZDI's results page does not list a specific cash figure for this one, only that the demo succeeded.
  • Kyeongmin Kim of KAIST Hacking Lab combined 1 unique bug with 2 collisions (3 bugs total) in a remote attack, earning $8,500 and 3.5 Master of Pwn points.
  • PetoWorks chained 3 bug collisions in a remote attack for a net $6,250 and 2.5 points.

A Confused Deputy bug, in general terms, is one where a piece of software with elevated privileges can be tricked by a lower-privileged party into carrying out an action the lower-privileged party was never supposed to be allowed to trigger — the kind of logic flaw that can turn an ordinary app permission into a path for unauthorized access.

Day Two also saw repeat targets fall for other devices, including five successful attempts against a Home Assistant Green hub and a $40,000 win against the "Dynamo" target, but the Galaxy S26 stayed the single most-attacked phone of the two days.

Taken together, the six Galaxy S26 entries used a mix of genuinely new findings and bug collisions — cases where more than one independent team happened to land on the same underlying flaw. Of the entries where ZDI explicitly characterized the bugs, Interrupt Labs' chain is the one confirmed to include a brand-new zero-day; the rest were either partial or full collisions with issues Samsung already knew about, including at least one that ZDI says was still unpatched at the time it was demonstrated again on stage.

Galaxy S26 Pwn2Own results, entry by entry

DayTeamBugs usedAwardMaster of Pwn points
Day OneViettel Cyber Security4 (3 known to vendor)$31,2503.25
Day OneInterrupt Labs4 (3 collisions, 1 zero-day)$15,7503.25
Day OneIkotas Labs, Inc.4 (1 known, unpatched)$11,0004.5
Day TwoValsamaras / Gannon / Valsamara (Mobile Hacking Lab, CENSUS Labs)1 (Confused Deputy, CWE-441)Not listedNot listed
Day TwoKyeongmin Kim (KAIST Hacking Lab)3 (1 unique, 2 collisions)$8,5003.5
Day TwoPetoWorks3 collisions$6,250 (net)2.5

Other devices researchers broke into the same week

The Galaxy S26 wasn't the only target to fall. ZDI's Day One post also lists successful entries against the Sonos Era 300 speaker, a LiteLLM deployment, a Lexmark CX532adwe printer, the Philips Hue Bridge Pro, a Garmin Index BPM smart scale, an Oracle Autonomous AI Database instance and OpenAI Codex, alongside failed attempts against a Brother MFC-L8970CDW printer, a second Lexmark CX532adwe entry, a Garmin Index BPM entry from the Summoning Team, the Google Pixel 10 and a Chroma target.

Day Two was even busier for non-phone targets. ZDI recorded five separate successful attacks on a Home Assistant Green hub — by Yves Bieri of Xint, Yassine Bengana and Maxence Schmitt of Doyensec, Kyeongmin Kim's KAIST team, PetoWorks and the researcher known as @_McCaulay — with rewards ranging from $4,750 to $30,000 per entry. A target ZDI calls "Dynamo" fell to HaeJung Yang of Out of Bounds for $40,000 and 4 Master of Pwn points, the single largest payout either day. The Oracle Autonomous AI Database was hit twice more, by Taisic Yun of Xint ($14,000) and by Ikotas Labs ($10,000, the same team that broke the Galaxy S26 on Day One). The Sonos Era 300 fell three more times, to Jack Dates of RET2 Systems, to Viettel Cyber Security researchers Nguyen Thanh Dat and dungnm, and to Sina Kheirkhah of Summoning Team. Lexmark's printer, a Chroma target and a Canon imageFORCE 1643F also had successful entries, while Brother's printer, Chroma and a second Home Assistant Green attempt (by Shio Kudo of GMO Flatt Security) held up against their respective challengers.

Why the same phone can be "hacked" six times

It can look strange that one device gets broken into by six different teams in two days, but that is how Pwn2Own is designed to work. Every registered entry targets the device fresh, usually by chaining together several individual bugs of its own choosing. When two teams happen to use the same underlying flaw, ZDI calls it a "collision" — it still counts as a successful demonstration, but it pays out less than a bug nobody has reported before, because the point of the contest is to surface new, unknown issues a vendor can fix. That is why Interrupt Labs' single zero-day earned it more per-bug recognition than Viettel's mostly-already-known chain, even though Viettel's total payout was higher thanks to the overall bounty table for that bug class.

Master of Pwn points work on a separate running scoreboard: they are what determines the contest's overall champion once every category and day is finished, independent of the dollar amount paid for any individual bug.

Has Samsung responded, and should Galaxy S26 owners be worried

Samsung has not issued a public statement about the specific Pwn2Own Ireland 2026 results as of this writing. That is normal at this stage: ZDI's contest rules require every working exploit to be privately disclosed to the affected vendor immediately after a successful demonstration, with the vendor then given time to investigate and ship a fix before any technical details are published. None of ZDI's results posts include exploit code, affected component names, or enough detail for anyone outside Samsung to reproduce the attacks.

For everyday Galaxy S26 owners, the practical takeaway is the same one that applies after every Pwn2Own event: keep automatic software updates turned on so the eventual Samsung security patch reaches the device as soon as it ships, and watch for it to land through the same channel Samsung uses for its regular One UI update rollout. None of the six entries described by ZDI indicate active, in-the-wild exploitation — these were controlled, invitation-only demonstrations, not attacks found on real users' phones. Still, the volume of successful attempts is a reminder that high-end phone security is an ongoing arms race rather than a solved problem, a point that also runs through plenty of unrelated incidents, such as the recently disclosed Arizona Supreme Court data breach, where the attack surface was a court system rather than a device.

The bigger event: Pwn2Own Ireland 2026

Pwn2Own Ireland 2026 runs October 6–9, 2026, in Cork, Ireland, and is organized by Trend Micro's Zero Day Initiative. ZDI's own announcement describes this year's lineup as spanning seven target categories: Mobile Phones, Smart Home Devices, Wellness, Printers, Messaging, AI Infrastructure and AI Coding Agents — a sign of how far the contest has expanded beyond the traditional consumer-electronics targets it started with. Registration for entries closed at 5:00 p.m. Irish Standard Time on October 1, 2026, meaning every team on stage this week had already locked in its target and submitted its exploit plan for review well before the Galaxy S26 was ever touched.

The contest's top overall scorer across every category and day is crowned "Master of Pwn," a title tied to a running points race worth up to 65,000 ZDI reward points at stake this year according to ZDI's announcement post. As of this writing, ZDI has published results for Day One and Day Two only; no Day Three or Master of Pwn wrap-up post is live yet, so the final standings, the overall champion and the event's total payout are not yet confirmed. ZDI's own announcement post also notes that the venue for a future Pwn2Own contest has not yet been revealed, saying only to "stay tuned" for that news.

What's next

Watch ZDI's own blog for the Day Three and Master of Pwn wrap-up posts, which should confirm the contest's final tally and crown an overall winner. Separately, keep an eye on Samsung's security update channel for the maintenance release that eventually patches whichever of these six bug chains Samsung chooses to fix first — ZDI's disclosure rules give Samsung a window to patch before any technical write-up becomes public, so specifics on the actual vulnerabilities are unlikely to surface for some time yet.

Frequently asked questions

Was the Samsung Galaxy S26 actually hacked at Pwn2Own Ireland 2026?

Yes. Trend Micro's Zero Day Initiative (ZDI) confirmed six separate successful exploit demonstrations against the Galaxy S26 across Day One (three) and Day Two (three) of Pwn2Own Ireland 2026, held October 6-9, 2026 in Cork, Ireland.

Who hacked the Galaxy S26 at Pwn2Own Ireland 2026?

On Day One: Viettel Cyber Security, Interrupt Labs, and Ikotas Labs, Inc. On Day Two: Dimitrios Valsamaras, Ken Gannon and Tenia Valsamara (Mobile Hacking Lab/CENSUS Labs), Kyeongmin Kim of KAIST Hacking Lab, and PetoWorks.

How much money did researchers earn for hacking the Galaxy S26?

Confirmed payouts were $31,250 (Viettel Cyber Security), $15,750 (Interrupt Labs) and $11,000 (Ikotas Labs, Inc.) on Day One, plus $8,500 (Kyeongmin Kim) and a net $6,250 (PetoWorks) on Day Two. ZDI's results page does not list a specific dollar figure for the Mobile Hacking Lab/CENSUS Labs entry.

Is it safe to keep using a Galaxy S26 after these hacks?

ZDI's disclosure rules require every working exploit to be reported privately to Samsung before any technical details are published, and none of the six demonstrations represent in-the-wild attacks on real users. The practical advice is the same as always: keep automatic updates on so Samsung's eventual security patch installs as soon as it is released.

What is Pwn2Own Ireland 2026?

It is Trend Micro's Zero Day Initiative live hacking contest, held October 6-9, 2026 in Cork, Ireland, covering seven target categories this year: Mobile Phones, Smart Home Devices, Wellness, Printers, Messaging, AI Infrastructure and AI Coding Agents.

Has a Master of Pwn winner been announced for Pwn2Own Ireland 2026?

No. As of this writing, ZDI has only published Day One and Day Two results. No Day Three or Master of Pwn wrap-up post has gone live yet, so the event's final standings and overall champion are not yet confirmed.

Sources

More on Galaxy S26 →Galaxy S26Pwn2Own Ireland 2026SamsungZero Day InitiativeMobile SecurityZDI
Nadia Osei
Written byNadia Osei

Nadia Osei covers mobile and consumer gadgets for Pandromeda: smartphones, tablets, smartwatches, earbuds and smart-home devices. She tracks launches, software updates and pricing across Apple, Google, Samsung and the rest, and builds comparisons from the manufacturers' published specifications.

More from Mobile & Gadgets

See all