Hackers Exploited 73 0-Day Vulnerabilities and Earned $1,024,750
The Pwn2Own Ireland 2025 event concluded successfully, showcasing significant advancements in hacking capabilities. During the competition, participants identified 73 unique zero-day vulnerabilities across various devices.
The Pwn2Own Ireland 2025 event concluded successfully, showcasing significant advancements in hacking capabilities. During the competition, participants identified 73 unique zero-day vulnerabilities across various devices.
The Zero Day Initiative (ZDI) hosted the event, distributing a total of $1,024,750 in prizes, reflecting the increasing complexity of cybersecurity threats and defenses.
Over three days, 56 vulnerabilities were rewarded, with participants focusing on smart home gadgets, printers, and mobile devices. The event encouraged vendor collaboration, with companies like Meta, Synology, and QNAP supporting the initiative.
Chris Anastasio of Team Cluck earned $20,000 for exploiting a type confusion vulnerability in the Lexmark CX532adwe printer. Ben R. and Georgi G. from Interrupt Labs won $50,000 for discovering a flaw in the Samsung Galaxy S25, enabling unauthorized access to the camera and location tracking. Xilokar utilized multiple bugs to compromise the Philips Hue Bridge, securing $17,500. Sina Kheirkhah of the Summoning Team exploited QNAP TS-453E for $20,000. David Berard from Synacktiv earned $30,000 for his dual-bug attack on the Ubiquiti AI Pro surveillance camera.
Several attempts did not succeed, highlighting the complexity and high stakes of the competition. Withdrawals included CyCraft Technology's and Team Z3's entries, emphasizing the rigorous preparation required.
The Summoning Team secured the Master of Pwn title, demonstrating exceptional preparation and skill across multiple categories. The event facilitated responsible disclosure of vulnerabilities, enhancing overall digital security.
The Pwn2Own Ireland 2025 event concluded successfully, showcasing significant advancements in hacking capabilities.
Researcher/Team Target Device Vulnerabilities Exploited Prize Master of Pwn Points Notes
Xilokar Philips Hue Bridge Authentication bypass, underflow, plus two others $17,500 3.5 Partial collision
Chris Anastasio (Team Cluck) Lexmark CX532adwe Printer Type confusion $20,000 2 Full success
Ben R. and Georgi G. (Interrupt Labs) Samsung Galaxy S25 Improper input validation $50,000 5 Enabled camera and location tracking
David Berard (Synacktiv) Ubiquiti AI Pro Pair of bugs $30,000 3 Included "Baby Shark" demo
Sina Kheirkhah (Summoning Team) QNAP TS-453E Hard-coded credentials, injection $20,000 4 Full success
The next event, Pwn2Own Automotive, is scheduled in Tokyo from Jan 21-23, 2026, expanding to include EV chargers and other categories. These events are crucial for enhancing global digital security through the identification and disclosure of new vulnerabilities.
Based on reporting by Cyber Security News.
