/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Windows 10, iOS 14, Chrome, Safari, and Firefox were hacked in Tianfu Cup, China's largest hacking competition; winning team from Qihoo 360 got $744K in prizes

Catalin Cimpanu / ZDNet :

ZDNet Catalin Cimpanu

Context & Ripple Effects

The Tianfu Cup is running its second headline-grabbing edition since becoming China's top contest after a participation ban kept Chinese researchers away from foreign events like Pwn2Own — last year it saw Chrome, Edge, and Safari fall on stage. This year the scope widened to full operating systems: Windows 10 and iOS 14 went down alongside all three major browser engines.

The result lands months after the 2020 Pwn2Own ran virtually and still produced exploits against Windows, macOS, Adobe Reader, and desktop Safari — evidence that elite exploit work continued on both sides of the split even as the two circuits no longer share competitors.

First-order effects

  • Qihoo 360's winning team walks away with $744K and holds working exploits against fully patched Windows 10, iOS 14, Chrome, Safari, and Firefox, putting Microsoft, Apple, Google, and Mozilla under immediate pressure to ship fixes.
  • Vendors who do not attend Tianfu Cup now learn about critical holes in their flagship OSes and browsers secondhand, through disclosures made on a stage they have no presence at.

Second-order effects

  • With Chinese researchers concentrated at Tianfu Cup rather than Pwn2Own, the $744K payout sets a new benchmark that pressures both contests to raise bounties to keep top talent — a bidding dynamic visible in the corpus's own payout history, where Pwn2Own totals grew from $557K in the 2015 Firefox-Chrome-Safari round to seven figures today.
  • Qihoo 360's sweep reinforces the position of China's large security firms as the primary employers of elite exploit researchers, squeezing independent teams out of the highest-value targets.

Third-order effects

  • If the circuit split holds, browser and OS patch cycles will increasingly be set by demonstrations at national contests rather than a single global venue, fragmenting the vulnerability-disclosure calendar along geopolitical lines.
  • A recurring pattern of one domestic firm dominating the flagship targets points toward consolidation of offensive research capability inside a few state-aligned companies — a structural shift regulators and vendors would need to account for when assessing whose exploits exist in the wild.

The trend: Elite hacking competitions are splitting along national lines, with Tianfu Cup displacing Pwn2Own as the stage where China's top researchers demonstrate browser and operating-system exploits.

Discussion

  • @tianfucup @tianfucup on x
    Many mature and hard targets have been pwned on this year's contest. 11 out of 16 targets cracked with 23 successful demos: Chrome, Safari, FireFox Adobe PDF Reader Docker-CE, VMware EXSi, Qemu, CentOS 8 iPhone 11 Pro+iOS 14, GalaxyS20 Windows 10 2004 TP-Link, ASUS Router 👍
  • @alexstamos Alex Stamos on x
    While good people at NSA/CYBERCOM and CISA are certainly paying attention, the lack of a national strategy that takes into account the reality of our situation is glaring. We've lost four years while the PRC has built an incredible (and paradoxically capitalist) ecosystem.
  • @alexstamos Alex Stamos on x
    This and similar contests contain hard lessons about the bug density of critical US software and the effectiveness of the PRC's effort to create a homegrown public-private offensive capability. These lessons need to be deeply considered by the reconstituted Biden NSC cyber team. …
  • @alexstamos Alex Stamos on x
    @pwnallthethings Sure, but still, these were the bugs that PRC authorities are ok getting patched. Combined with the evidence that the PRC was using a full iOS exploit chain against thousands of their own citizens, I think our estimates of what are in the “strategic reserve” shou…