/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers earned $1M+ for 58 zero-day exploits targeting consumer products at Pwn2Own Toronto 2023 and hacked a fully patched Samsung Galaxy S23 four times

This playlist contains all of the videos recorded at Pwn2Own Toronto 2023. Dustin Childs / Zero Day Initiative : Pwn2Own Toronto 2023 - Day Three Results Alex Ivanovs / Stack Diary : Samsung's Galaxy S23 faces multiple successful hacks at Pwn2Own Mihai Matei / SamMobile : Galaxy S23 got hacked three more times at Pwn2Own Ionut Arghire / SecurityWeek : Hackers Earn $350k on Second Day at Pwn2Own Toronto 2023 Mihai Matei / SamMobile : Galaxy S23 and rival Xiaomi 13 Pro get hacked live Ionut Arghire / SecurityWeek : Hackers Earn $400k on First Day at Pwn2Own Toronto 2023 Andy Walker / Android Authority : Hacking contest proves Galaxy S23 isn't so secure after all Sumit Adhikari / Android Headlines : Galaxy S23 and Xiaomi 13 Pro hacked twice in a day at Pwn2Own Matthew Zucca / Android Police : Samsung's Galaxy S23 was just hacked four times this week X: Charlie Miller / @0xcharlie : Interesting data from this week's Pwn2Own. 1) No attempts against Google Pixel or iPhone even though they are worth 4-5x other targets. 2). 15 straight years of hacking Apple products at Pwn2Own ended last year and continues this year. Apple is secure now? 1/n Charlie Miller / @0xcharlie : 3) The only interesting (to me) device getting targeted is Samsung Galaxy. 4) Why is pwn2own targeting smart speakers and printers? That's so easy even I could do it and I'm old. 5) When did pwn2own have rules written by lawyers? Used to be a tweet, a blog if you were lucky. @pentestltd : #Pwn2Own Toronto released a nice little short of our Samsung Galaxy S23 exploit. Why does hacking always look cooler in film/video? 🤷‍♂️ @thezdi [video] @thezdi : That's a wrap on #Pwn2Own Toronto 2023! We awarded $1,038,250 for 58 unique 0-days during the event. Congratulations to Team Viettel (@vcslab) for winning Master of Pwn with $180K and 30 points. We'll see you at Pwn2Own Automotive in Tokyo next January. [image] @claroty : Today at #Pwn2Own Toronto, Team82 chained 4 exploits to remotely attack a TP-Link Omada router, then pivot to the local network to access a Synology BC500 camera. All technical details were disclosed to the vendors. Team82 was awarded $40,000 USD in prize money for its efforts. [image] @thezdi : Success! STAR Labs SG was able to exploit a permissive list of allowed inputs against the Samsung Galaxy S23. They earn $25,000 and 5 Master of Pwn points. #Pwn2Own [image] LinkedIn: Sharni Harris : The money in being a cyber criminal is wild, even this short competition shows how easy it is, and how lucrative it is … Lonny H. : We do soooo much more than than what people think - check this out! Alexandre BLANC Cyber Security : All it takes is motivation, this example should remind you of the factual reality.  —  “Hackers earn over $1 million for 58 zero-days at Pwn2Own Toronto” … Forums: r/InfoSecNews : Hackers earn over $1 million for 58 zero-days at Pwn2Own Toronto

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

Pwn2Own Toronto had already shown that consumer devices spanning phones, printers, routers and NAS systems could yield new exploit chains, including the 2022 opening-day findings across consumer hardware. The 2023 results broaden that signal from isolated product categories to a concentrated set of 58 distinct zero-days.

The repeated compromise of a fully patched Galaxy S23 matters because it highlights both handset attack surface and the contest’s role in moving vulnerabilities into vendors’ remediation pipelines. Later Pwn2Own events continued to reward successful demonstrations across PCs, cars and operating systems, including the 2024 Vancouver zero-day demonstrations.

First-order effects

  • Samsung must assess and remediate the vulnerability paths exposed by four successful Galaxy S23 compromises, while the affected router and camera vendors have already been notified of Team82’s chained attack.
  • Researchers received more than $1 million for 58 unique zero-days, converting previously private exploit knowledge into coordinated vendor disclosures.

Second-order effects

  • Consumer-device makers face pressure to test cross-device attack paths, not only single-product flaws: Team82’s router-to-camera pivot demonstrates how a weakness in network equipment can expose adjacent hardware.
  • High payouts and public demonstrations strengthen the market incentive for researchers to direct high-impact findings to coordinated-disclosure programs rather than leave them undisclosed.

Third-order effects

  • If contests continue to surface large numbers of unique flaws across connected consumer products, security competition will increasingly center on ecosystem resilience—patch speed, device lifecycle support and isolation between products—rather than headline device hardening alone.
  • The later expansion of Pwn2Own targets to AI products in the 2026 Berlin contest suggests the same disclosure-and-reward model may keep extending as new product categories become mainstream attack surfaces.

The trend: Pwn2Own results reflect a widening security-testing economy in which coordinated disclosure is increasingly focused on exploit chains across consumer and emerging computing platforms.

Discussion

  • @0xcharlie Charlie Miller on x
    Interesting data from this week's Pwn2Own. 1) No attempts against Google Pixel or iPhone even though they are worth 4-5x other targets. 2). 15 straight years of hacking Apple products at Pwn2Own ended last year and continues this year. Apple is secure now? 1/n
  • @0xcharlie Charlie Miller on x
    3) The only interesting (to me) device getting targeted is Samsung Galaxy. 4) Why is pwn2own targeting smart speakers and printers? That's so easy even I could do it and I'm old. 5) When did pwn2own have rules written by lawyers? Used to be a tweet, a blog if you were lucky.
  • @pentestltd @pentestltd on x
    #Pwn2Own Toronto released a nice little short of our Samsung Galaxy S23 exploit. Why does hacking always look cooler in film/video? 🤷‍♂️ @thezdi [video]
  • @thezdi @thezdi on x
    That's a wrap on #Pwn2Own Toronto 2023! We awarded $1,038,250 for 58 unique 0-days during the event. Congratulations to Team Viettel (@vcslab) for winning Master of Pwn with $180K and 30 points. We'll see you at Pwn2Own Automotive in Tokyo next January. [image]
  • @claroty @claroty on x
    Today at #Pwn2Own Toronto, Team82 chained 4 exploits to remotely attack a TP-Link Omada router, then pivot to the local network to access a Synology BC500 camera. All technical details were disclosed to the vendors. Team82 was awarded $40,000 USD in prize money for its efforts. […
  • @thezdi @thezdi on x
    Success! STAR Labs SG was able to exploit a permissive list of allowed inputs against the Samsung Galaxy S23. They earn $25,000 and 5 Master of Pwn points. #Pwn2Own [image]
  • r/InfoSecNews r on reddit
    Hackers earn over $1 million for 58 zero-days at Pwn2Own Toronto