• News/
  • https://www.bleepingcomputer.com/news/security/hackers-get-1-047-000-for-76-zero-days-at-pwn2own-automotive-2026/

Hackers get $1,047,000 for 76 zero-days at Pwn2Own Automotive 2026

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 23, 2026
·
Updated

Pwn2Own Automotive 2026 has ended with security researchers earning $1,047,000 after exploiting 76 zero-day vulnerabilities between January 21 and January 23. The Pwn2Own Automotive hacking competition focuses on automotive technologies and took place this week in Tokyo, Japan, during the Automotive World auto conference. Throughout the contest, the hackers targeted fully patched in-vehicle infotainment (IVI) systems, electric vehicle (EV) chargers, and car operating systems (e.g., Automotive Grade Linux). Before TrendMicro's Zero Day Initiative publicly discloses them, vendors have 90 days to develop and release security fixes for zero-days that were exploited and reported during the Pwn2Own contest. Team Fuzzware.io won the Pwn2Own Automotive 2026 contest after taking home $215,000 in cash, followed by Team DDOS with $100,750 and Synactiv with $85,000. ​In total, Fuzzware.io earned $118,00 after hacking an Alpitronic HYC50 Charging Station, an Autel charger, and a Kenwood DNR1007XR navigation receiver on the first day. They were also awarded another $95,000 for demonstrating multiple zero-days in the Phoenix Contact CHARX SEC-3150 charging controller, the ChargePoint Home Flex EV charger, and the Grizzl-E Smart 40A EV charging station on the second day, and an additional $2,500 after a bug collision while attempting to root an Alpine iLX-F511 multimedia receiver on the last day of the contest. Synacktiv Team also collected $35,000 after chaining an out‑of‑bounds write flaw...

Read full article

Affected Software

9 affected components
alpitronic HYC50 Charging Station
Autel charger
Kenwood DNR1007XR navigation receiver
Phoenix Contact CHARX SEC-3150 charging controller
ChargePoint Home Flex EV charger
Grizzl-E Smart 40A EV charging station
Alpine iLX-F511 multimedia receiver
Tesla Infotainment System
Tesla car
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What was the total amount earned by hackers at Pwn2Own Automotive 2026?

Hackers earned a total of $1,047,000 by exploiting vulnerabilities at the event.

2

How many zero-day vulnerabilities were exploited during the competition?

A total of 76 zero-day vulnerabilities were successfully exploited by security researchers.

3

What types of products or software were affected by the vulnerabilities?

The affected products include various automotive systems such as charging stations and infotainment systems from multiple vendors.

4

What was the focus of the Pwn2Own Automotive competition?

The Pwn2Own Automotive competition focuses on identifying security vulnerabilities in automotive technology.

5

When did the Pwn2Own Automotive 2026 event take place?

The event took place from January 21 to January 23, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203