Pwn2Own loses HP as its sponsor amid concerns of compliance with the Wassenaar Arrangement, an international treaty that has rules governing software exploits
Dan Goodin / Ars Technica :
Context & Ripple Effects
HP's exit lands five months after Pwn2Own's biggest showcase yet, when researchers broke fully patched versions of Firefox, Chrome, IE 11, and Safari in front of live audiences while the $557K payout pool made the contest's cash-for-exploits model impossible to ignore. That visibility is exactly what triggered the problem: the Wassenaar Arrangement treats software exploits as controlled dual-use items, and a corporate sponsor paying bounties for them sits squarely inside that gray zone.
The stakes are structural rather than reputational. Pwn2Own has spent years expanding its target surface — from browsers to virtualization escapes like the Edge/Windows/VMware host-compromise chain to industrial control systems in Miami — so losing its anchor sponsor tests whether a public, prize-funded exploit market can survive under export-control scrutiny at all.
First-order effects
- Pwn2Own loses its title sponsor mid-cycle, putting the prize pools that drew researchers to break patched browsers in March directly at risk for future events.
- HP removes itself from legal exposure under Wassenaar's exploit-trading rules, trading its security-research halo for regulatory caution.
Second-order effects
- Other vendors that benefit from Pwn2Own's disclosures must decide whether to fill the sponsorship gap or quietly distance themselves, splitting the buyer side of the exploit market between public contests and private acquisition.
- Researchers weighing contest payouts against private broker sales now face a pricing question: if public venues shrink under treaty pressure, the same exploits command different terms behind closed doors.
Third-order effects
- If Wassenaar-style controls keep tightening, exploit disclosure migrates from open competition toward government-brokered channels, weakening the vendor patch pipeline that contests feed — though the contest's later survival, from Miami's industrial control systems debut to Berlin 2026's $1.29M AI-product round, suggests it adapted by rotating sponsors and target categories rather than dying.
The trend: Export-control treaties are forcing the public vulnerability market to restructure around whoever is willing to fund it, with each new target category — browsers, VMs, ICS, now AI — dragging the contest back into regulators' scope.