← All posts / Tools

Five AI Targets, Five Falls: Pwn2Own Ireland Puts the AI Stack on the Hacking Stage

At Pwn2Own Ireland in Cork, researchers collected $388,500 and 32 zero-days on day one alone — and every AI Infrastructure target from OpenAI Codex to LiteLLM, Chroma, Dynamo and Oracle's Autonomous AI Database fell to attack.

Five AI Targets, Five Falls: Pwn2Own Ireland Puts the AI Stack on the Hacking Stage

CORK, IRELAND — The world’s most prestigious hacking competition has a new favorite target, and it is the plumbing of the AI boom. On day one of Pwn2Own Ireland 2026, which kicked off October 6 in Cork, researchers demonstrated 32 unique zero-day vulnerabilities and walked away with $388,500 in bounties. The most consequential wins didn’t involve phones or printers at all: they came in the event’s AI Infrastructure category, where OpenAI’s Codex coding agent, the LiteLLM gateway, the Chroma vector database, NVIDIA’s Dynamo inference server, and Oracle’s Autonomous AI Database were all successfully compromised in front of a live audience.

Run by TrendAI’s Zero Day Initiative (ZDI), Pwn2Own Ireland is the second outing this year for the AI Infrastructure category, after its debut at Pwn2Own Berlin earlier in 2026. In Cork the category pays $40,000 and 4 Master of Pwn points for a clean full win — the same bounty tier as a remote Samsung Galaxy S26 exploit — a pricing decision that says plainly what ZDI thinks the attack surface of 2026 looks like.

Codex falls to a single bug

The most talked-about result of the competition so far is also one of the simplest. Ikotas Labs exploited OpenAI Codex — the agentic coding tool millions of developers now run against their own repositories — using a single argument injection bug, earning $40,000 and 4 Master of Pwn points. It was Ikotas Labs’ second win of the day, after an earlier collision-winning chain against the Samsung Galaxy S26.

The elegance is the point. Coding agents like Codex are built to interpret instructions and execute tool calls — shells, file edits, package installs — often with broad access to a developer’s environment. An argument injection in that context isn’t a theoretical flaw; it is a direct path from untrusted input to code execution inside the exact machine that holds your source code and credentials. Security researchers have spent two years warning that agentic AI tools blur the line between “assistant” and “arbitrary code runner.” At Pwn2Own, that warning stopped being hypothetical.

LiteLLM’s rough day — twice over

If Codex was the headline, LiteLLM was the subplot. The open-source LLM gateway, which sits in front of model APIs at a large share of enterprise AI deployments and enforces keys, routing, and budgets, was attacked twice on day one — and fell both times.

First, Taisic Yun of team Xint used an improper input validation bug chained with code injection to land a reverse shell on LiteLLM, taking the full $40,000 pot and 4 points. Hours later, HaeJung Yang and ByungYoung Yi of Out of Bounds exploited LiteLLM again with a four-bug chain (two of which were already known to the vendor), netting a $15,000 partial award. A gateway that terminates a reverse shell is a gateway that no longer enforces anything — keys, quotas, or model access — for every client behind it.

The rest of the AI Infrastructure board filled in quickly. VinSOC’s Nam Nguyen, Thanh Vu, and Tin Huynh combined five bugs to compromise Oracle’s Autonomous AI Database for $40,000. On day two, HaeJung Yang of Out of Bounds returned to take down Dynamo, NVIDIA’s open-source inference serving framework, for another $40,000 — a rare double for a researcher across two targets in the same category. Team MAMMOTH (a seven-person squad from South Korea) cracked the Chroma vector database with a chain containing one unique zero-day, and Alessandro Fanio Gonzalez added another partial win against Chroma, closing out a board on which, by the end of day two, no AI category target had survived.

The wider carnage

The AI targets were only part of the story. Day one’s 32 zero-days also took down the Samsung Galaxy S26 three times (Viettel Cyber Security, Interrupt Labs, and Ikotas Labs all claimed bounties), the Sonos Era 300 speaker via an out-of-bounds write chained with a format string bug (McCaulay Hudson, $50,000), and the Philips Hue Bridge Pro via an astonishing seven zero-day chain from VinSOC’s Vũ Chí Thành and Huỳnh Đức Tin, worth $40,000.

Day two kept the pace with roughly $780,000 on the table across 24 attempts. Home Assistant Green — the open-source smart home hub — proved the day’s most besieged device, falling to Xint’s Yves Bieri ($30,000), PetoWorks, Kyeongmin Kim of KAIST Hacking Lab, and McCaulay Hudson in a six-bug chain. The Samsung Galaxy S26 fell three more times, including a remote exploit by KAIST’s Kyeongmin Kim using a single unique bug and a “Confused Deputy” (CWE-441) attack from the Valsamaras/Gannon/Djini.ai/Valsamara entry. Printers, as ever, died loudly: the Lexmark CX532adwe was exploited at least four separate times, and McCaulay Hudson took a Canon imageFORCE 1643F using a chain that included hard-coded credentials, missing authentication on a critical function, and command injection — a bug trilogy that reads like a 2010-era advisory, in 2026 office hardware.

ZDI says this edition has more phone entries than any Pwn2Own in history and more than 60 total attempts across three days, with the final day running October 8.

Why this matters beyond Cork

Three takeaways stand out for anyone building on or securing the AI stack.

First, the AI toolchain is now bankable attack surface. ZDI doesn’t pay $40,000 for curiosities. Every target in the AI Infrastructure category — gateway, coding agent, vector store, inference server, AI database — is a component that thousands of production deployments expose to users or to other services. When all five fall in under two days, the message is that the layer between your users and your model weights was built for velocity, not adversarial pressure.

Second, the bug classes are depressingly classic. Argument injection. Improper input validation. SSRF-adjacent chains. Missing authentication. The AI wrappers weren’t broken by exotic ML-specific attacks — they were broken by the same CWE entries that have killed web apps for two decades. The lesson for AI infrastructure vendors is that “AI-native” does not exempt you from input validation 101; the lesson for buyers is to audit the AI stack with the same rigor (and the same tooling) as any other internet-facing service.

Third, coordinated disclosure now covers the AI ecosystem. Every bug demonstrated at Pwn2Own goes through ZDI’s disclosure process to the affected vendor before details are published. That means a wave of CVEs and patches for OpenAI, the LiteLLM and Chroma maintainers, NVIDIA, Oracle, Samsung, Sonos, Signify, and others is coming in the months ahead — and organizations running these components self-hosted should treat the next patch cycle as non-optional.

The stakes are also rising with usage. Agentic coding tools now mediate a substantial share of professional software development, and LLM gateways increasingly hold the keys — literal API keys — to an organization’s entire model estate. A reverse shell on a gateway or an injection into an agent isn’t a data-leak bug; it’s a foothold into the machinery that writes and deploys your code.

Pwn2Own has always been a lagging indicator of where attackers are already going. When its bounties flowed to browsers, browsers got hardened. When they flowed to phones and cars, so did vendor attention. In Cork this week, they flowed to the AI stack — the clearest signal yet that in 2026, the AI toolchain is production-critical infrastructure, and it is being tested like it.