metir
metir
Docs
Download on App StoreGet it on Google PlayLog inSign up
Back to Blog
Pwn2Own
AI Security
Coding Agents
LiteLLM
AI Infrastructure

Pwn2Own Ireland 2026: AI Coding Agents and LiteLLM Hacked

Pwn2Own Ireland 2026 paid out for exploits of OpenAI Codex, LiteLLM, NVIDIA Dynamo and Oracle's AI database. What the AI results say about the toolchain.

Metir AI TeamOctober 8, 20268 min read
Pwn2Own Ireland 2026: AI Coding Agents and LiteLLM Hacked

Pwn2Own Ireland 2026, the hacking contest run by the Zero Day Initiative (ZDI) in Cork from October 6 to 9, added two AI categories this year, AI Infrastructure and Coding Agent, and in the first two days researchers collected five-figure payouts against OpenAI Codex, LiteLLM, NVIDIA Dynamo, Chroma and Oracle's Autonomous AI Database. The results are a useful public data set on how exploitable the everyday AI toolchain is, because every entry is a live demonstration against a default install, judged by a third party, with a payout attached. This post covers only what ZDI has published through Day Two. A Day Three results post had not been published when this was written, so it is not included.

OpenAI logoOpenAI
NVIDIA logoNVIDIA
Two vendors whose products were targeted in the AI categories at Pwn2Own Ireland 2026.
$388,500Awarded on Day One32 unique zero-days, per ZDI
$40,000Top listed AI prizeCodex, LiteLLM, Dynamo, Oracle
14AI entries on the schedule13 AI Infrastructure, 1 Coding Agent
$1,024,750Pwn2Own Ireland 2025 total73 zero-days, last year's event

What the AI categories at Pwn2Own Ireland 2026 contained

ZDI's rules list two new AI categories. In AI Infrastructure, the exploit is launched from the contestant's laptop on the contest network and must bypass the target's authentication. The listed targets and prizes are Chroma ($20,000, 2 Master of Pwn points), Postgres pgvector ($30,000, 3 points), and Oracle Autonomous AI Database, LiteLLM and NVIDIA Dynamo ($40,000 and 4 points each). In Coding Agent, targets run on Windows 11 25H2 in default configuration with sandboxing enabled, and the rules list Anthropic Claude Code and OpenAI Codex at $40,000 and 4 points each.

The published schedule shows what contestants actually registered for: 14 AI entries, 13 in AI Infrastructure and one in Coding Agent. That one entry was Ikotas Labs against OpenAI Codex. The schedule lists no entry for Claude Code, and none for pgvector. Oracle drew five registered attempts and Chroma five.

Day One: Codex, LiteLLM and Oracle

On Day One, ZDI reports that Ikotas Labs "used a single argument injection bug to exploit OpenAI Codex" and won $40,000 and 4 Master of Pwn points. Taisic Yun of Xint "used an Improper Input Validation bug along with code injection to get his reverse shell on LiteLLM," earning $40,000 and 4 points. A second LiteLLM attempt, by HaeJung Yang and ByungYoung Yi of Out of Bounds, was a collision (4 bugs, 2 of them known) and paid $15,000 and 3 points. VinSOC's Nam Nguyen, Thanh Vu and Tin Huynh combined 5 bugs against the Oracle Autonomous AI Database for $40,000 and 4 points. VinSOC's attempt on Chroma was a failure: it ran out of the time limit.

BleepingComputer's report on the opening day put the overall tally at 32 zero-days and $388,500, which matches the figure ZDI repeats at the top of its Day Two post. It also noted that last year's event paid $1,024,750 for 73 zero-days.

Day Two: Dynamo falls, Chroma splits

On Day Two, HaeJung Yang of Out of Bounds earned the full $40,000 and 4 points for exploiting NVIDIA Dynamo. Chroma produced mixed results: one researcher, Eugene, failed on a final attempt with seconds left, while Team MAMMOTH succeeded with 2 collisions and 1 zero-day ($12,000, 1.25 points) and Alessandro Fanio Gonzalez succeeded with 2 N-days and 1 collision ($4,500, 1 point). Oracle's database fell twice more: Xint, with 3 collisions and 2 unique zero-days, took $14,000, and Ikotas Labs landed a 7-bug chain ending in Use-After-Free and Type Confusion for $10,000.

ZDI's Day Two post lists $388,500 for Day One and, by our own addition of the individual payouts it publishes, at least $220,000 for Day Two (one Samsung entry has no stated payout), for roughly $608,500 across two days. That cumulative figure is our arithmetic, not a total ZDI states.

Payout per successful AI-category entry vs the listed prize

Dark bar: amount awarded. Light bar: the listed prize for that target. Entries that collided with known or already-submitted bugs paid a fraction of the listed prize. Source: ZDI Day One and Day Two results posts.

OpenAI Codex (Ikotas Labs, Day 1)$40,000
LiteLLM (Xint, Day 1)$40,000
Oracle Autonomous AI Database (VinSOC, Day 1)$40,000
NVIDIA Dynamo (Out of Bounds, Day 2)$40,000
LiteLLM (Out of Bounds, Day 1)$15,000 of $40,000
Oracle Autonomous AI Database (Xint, Day 2)$14,000 of $40,000
Chroma (Team MAMMOTH, Day 2)$12,000 of $20,000
Oracle Autonomous AI Database (Ikotas Labs, Day 2)$10,000 of $40,000
Chroma (A. F. Gonzalez, Day 2)$4,500 of $20,000

What the bug classes say about the AI toolchain

Read together, the AI results are notable for how ordinary the bugs are. The ZDI posts describe argument injection (Codex), improper input validation with code injection (LiteLLM), and memory-safety flaws in a database written in a conventional stack (Use-After-Free, Type Confusion in Oracle). These are not novel machine-learning attacks. They are the same injection and memory-corruption classes that have shaped web and database security for decades, applied to software that happens to sit next to models.

That matters because of where these tools sit. A coding agent is a program that turns text into commands on a developer machine, so an argument-injection bug is a bridge between untrusted input and a shell. An LLM gateway such as LiteLLM concentrates provider API keys and routes traffic for many applications, so code execution there is a path to every credential it holds. An inference server and a vector database are often deployed inside the network because they are "internal," which is the assumption the contest's authentication-bypass rule deliberately tests. ZDI's post does not give root-cause detail for these bugs, which stay private until vendors patch (ZDI's standard window is 90 days), so claims about exact mechanisms beyond the one-line descriptions would be speculation.

“

The AI-category bugs are old classes in new places: injection and memory corruption, now sitting next to credentials, models and source code.

Metir analysis of ZDI Day One and Day Two results

Prize-value signalling

The prize table carries information. ZDI priced Codex, Claude Code, LiteLLM, Dynamo and Oracle's database at $40,000 each, above Chroma ($20,000) and pgvector ($30,000). The schedule shows researchers agreed, with five registered Oracle attempts. Whether those prices reflect market value is not something ZDI's posts claim, but the ordering suggests ZDI judged the AI gateway and coding-agent targets as higher value than open-source vector stores.

The collisions tell a second story. Of the nine successful AI entries listed in the posts, four paid the full listed prize and the other five paid between $4,500 and $15,000 of a listed $20,000 or $40,000, where ZDI's posts flag collisions (known or already-submitted bugs) on most of them, though the Oracle Ikotas Labs entry is not labelled as a collision. The Oracle database paid $40,000, $14,000 and $10,000 to three different teams. Later successes on a crowded target paid less, which is a rough signal that several well-funded groups were independently finding overlapping flaws in the same products.

View over the rooftops of Cork City, Ireland, from Bell's Field on a sunny day
A view of Cork City from Bell's Field, taken in September 2025. Cork is the host city of Pwn2Own Ireland 2026; the photograph shows the city, not the contest or any of the targets. Photo by William Murphy via Wikimedia Commons, CC BY-SA 4.0.

Practical takeaways for teams running these tools

None of the following is a ZDI recommendation. It is our reading of the results.

  • Treat coding agents as untrusted-input processors. Keep sandboxing on, run them with least privilege, and do not give them standing credentials beyond the task.
  • Do not leave gateways and inference servers unauthenticated on internal networks. The AI Infrastructure rules require an authentication bypass, so authentication is the control under test.
  • Isolate secrets. Keep provider keys in a secrets manager and scope them per service, so one compromised gateway does not expose every upstream account.
  • Patch quickly once fixes ship. ZDI-reported bugs are disclosed publicly after the 90-day vendor window, and collisions imply other parties may already hold similar findings.
  • Reduce single points of failure. Teams that route model calls through a single gateway or vendor inherit its bugs. Multi-model tools such as Metir AI treat the model and provider as swappable, which limits how much any one component matters, though it does not remove the need to patch the gateway layer you do run.

What to watch next

Open questions remain. Day Three results and the final Master of Pwn standings were not yet published at the time of writing. Which vendors patch within the 90-day window, and whether Claude Code draws any entrant in future events, are also unanswered. For now, the Ireland results reinforce a plain point: the AI stack inherits the old bug classes along with its new capabilities.

Sources:

  • Pwn2Own Ireland 2026: Day One Results (Zero Day Initiative, Oct 6, 2026)
  • Pwn2Own Ireland 2026: Day Two Results (Zero Day Initiative, Oct 7, 2026)
  • Pwn2Own Ireland 2026: The Full Schedule (Zero Day Initiative, Oct 5, 2026)
  • Pwn2Own Ireland 2026 Rules (Zero Day Initiative)
  • Hackers exploit 32 zero-days on first day of Pwn2Own Ireland (BleepingComputer)

Image credits

Header and in-body image: View of Cork City from Bell's Field, September 2025, by William Murphy via Wikimedia Commons, licensed under CC BY-SA 4.0.

Ready to experience AI that adapts to you?

metir brings together the world's best AI models in one seamless experience. Start for free today.

Get Started Free
metir

Agentic Operating System for Professionals buried in meetings, emails and docs.

© 2026 metir. All rights reserved.

Product

  • Features
  • Pricing
  • Research
  • Docs
  • Blog
  • Enterprise

Company

  • Docs
  • Support
  • Careers

Legal

  • Terms of service
  • Privacy policy

Personalisation is powerful. Privacy is non-negotiable.

Status: All systems operational