IoT Security

Hackers Earn $400k on First Day at Pwn2Own Toronto 2023

NAS devices, printers, IP cameras, speakers, and mobile phones were hacked on the first day at Pwn2Own Toronto 2023.

NAS devices, printers, IP cameras, speakers, and mobile phones were hacked on the first day at Pwn2Own Toronto 2023.

The Pwn2Own Toronto 2023 hacking contest kicked off yesterday and participants successfully hacked NAS, printers, mobile phones, and other types of devices, earning a total of more than $400,000 on the first day.

The highest reward of the day went to team Orca of Sea Security, which executed a two-vulnerability exploit chain (out-of-bounds read and use-after-free) against the Sonos Era 100 speaker, earning $60,000.

The Pentest Limited team earned the second highest reward of the day, at $50,000, for an improper input validation exploit targeting the Samsung Galaxy S23 mobile phone.

The team also earned a $40,000 reward for a two-bug exploit chain (denial-of-service and server-side request forgery) leading to the compromise of Western Digital’s My Cloud Pro Series PR4100 network-attached storage (NAS) product.

Two other $40,000 rewards were earned for exploits targeting the Xiaomi 13 Pro mobile phone (team Viettel – single-bug exploit) and the QNAP TS-464 NAS device (team ECQ – a three-bug exploit chain involving a server-side request forgery and two injection flaws).

Vulnerabilities in the Synology BC500 IP camera were also exploited on the first day of the contest, with hackers earning roughly $50,000 for the exploits.

Advertisement. Scroll to continue reading.

Additional exploits targeting the Xiaomi 13 Pro and the Samsung Galaxy S23 were demonstrated as well and earned the hacking teams more than $40,000 in rewards.

The participating teams and individual hackers also pwned the Canon imageCLASS MF753Cdw and the Lexmark CX331adwe printers, earning more than $60,000 for their exploits.

According to ZDI, not all the exploits demonstrated on the first day of Pwn2Own Toronto 2023 were new, but participants still earned lower-tier rewards for their efforts.

The hacking competition will continue until Friday, with exploits to be demonstrated in the NAS devices, smart speakers, printers, mobile phones, and surveillance systems categories.

Missing from the contest are smart vehicles, which will be present at Pwn2Own Automotive, set to be hosted at the Automotive World conference, in January 2024, in Tokyo, Japan. It will be the first Pwn2Own competition dedicated to automotive.

Related: Mikrotik Belatedly Patches RouterOS Flaw Exploited at Pwn2Own

Related: VMware Patches Critical Vulnerability Disclosed at Pwn2Own Hacking Contest

Related: ZDI Discusses First Automotive Pwn2Own

Related Content

Artificial Intelligence

Participants demonstrated exploits for Windows, Linux, VMware, Nvidia, and AI products.

Vulnerabilities

Pwn2Own participants disclosed a total of 76 vulnerabilities during the three-day event. 

Vulnerabilities

Multiple vulnerabilities across QNAP’s portfolio could lead to remote code execution, information disclosure, and denial-of-service (DoS) conditions.

Vulnerabilities

WhatsApp told SecurityWeek that the two low-impact vulnerabilities cannot be used for arbitrary code execution. 

IoT Security

Participants exploited 34 previously unknown vulnerabilities to hack printers, NAS devices, and smart home products.

IoT Security

Set for January 2026 at Automotive World in Tokyo, the contest will have six categories, including Tesla, infotainment systems, EV chargers, and automotive OSes.

Vulnerabilities

Meta is sponsoring ZDI’s Pwn2Own hacking competition, where participants can earn big prizes for smartphone, WhatsApp and wearable device exploits.

Vulnerabilities

Four CVEs disclosed at the Pwn2Own Berlin 2025 hacking competition have been patched in VMware products.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version