Hackers breach iPhone X, Galaxy S9, and Xiaomi Mi6 and earn $325K for exposing 18 exploits at the Pwn2Own Tokyo 2018 contest
Three major mobile phone models - the Samsung Galaxy S9, iPhone X and the Xiaomi Mi6 - failed to survive the hacker onslaught at this year's Pwn2Own Tokyo 2018.
Context & Ripple Effects
This is the second straight year the mobile edition of Pwn2Own has put flagship phones on the chopping block: last year's Mobile Pwn2Own paid out $515K for 32 vulnerabilities across the iPhone 7, Galaxy S8 and Huawei Mate 9 Pro. Tokyo 2018 continues the format with a smaller purse — $325K for 18 exploits — but the same outcome: every premium device entered fell.
The targets are not marginal handsets. The iPhone X was the world's best-selling smartphone model through early 2018 and generated an outsized share of industry profits, while the Galaxy S9 was Samsung's then-current flagship — so the contest is effectively stress-testing the devices carrying the most user data and vendor reputation.
First-order effects
- Apple, Samsung and Xiaomi receive working exploit chains against their current flagships and must ship patches for 18 vulnerabilities before details leak beyond the contest.
- The hackers collect $325K from the Pwn2Own organizers, converting phone-breaking into direct income and setting a public price benchmark for mobile exploits.
Second-order effects
- Vendors' internal bug-bounty programs now have to compete with contest payouts that keep climbing — the same series later paid $400K on day one alone at Pwn2Own Toronto 2022 and over $1M for 58 exploits at Toronto 2023, pressuring Apple and Samsung to price their own rewards near market rate.
- Every breach of a best-selling device like the iPhone X lands during peak sales cycles, giving rivals and enterprise buyers fresh ammunition in security-focused procurement debates.
Third-order effects
- Contest findings have proven predictive of real-world risk: within a year of these events, attackers were running an Android zero-day in the wild against roughly 18 phone models via a malicious app, suggesting the researcher market and criminal exploitation draw on the same vulnerability pool.
- If payout escalation holds, mobile security consolidates into a professionalized research economy where flagship launch cycles double as scheduled stress tests, and unpatched-exploit windows become a measurable competitive liability for handset makers.
The trend: Smartphone security is becoming a monetized research market, with Pwn2Own payouts escalating each cycle and contest breaches increasingly foreshadowing zero-days exploited in the wild.