/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Chrome, Edge, Safari hacked at elite hacking contest Tianfu Cup, which is now China's top competition after a participation ban on foreign contests like Pwn2Own

China's top white-hat hackers have gathered in Chengdu to test zero-days against today's top software.

ZDNet Catalin Cimpanu

Context & Ripple Effects

For most of the past decade, the world's best browser exploits surfaced at Pwn2Own in Vancouver, where fully patched Firefox, Chrome, IE and Safari fell for six-figure prize pools and researchers chained bugs into VM escapes like the 2017 Edge-Windows-VMware host compromise. With Chinese participants barred from foreign contests, that talent pool has been redirected to Tianfu Cup in Chengdu.

This article marks the moment the replacement matures: elite Chinese white-hats are demonstrating zero-days against all three major browser engines on home soil. A year on, the trajectory holds — the 2020 edition saw Windows 10, iOS 14, Chrome, Safari, and Firefox fall, with Qihoo 360's team collecting $744K in prizes.

First-order effects

  • Google, Microsoft, and Apple each leave Chengdu holding working zero-day exploits against their flagships, forcing out-of-band patch work outside the usual Pwn2Own disclosure calendar.
  • Chinese research teams now monetize top-tier browser bugs at a domestic contest rather than traveling to foreign events, keeping both the exploits and the prize money inside China's security industry.

Second-order effects

  • With the same researcher base no longer feeding Pwn2Own, Western contest organizers and browser vendors face thinner fields at legacy events — the 2020 virtual Pwn2Own still landed Windows, Ubuntu, macOS, Adobe Reader, and Safari exploits, but the competition for talent is now bilateral.
  • Prize pools become a bidding war for zero-days between contest ecosystems, pressuring vendors to raise their own bug-bounty payouts to keep disclosures flowing through coordinated channels.

Third-order effects

  • If national bans on foreign contests hold, exploit discovery and disclosure split into parallel geopolitical tracks, weakening the shared patch cadence that browser vendors have relied on since the Pwn2Own era.
  • Vendors may need standing relationships with both ecosystems — and regulators may weigh in — as zero-days demonstrated publicly at state-aligned contests become a recurring feature of US-China tech competition.

The trend: Zero-day discovery is bifurcating into rival domestic contest ecosystems — Tianfu Cup versus Pwn2Own — with browser vendors forced to run patch pipelines against two calendars.

Discussion

  • @williamnee William Nee on x
    Chrome, Edge, Safari hacked at elite Chinese hacking contest China's top white-hat hackers have gathered in Chengdu to test zero-days against today's top software. https://www.zdnet.com/... via @ZDNet & @campuscodi