Security researchers have hacked the Tesla Infotainment System and earned $516,500 after exploiting 37 zero-days on the first day of the Pwn2Own Automotive 2026 competition. Synacktiv Team took home $35,000 after successfully chaining an information leak and an out‑of‑bounds write flaw to get root permissions on the Tesla Infotainment System in the USB-based attack category. They also chained three vulnerabilities to gain root-level code execution on the Sony XAV-9500ES digital media receiver, earning an additional $20,000 cash award. Teams Fuzzware.io collected another $118,000 after hacking an Alpitronic HYC50 Charging Station, an Autel charger, and a Kenwood DNR1007XR navigation receiver, while PetoWorks was awarded $50,000 for chaining three zero-day bugs to gain root privileges on a Phoenix Contact CHARX SEC-3150 charging controller. Team DDOS also earned $72,500 for hacking the ChargePoint Home Flex, the Autel MaxiCharger, and the Grizzl-E Smart 40A vehicle charging station. On the second day of Pwn2Own, the Grizzl-E Smart 40A will be targeted by four teams, the Autel MaxiCharger will be targeted three times, while two teams will attempt to root the ChargePoint Home Flex, each successful attempt bringing the hackers $50,000. Team Fuzzware.io will also attempt to hack the Phoenix Contact CHARX SEC-3150 vehicle charger for a $70,000 cash reward. Vendors have 90 days to develop and release security fixes before TrendMicro's Zero Day Initiative publicly discloses them afte...
Tesla hacked, 37 zero-days demoed at Pwn2Own Automotive 2026
BleepingComputer
·Sergiu Gatlan
·Published Jan 21, 2026
·Updated
Affected Software
9 affected components
Tesla Infotainment System
Sony XAV-9500ES
alpitronic HYC50 Charging Station
Autel charger
Kenwood DNR1007XR
Phoenix Contact CHARX SEC-3150
ChargePoint Home Flex
Autel MaxiCharger
Grizzl-E Smart 40A
Frequently Asked Questions
1
What was the main event discussed in the article?
The article discusses the Pwn2Own Automotive 2026 competition where Tesla was hacked by the Synacktiv Team.
2
How many zero-day vulnerabilities were exploited during the competition?
The researchers demonstrated 37 zero-day vulnerabilities in the hacking attempt.
3
Which specific Tesla product was targeted in the hacks?
The Tesla Infotainment System was specifically targeted during the hacking event.
4
What was the total prize money earned by the hackers?
The hackers earned a total of $516,500 for their exploits.
5
What other products or software were mentioned as affected?
Other affected products included devices from Sony, Alpitronic, Autel, Kenwood, and ChargePoint.