Pwn2Own Toronto 2022, Hackers Earn big for 63 unique zero-day exploits

December 12, 2022

Participants in the Pwn2Own Toronto 2022 hacking competition earned $400,000 on the first day, and a total of $989,750 on the final day for new exploits targeting phones, printers, routers, and NAS devices.

26 teams and security researchers targeted devices in the categories of mobile phones, home automation hubs, printers, wireless routers, network-attached storage, and smart speakers during this hacking competition, all of which were up to date and in their default configuration.

On their third attempt, the STAR Labs team was the first to exploit a zero-day in Samsung’s flagship device by executing an improper input validation attack, earning $50,000 and 5 Master of Pwn points.

On the first day of the competition, another contestant known as Chim demonstrated another successful exploit targeting the Samsung Galaxy S22. On the second and third days of the competition, security researchers from Interrupt Labs and Pentest Limited also hacked the Galaxy S22, with Pentest Limited demonstrating their zero-day exploit in just 55 seconds.

The Devcore team, which had previously competed in several Pwn2Own contests, received the highest single reward on the first day. They were paid $100,000 for hacking a MikroTik router and a Canon printer connected to it.

The event totals $989,750, 63 unique 0-days, 66 entries, and 36 different teams representing 14+ countries.

The sources for this piece include an article in BleepingComputer.

Top Stories

Related Articles

January 20, 2026 Hackers are advertising what they claim is internal source code stolen from Target. A sample of the more...

January 16, 2026 A newly uncovered malware framework suggests attackers are quietly preparing for a much deeper push into Linux more...

January 16, 2026 A massive trove of personal data belonging to thousands of U.S. immigration agents has reportedly been leaked more...

December 30, 2025 A fast-moving cyberattack has compromised more than 59,000 internet-facing Next.js servers in less than two days after more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn