• News/
  • https://www.bleepingcomputer.com/news/security/pwn2own-hacking-contest-pays-1-million-for-whatsapp-exploit/

Pwn2Own hacking contest pays $1 million for WhatsApp exploit

BleepingComputer
·
Sergiu Gatlan
·
Published Aug 1, 2025
·
Updated

The Zero Day Initiative is offering a $1 million reward to security researchers who will demonstrate a zero-click WhatsApp exploit at its upcoming Pwn2Own Ireland 2025 hacking contest. The record bounty targets zero-click security flaws that allow code execution without user interaction on the messaging platform used by more than three billion people worldwide. Meta, alongside Synology and QNAP, is co-sponsoring the Pwn2Own Ireland 2025 competition, which will take place from October 21 to October 24 in Cork, Ireland. "As you might have guessed from the title, we're excited to announce that Meta is co-sponsoring this year's event, and they are hoping to see some great WhatsApp exploits. They are so excited for it, we're putting up $1,000,000 for a 0-click WhatsApp bug that leads to code execution," the Zero Day Initiative announced Thursday. "We also will have lesser cash awards for other WhatsApp exploits, so be sure to check out the Messaging section for full details. We introduced this category last year, but no one attempted it. Perhaps a number with two commas will provide the needed motivation." ​The contest features eight categories targeting mobile phones, messaging apps, home networking equipment, smart home devices, printers, network storage systems, surveillance equipment, and wearable technology, including Meta's Ray-Ban Smart Glasses and Quest 3/3S headsets, as well as Samsung Galaxy S25, Google Pixel 9, and Apple iPhone 16 flagship smartphones. The ZDI has also...

Read full article

Affected Software

1 affected component
Meta WhatsApp
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a $1 million reward for exploiting a zero-click vulnerability in WhatsApp at the Pwn2Own 2025 hacking contest.

2

What security implications are discussed in the article?

The article highlights the potential risks associated with zero-click exploits that can compromise user security without any action needed from the victim.

3

What product is primarily affected by the exploits discussed?

The primary product affected by the exploits mentioned in the article is Meta's WhatsApp.

4

What type of vulnerabilities are targeted for the contest?

The contest is specifically targeting zero-click security flaws, which do not require user interaction.

5

Who is offering the reward for the exploit?

The reward is offered by the Zero Day Initiative, which organizes the Pwn2Own hacking contest.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203