Zero Day Initiative said day one of Pwn2Own Ireland 2026 produced 32 zero-day disclosures and more than $368,000 in prize money, with targets spanning smartphones, smart home gear, printers, and AI tools such as OpenAI Codex and LiteLLM. The first-day list also included successful hits on Sonos Era 300, Philips Hue Bridge Pro, Lexmark CX532adwe, Oracle Autonomous AI Database, and Garmin Index BPM.
The AI-tool wins were straightforward trust-boundary failures: Ikotas Labs said a single argument injection bug was enough to exploit OpenAI Codex, and Xint used improper input validation plus code injection to get a reverse shell on LiteLLM. That matters because once a tool treats attacker-controlled input as something it can act on, it can move from answering prompts to running code.
The broader signal is where contest attention is landing. If your environment uses assistants or automation that accept untrusted prompts or arguments and can take actions, these results show that AI tooling and consumer devices are already yielding high-impact bugs quickly, not just isolated crashes.
Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days.