Vulnerabilities

Infotainment, EV Charger Exploits Earn Hackers $1M at Pwn2Own Automotive 2026

Pwn2Own participants disclosed a total of 76 vulnerabilities during the three-day event. 

Hacking competition

White hat hackers earned $1,047,000 for 76 unique vulnerabilities at Pwn2Own Automotive 2026, the automotive-focused hacking competition organized this week by Trend Micro’s Zero Day Initiative (ZDI) in Japan. 

The winner of the event, the Fuzzware.io team, earned a total of $215,500 for its exploits. The team received the highest individual reward: $60,000 for an Alpitronic HYC50 EV charger exploit delivered through the charging gun. ZDI described it as “the first public exploit of a supercharger”.

Hacks targeting Autel and Phoenix Contact EV chargers earned Pwn2Own Automotive 2026 participants $50,000 each. 

Exploits aimed at ChargePoint, Alpitronic, and Grizzl-E chargers earned $40,000 each.

One noteworthy exploit involved chaining three vulnerabilities to hack Automotive Grade Linux, earning a researcher $40,000. 

Another exploit highlighted by ZDI targeted Tesla’s infotainment system. Researchers received $35,000 for a full hack executed by simply plugging in a USB stick.

Advertisement. Scroll to continue reading.

Sony, Kenwood, and Alpine infotainment system, and Alpitronic, Grizzl-E, Autel, Phoenix Contact, and ChargePoint charger exploits earned researchers thousands and even tens of thousands of dollars.

At last year’s Pwn2Own Automotive, participants received a total of $886,000.

Related: QNAP Patches Vulnerabilities Exploited at Pwn2Own Ireland

Related: $1M WhatsApp Hack Flops: Only Low-Risk Bugs Disclosed to Meta After Pwn2Own Withdrawal

Related: VMware Flaws That Earned Hackers $340,000 at Pwn2Own Patched

Related: Hackers Earn Over $1 Million at Pwn2Own Berlin 2025

Related Content

ICS/OT

A researcher has explained how an attacker could exploit these vulnerabilities to target industrial organizations.

Artificial Intelligence

AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization.

Vulnerabilities

The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations.

Vulnerabilities

An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts.

Vulnerabilities

CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access.

Vulnerabilities

Many of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI.

Artificial Intelligence

The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models.

Vulnerabilities

A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version