Inside the Pwn2Own Miami 2020 hacking contest, where hackers targeted industrial control systems software for the first time
At Pwn2Own, hackers had no trouble dismantling systems that help run everything from car washes to nuclear plants—with the prize of taking home the very computers they “pwn.” Tweets: @wired , @wired , and @a_greenberg Tweets: @wired : At Pwn2Own, the world's biggest hacking competition, hackers dismantle systems that help run everything from car washes to nuclear plants. But the goal of the competition is actually to make its hacking targets more secure. https://www.wired.com/... @wired : Pwn2Own is the world's biggest hacking competition. For the first time it focused exclusively on industrial control software. Every target was an application that touches physical machinery and the compromises could in many cases have catastrophic effects. https://www.wired.com/... Andy Greenberg / @a_greenberg : At the first #Pwn2Own hacking contest to focus on industrial control systems, hackers demonstrated at least one zero-day in all eight software targets. Which, considering the power grids, refineries and factories this code controls, is a little disturbing. https://www.wired.com/...
Context & Ripple Effects
Pwn2Own had spent years proving out desktop and virtualization software — including a 2017 chain that escaped a VMware virtual machine to compromise the host — before Miami 2020 marked its first edition aimed exclusively at industrial control systems. The result validated the expansion immediately: researchers demonstrated at least one zero-day in every one of the eight ICS software targets, covering systems that run everything from car washes to nuclear plants.
The playbook stuck. The contest's vertical-by-vertical march continued with a Vancouver 2022 round hitting Microsoft, Ubuntu, and Tesla products and a first automotive-focused event that paid out $1.3M+ across 49 car-related zero-days, making Miami 2020 the template for how Pwn2Own opens a new attack surface category.
First-order effects
- The vendors behind all eight ICS software targets received working zero-day demonstrations against products deployed in industrial environments, triggering coordinated patching for flaws that were previously unknown even to their makers.
- Operators of the affected systems — from car wash operators to nuclear facility managers — learned that off-the-shelf control software they assumed was obscure was now demonstrably breakable on stage.
Second-order effects
- The clean sweep proved demand for an ICS-specific contest, pushing organizers to keep carving Pwn2Own into vertical editions like the automotive event, where payouts reached $1.3M+ across 49 zero-days.
- Industrial control vendors now compete in a market where their code is publicly stress-tested alongside consumer software like the Samsung Galaxy S23, which fell four times at Toronto 2023 — raising buyer expectations for patch responsiveness in OT products.
Third-order effects
- If the pattern holds, coordinated-disclosure contests become a standing procurement input for critical infrastructure: buyers can weigh vendors' Pwn2Own track records the way they weigh certifications, shifting security spending toward pre-emptive researcher payouts.
- The steady extension from desktops to VMs to ICS to cars points toward bug-bounty economics absorbing operational technology as a whole, with each new vertical's first contest exposing a backlog of unpatched flaws that regulators and insurers will eventually price in.
The trend: Pwn2Own is expanding contest-driven zero-day discovery from consumer and enterprise software into critical-infrastructure verticals, with each new sector's debut edition exposing systemic weaknesses in previously untested code.