Vulnerabilities

Over $380,000 Paid Out on First Day of Pwn2Own Automotive 2025

$380,000 paid out on the first day of Pwn2Own Automotive 2025 for exploits targeting car infotainment units, operating systems, and chargers. 

Pwn2Own Automotive 2025

Trend Micro’s Zero Day Initiative (ZDI) has announced the results from the first day of the Pwn2Own Automotive 2025 hacking contest taking place this week in Tokyo alongside the Automotive World conference. 

On the first day of Pwn2Own Automotive 2025, participants earned a total of $382,750 for 16 unique zero-day vulnerabilities affecting infotainment systems, electric vehicle (EV) chargers, and automotive operating systems. 

The biggest rewards — $50,000 each — were given out for exploits targeting Autel and Ubiquiti EV chargers. A Phoenix Contact charging controller exploit earned $41,750 and a ChargePoint charger exploit earned $47,500. Other Autel and Phoenix Contact charger exploits were rewarded with $25,000 each. 

An exploit targeting Automotive Grade Linux, which included a previously known vulnerability, earned participants $33,500.

$20,000 were earned by Pwn2Own participants who hacked Alpine, Kenwood and Sony in-vehicle infotainment products. 

Nearly two dozen more attempts are scheduled for the next two days at Pwn2Own Automotive 2025. They will target chargers and infotainment systems.

Advertisement. Scroll to continue reading.

There will be no attempts to target a Tesla vehicle, for which the organizers had been prepared to reward participants with a car and up to $500,000 in cash for an autopilot exploit.

At last year’s Pwn2Own Automotive, participants earned a total of $1.3 million for exploits targeting Teslas, EV chargers and infotainment systems.

Related: Details Disclosed for Mercedes-Benz Infotainment Vulnerabilities

Related: Over $1 Million Paid Out at Pwn2Own Ireland 2024

Related: Synology, QNAP, TrueNAS Address Vulnerabilities Exploited at Pwn2Own Ireland

Related Content

Artificial Intelligence

Participants demonstrated exploits for Windows, Linux, VMware, Nvidia, and AI products.

Vulnerabilities

Pwn2Own participants disclosed a total of 76 vulnerabilities during the three-day event. 

Vulnerabilities

Multiple vulnerabilities across QNAP’s portfolio could lead to remote code execution, information disclosure, and denial-of-service (DoS) conditions.

Vulnerabilities

WhatsApp told SecurityWeek that the two low-impact vulnerabilities cannot be used for arbitrary code execution. 

Mobile & Wireless

Questions have been raised over the technical viability of the purported WhatsApp exploit, but the researcher says he wants to keep his identity private.

IoT Security

Participants exploited 34 previously unknown vulnerabilities to hack printers, NAS devices, and smart home products.

IoT Security

Set for January 2026 at Automotive World in Tokyo, the contest will have six categories, including Tesla, infotainment systems, EV chargers, and automotive OSes.

Vulnerabilities

Meta is sponsoring ZDI’s Pwn2Own hacking competition, where participants can earn big prizes for smartphone, WhatsApp and wearable device exploits.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version