Three teams broke into a fully patched Pixel 10. The iPhone 17 went untouched.
The contest that took apart a Philips Hue bridge before lunch on Tuesday wrapped up in Cork on Thursday. Final tally: 1,262,000 dollars handed over for 98 separate zero-day flaws, across 29 research teams.
The last day belonged to Google's Pixel 10. Three teams broke into one remotely, meaning through a browser or over NFC, Wi-Fi, Bluetooth or the cellular baseband rather than with the phone in hand. Ikotas Labs chained several bugs together for 300,000 dollars and took the Master of Pwn title with 361,000 dollars across four wins. Xint earned 150,000, and the team of Dimitrios Valsamaras, Ken Gannon and Tenia Valsamara 112,500. Samsung's Galaxy S26 fell six times over the week. Apple's iPhone 17 was the one target nobody managed, despite a 300,000 dollar prize sitting on it.
The rest of the list is the stuff in ordinary homes. A Sonos Era 300 went down in under a minute to Jack Dates of RET2 Systems. Interrupt Labs got a Lexmark printer running DOOM on its own control panel. Team MAMMOTH closed the event by stringing six zero-days together against a Home Assistant Green hub. Every device was running current firmware when it was attacked, which is the entire point of the exercise.
Vendors get 90 days before the technical details go public, so the fixes will turn up in routine updates between now and January, mostly without announcement. Worth knowing what is actually sitting on your network before then. Tendvane's network scan lists every device connected to your router, including the ones you had forgotten were there.