Pwn2Own Ireland 2026, the hacking contest run by the Zero Day Initiative (ZDI) in Cork from October 6 to 9, added two AI categories this year, AI Infrastructure and Coding Agent, and in the first two days researchers collected five-figure payouts against OpenAI Codex, LiteLLM, NVIDIA Dynamo, Chroma and Oracle's Autonomous AI Database. The results are a useful public data set on how exploitable the everyday AI toolchain is, because every entry is a live demonstration against a default install, judged by a third party, with a payout attached. This post covers only what ZDI has published through Day Two. A Day Three results post had not been published when this was written, so it is not included.
NVIDIAWhat the AI categories at Pwn2Own Ireland 2026 contained
ZDI's rules list two new AI categories. In AI Infrastructure, the exploit is launched from the contestant's laptop on the contest network and must bypass the target's authentication. The listed targets and prizes are Chroma ($20,000, 2 Master of Pwn points), Postgres pgvector ($30,000, 3 points), and Oracle Autonomous AI Database, LiteLLM and NVIDIA Dynamo ($40,000 and 4 points each). In Coding Agent, targets run on Windows 11 25H2 in default configuration with sandboxing enabled, and the rules list Anthropic Claude Code and OpenAI Codex at $40,000 and 4 points each.
The published schedule shows what contestants actually registered for: 14 AI entries, 13 in AI Infrastructure and one in Coding Agent. That one entry was Ikotas Labs against OpenAI Codex. The schedule lists no entry for Claude Code, and none for pgvector. Oracle drew five registered attempts and Chroma five.
Day One: Codex, LiteLLM and Oracle
On Day One, ZDI reports that Ikotas Labs "used a single argument injection bug to exploit OpenAI Codex" and won $40,000 and 4 Master of Pwn points. Taisic Yun of Xint "used an Improper Input Validation bug along with code injection to get his reverse shell on LiteLLM," earning $40,000 and 4 points. A second LiteLLM attempt, by HaeJung Yang and ByungYoung Yi of Out of Bounds, was a collision (4 bugs, 2 of them known) and paid $15,000 and 3 points. VinSOC's Nam Nguyen, Thanh Vu and Tin Huynh combined 5 bugs against the Oracle Autonomous AI Database for $40,000 and 4 points. VinSOC's attempt on Chroma was a failure: it ran out of the time limit.
BleepingComputer's report on the opening day put the overall tally at 32 zero-days and $388,500, which matches the figure ZDI repeats at the top of its Day Two post. It also noted that last year's event paid $1,024,750 for 73 zero-days.
Day Two: Dynamo falls, Chroma splits
On Day Two, HaeJung Yang of Out of Bounds earned the full $40,000 and 4 points for exploiting NVIDIA Dynamo. Chroma produced mixed results: one researcher, Eugene, failed on a final attempt with seconds left, while Team MAMMOTH succeeded with 2 collisions and 1 zero-day ($12,000, 1.25 points) and Alessandro Fanio Gonzalez succeeded with 2 N-days and 1 collision ($4,500, 1 point). Oracle's database fell twice more: Xint, with 3 collisions and 2 unique zero-days, took $14,000, and Ikotas Labs landed a 7-bug chain ending in Use-After-Free and Type Confusion for $10,000.
ZDI's Day Two post lists $388,500 for Day One and, by our own addition of the individual payouts it publishes, at least $220,000 for Day Two (one Samsung entry has no stated payout), for roughly $608,500 across two days. That cumulative figure is our arithmetic, not a total ZDI states.
Payout per successful AI-category entry vs the listed prize
Dark bar: amount awarded. Light bar: the listed prize for that target. Entries that collided with known or already-submitted bugs paid a fraction of the listed prize. Source: ZDI Day One and Day Two results posts.
What the bug classes say about the AI toolchain
Read together, the AI results are notable for how ordinary the bugs are. The ZDI posts describe argument injection (Codex), improper input validation with code injection (LiteLLM), and memory-safety flaws in a database written in a conventional stack (Use-After-Free, Type Confusion in Oracle). These are not novel machine-learning attacks. They are the same injection and memory-corruption classes that have shaped web and database security for decades, applied to software that happens to sit next to models.
That matters because of where these tools sit. A coding agent is a program that turns text into commands on a developer machine, so an argument-injection bug is a bridge between untrusted input and a shell. An LLM gateway such as LiteLLM concentrates provider API keys and routes traffic for many applications, so code execution there is a path to every credential it holds. An inference server and a vector database are often deployed inside the network because they are "internal," which is the assumption the contest's authentication-bypass rule deliberately tests. ZDI's post does not give root-cause detail for these bugs, which stay private until vendors patch (ZDI's standard window is 90 days), so claims about exact mechanisms beyond the one-line descriptions would be speculation.
The AI-category bugs are old classes in new places: injection and memory corruption, now sitting next to credentials, models and source code.
Metir analysis of ZDI Day One and Day Two results
Prize-value signalling
The prize table carries information. ZDI priced Codex, Claude Code, LiteLLM, Dynamo and Oracle's database at $40,000 each, above Chroma ($20,000) and pgvector ($30,000). The schedule shows researchers agreed, with five registered Oracle attempts. Whether those prices reflect market value is not something ZDI's posts claim, but the ordering suggests ZDI judged the AI gateway and coding-agent targets as higher value than open-source vector stores.
The collisions tell a second story. Of the nine successful AI entries listed in the posts, four paid the full listed prize and the other five paid between $4,500 and $15,000 of a listed $20,000 or $40,000, where ZDI's posts flag collisions (known or already-submitted bugs) on most of them, though the Oracle Ikotas Labs entry is not labelled as a collision. The Oracle database paid $40,000, $14,000 and $10,000 to three different teams. Later successes on a crowded target paid less, which is a rough signal that several well-funded groups were independently finding overlapping flaws in the same products.

Practical takeaways for teams running these tools
None of the following is a ZDI recommendation. It is our reading of the results.
- Treat coding agents as untrusted-input processors. Keep sandboxing on, run them with least privilege, and do not give them standing credentials beyond the task.
- Do not leave gateways and inference servers unauthenticated on internal networks. The AI Infrastructure rules require an authentication bypass, so authentication is the control under test.
- Isolate secrets. Keep provider keys in a secrets manager and scope them per service, so one compromised gateway does not expose every upstream account.
- Patch quickly once fixes ship. ZDI-reported bugs are disclosed publicly after the 90-day vendor window, and collisions imply other parties may already hold similar findings.
- Reduce single points of failure. Teams that route model calls through a single gateway or vendor inherit its bugs. Multi-model tools such as Metir AI treat the model and provider as swappable, which limits how much any one component matters, though it does not remove the need to patch the gateway layer you do run.
What to watch next
Open questions remain. Day Three results and the final Master of Pwn standings were not yet published at the time of writing. Which vendors patch within the 90-day window, and whether Claude Code draws any entrant in future events, are also unanswered. For now, the Ireland results reinforce a plain point: the AI stack inherits the old bug classes along with its new capabilities.
Sources:
- Pwn2Own Ireland 2026: Day One Results (Zero Day Initiative, Oct 6, 2026)
- Pwn2Own Ireland 2026: Day Two Results (Zero Day Initiative, Oct 7, 2026)
- Pwn2Own Ireland 2026: The Full Schedule (Zero Day Initiative, Oct 5, 2026)
- Pwn2Own Ireland 2026 Rules (Zero Day Initiative)
- Hackers exploit 32 zero-days on first day of Pwn2Own Ireland (BleepingComputer)
Image credits
Header and in-body image: View of Cork City from Bell's Field, September 2025, by William Murphy via Wikimedia Commons, licensed under CC BY-SA 4.0.