IoT Security

Hackers Earn Over $520,000 on First Day of Pwn2Own Ireland 2025

Participants exploited 34 previously unknown vulnerabilities to hack printers, NAS devices, and smart home products.

Pwn2Own Ireland 2025

On the first day of the Pwn2Own Ireland 2025 hacking contest organized by Trend Micro’s Zero Day Initiative (ZDI), participants earned a total of $522,500 for the exploits they demonstrated.

A total of 34 previously unknown vulnerabilities have been exploited to hack printers, network-attached storage (NAS) devices, routers, and smart home products.

The largest reward, $100,000, was awarded in the ‘SOHO Smashup’ category, which combines exploits targeting two different types of devices. Researchers chained exploits targeting the QNAP Qhora-322 router and the QNAP TS-453E NAS device. 

Another significant reward, $50,000, was paid out for a Synology ActiveProtect Appliance DP320 exploit. The same amount was also earned for a Sonos Era 300 smart speaker hack. 

Other NAS device exploits, targeting Synology and QNAP products, earned researchers $40,000 each.

ZDI rewarded vulnerabilities in the Home Assistant Green home automation device with $40,000, $20,000, and $12,500. Phillips Hue Bridge exploits earned participants $40,000 and $20,000. 

Advertisement. Scroll to continue reading.

Hacking Canon and HP printers earned researchers $20,000 and $10,000.

Pwn2Own Ireland 2025 will continue until Thursday, when a researcher is scheduled to demonstrate a zero-click remote code execution exploit against WhatsApp in hopes of winning $1 million. 

A total of more than $1 million was awarded at Pwn2Own Ireland 2024 for camera, printer, NAS device, smart speaker and smartphone exploits.

Related: Over $3 Million in Prizes Offered at Pwn2Own Automotive 2026

Related: $4.5 Million Offered in New Cloud Hacking Competition

Related: VMware Flaws That Earned Hackers $340,000 at Pwn2Own Patched

Related Content

Vulnerabilities

Exploiting a race condition in Microsoft Defender, the exploit leads to local privilege escalation to SYSTEM.

Artificial Intelligence

Public LLM models with safeguards turned off can also build working exploits, increasing patch gap risks.

Vulnerabilities

The one-click vulnerability allows attackers to execute arbitrary code on self-hosted Flowise servers by tricking users into importing a malicious chatflow.

Vulnerabilities

The researcher dropped the MiniPlasma exploit that uses the original proof-of-concept (PoC) code targeting the bug.

Artificial Intelligence

Participants demonstrated exploits for Windows, Linux, VMware, Nvidia, and AI products.

Vulnerabilities

Introduced in 2008, the critical-severity security defect was patched this week in NGINX Plus and NGINX open source.

Artificial Intelligence

The zero-day was designed to bypass 2FA and it was developed by a prominent cybercrime group.

Mobile & Wireless

Targeting six iOS vulnerabilities and leading to full device compromise, the exploit chain is meant for surveillance.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version