/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Hackers breach iPhone X, Galaxy S9, and Xiaomi Mi6 and earn $325K for exposing 18 exploits at the Pwn2Own Tokyo 2018 contest

Three major mobile phone models - the Samsung Galaxy S9, iPhone X and the Xiaomi Mi6 - failed to survive the hacker onslaught at this year's Pwn2Own Tokyo 2018.

Threatpost Tom Spring

Context & Ripple Effects

This is the second straight year the mobile edition of Pwn2Own has put flagship phones on the chopping block: last year's Mobile Pwn2Own paid out $515K for 32 vulnerabilities across the iPhone 7, Galaxy S8 and Huawei Mate 9 Pro. Tokyo 2018 continues the format with a smaller purse — $325K for 18 exploits — but the same outcome: every premium device entered fell.

The targets are not marginal handsets. The iPhone X was the world's best-selling smartphone model through early 2018 and generated an outsized share of industry profits, while the Galaxy S9 was Samsung's then-current flagship — so the contest is effectively stress-testing the devices carrying the most user data and vendor reputation.

First-order effects

  • Apple, Samsung and Xiaomi receive working exploit chains against their current flagships and must ship patches for 18 vulnerabilities before details leak beyond the contest.
  • The hackers collect $325K from the Pwn2Own organizers, converting phone-breaking into direct income and setting a public price benchmark for mobile exploits.

Second-order effects

  • Vendors' internal bug-bounty programs now have to compete with contest payouts that keep climbing — the same series later paid $400K on day one alone at Pwn2Own Toronto 2022 and over $1M for 58 exploits at Toronto 2023, pressuring Apple and Samsung to price their own rewards near market rate.
  • Every breach of a best-selling device like the iPhone X lands during peak sales cycles, giving rivals and enterprise buyers fresh ammunition in security-focused procurement debates.

Third-order effects

  • Contest findings have proven predictive of real-world risk: within a year of these events, attackers were running an Android zero-day in the wild against roughly 18 phone models via a malicious app, suggesting the researcher market and criminal exploitation draw on the same vulnerability pool.
  • If payout escalation holds, mobile security consolidates into a professionalized research economy where flagship launch cycles double as scheduled stress tests, and unpatched-exploit windows become a measurable competitive liability for handset makers.

The trend: Smartphone security is becoming a monetized research market, with Pwn2Own payouts escalating each cycle and contest breaches increasingly foreshadowing zero-days exploited in the wild.