Google Pixel 10 Hacked Three Times at Pwn2Own, Researchers Win $562,500

Abeerah Hashim  - Security Expert
Last updated: October 9, 2026
Share
Google Pixel 10 Hacked Three Times at Pwn2Own, Winning Teams $562,500
  • Three teams broke into a fully patched Google Pixel 10 on October 8 at Pwn2Own Ireland. Together they earned $562,500.
  • Ikotas Labs won the top prize of $300,000 and emerged the overall winner. Its Pixel entry was labeled a collision, which means it used a bug already known.
  • No one has shared how the attacks worked. Google has yet to list a fix or action for Pixel owners.

Hackers got into Google’s newest flagship phone three times on Thursday. The break-ins happened at Pwn2Own Ireland, a contest in Cork run by Trend Micro’s Zero Day Initiative, or ZDI.

The contest pays researchers to show real attacks on up-to-date devices. The flaws are then passed to the makers so they can fix them. Pwn2Own ran from October 6 to October 9. The event recorded three successful remote hacks of Google’s Pixel 10. According to ZDI’s official results, the three entries earned $562,500 in total.

The three successful attacks on Pixel 10

The teams earned different rewards based on their results and the bugs involved. Xint went first. Tim Becker and Yves Bieri used what ZDI called a single bug collision. They earned $150,000 and 15 points. That is half the listed prize. ZDI first announced the win before setting the final amount.

Ikotas Labs went second. ZDI said the team chained multiple issues together. The results label the entry a collision, yet the team received the full $300,000 and 30 points. ZDI has not explained why.

Dimitrios Valsamaras, Ken Gannon and Tenia Valsamara went third. They chained two bugs. One was a collision. The other was a zero-day, meaning a flaw the maker did not know about. They earned $112,500 and 22.5 points.

All three entries were listed as remote attacks. Under the rules, that means breaking in through a web page opened in the phone’s default browser or using NFC, Wi-Fi, Bluetooth or the phone’s cellular chip. A winning entry must run code the attacker chooses on the phone or retrieve sensitive data. Which route each team used is not public.

Three of four remote tries on the Pixel 10 worked. The failed one came on day one. A team called White Noise Club ran out of time before its exploit worked.

Contest rules require bugs that are unknown to the vendor and to ZDI. A bug that is already known is called a collision. Those entries are still acceptable, but at a lower price.

That was the pattern on Samsung’s Galaxy S26 earlier in the week. Interrupt Labs used four bugs, three of them collisions, and earned $15,750. Ikotas Labs used four bugs on the S26, one known to Samsung but still unpatched. It earned $11,000.

Against that backdrop, the full $300,000 paid to Ikotas Labs for the Pixel stands out. At least two of the three Pixel wins relied on a known bug.

Google to release disclosure and corresponding patches 

Winning teams hand their exploits and write-ups to ZDI. ZDI passes the bugs to the vendors. According to Trend Micro’s explanation process, Vendors then get 90 days to release patches before ZDI publishes full technical details. That points to roughly early January.

Google’s October Pixel security bulletin came out on October 6, two days before the Pixel 10 attacks. It does not mention the contest. ZDI’s results list no fix and no steps for Pixel owners. The usual advice still applies: install updates when Google sends them.

Other technology providers have also urged users to update their software after fixing security flaws, including Plex, which urged users to update after patching previously undisclosed security flaws.

Separately, Google patched a Pixel modem flaw in September. Tracked as CVE-2026-58704, it “may be under limited, targeted exploitation,” according to Google. Phones with a patch level of 2026-09-05 or later have that fix.

Galaxy S26 and other devices fall

Samsung’s Galaxy S26 fell in all seven attempts made on it. Six of the seven winning entries included at least one collision. ZDI said one bug in the chain Ikotas Labs used on day one was known to Samsung but not yet fixed.

Ikotas Labs earned the title Master of Pwn, given to the contestant with the most points. Its four wins total $361,000 and 42.5 points. They included OpenAI’s Codex coding agent and, on day two, Oracle’s Autonomous AI Database.

Researchers also broke into Lexmark, Canon and Brother printers. They hacked three smart home devices: the Sonos Era 300, Philips Hue Bridge Pro, and Home Assistant Green. They also got into the Garmin Index BPM, a wellness device.

Every product on the schedule was exploited at least once. Of 63 scheduled attempts, 51 succeeded. The schedule listed no attempt on Apple’s iPhone 17 or on WhatsApp. Each carried a top prize of $300,000.

ZDI’s posted awards for the three days top $1.2 million. Last year’s Ireland contest paid $1,024,750. Phones drew extra attention this time. ZDI’s Dustin Childs wrote ahead of the event that “we’ve never had so many attempts on phones.”

The big unknown is how the Pixel attacks worked. ZDI has not said, and it will likely stay quiet until vendors have had their 90 days. Google’s October bulletin makes no mention of the contest. Watch for its November and December bulletins, which may show whether fixes are on the way.

Share this article

About the Author

Abeerah Hashim

Abeerah Hashim

Security Expert

Abeerah is a passionate technology blogger and cybersecurity enthusiast. She yearns to know everything about the latest technology developments. Specifically, she’s crazy about the three C’s; computing, cybersecurity, and communication. When she is not writing, she’s reading about the tech world.

More from Abeerah Hashim

Comments

No comments.