Pwn2Own loses HP as its sponsor amid concerns of compliance with the Wassenaar Arrangement, an international treaty that has rules governing software exploits
Dan Goodin / Ars Technica :
Context & Ripple Effects
HP is pulling out as sponsor of Pwn2Own because of compliance worries around the Wassenaar Arrangement, whose rules treat certain software exploits as controlled items. That leaves the contest — which just months earlier paid out $557K for exploits against fully patched Firefox, Chrome, IE 11, and Safari — without a named corporate backer at a moment when its entire model rests on publicly demonstrating live exploits.
The stakes go beyond one sponsor: if export-control exposure makes vendors skittish underwriting public exploit demos, the contest has to find either new backers or new legal footing to keep paying researchers.
First-order effects
- HP exits the sponsor role, removing a named corporate backer from Pwn2Own and forcing organizers to replace that funding or scale payouts down.
Second-order effects
- Vendors weighing sponsorship now have to price Wassenaar compliance risk into the decision, while researchers face uncertainty about whether contest payouts remain a reliable channel for monetizing exploit work.
Third-order effects
- If the pattern holds, export-control pressure doesn't kill public exploit contests so much as reshape them — the corpus shows the format surviving and expanding into new territory, from industrial control systems at Pwn2Own Miami to AI products like Codex and Cursor at Pwn2Own Berlin 2026, where payouts reached $1.29M.
The trend: Arms-control regimes governing exploit trade keep pressuring public vulnerability research, and the contest circuit adapts by rotating into whatever target class — browsers, ICS, AI tools — draws fresh sponsor and researcher interest.