Daniel Reyes, YuSMP Group
Daniel Reyes Principal Engineer, AI/ML, YuSMP Group · agentic and retrieval systems in production for US and EU teams
An open server rack glowing with cyan cables on a spotlit competition stage, next to a laptop and a brass stopwatch on a small table, illustrating a timed live hacking contest

The contest in brief

The software that sits between your applications and your models is now a standard target for professional exploit developers. Trend Micro’s Zero Day Initiative (ZDI) ran Pwn2Own Ireland in Cork from 6 to 8 October 2026. AI infrastructure was a full category, with targets ranging from the LiteLLM model gateway and NVIDIA Dynamo inference server to the Chroma vector database.

By our count of ZDI’s published results, there were 11 successful exploits against AI infrastructure and AI coding targets, worth about $227,750 in awards. The single biggest prize of the week went elsewhere. Japan’s Ikotas Labs took the Master of Pwn title after a $300,000 remote exploit of the Google Pixel 10, having already broken OpenAI Codex and Oracle’s AI database.

For companies that run or commission AI agents and LLM-backed workflows, the result is a practical warning. Gateways, inference servers and vector stores often run with broad network access and live API keys. Most security reviews still treat them as internal plumbing.

Which AI tools were hacked?

LiteLLM, the open-source proxy that many teams use to route calls to several model providers, fell twice on day one. Taisic Yun of Xint combined an improper input validation bug with code injection to get a reverse shell, for $40,000. Out of Bounds also exploited it with a four-bug chain, two of which were already known, for $15,000.

OpenAI Codex, the cloud-based coding agent, was taken over by Ikotas Labs with a single argument injection bug, worth $40,000. Argument injection is an old class of flaw: user-influenced input ends up as a command-line option to a tool the agent runs. Coding agents call shell tools constantly, so the class will keep coming back.

NVIDIA Dynamo, an inference-serving framework, fell to HaeJung Yang of Out of Bounds on day two for $40,000. Chroma, a popular open-source vector database, survived two attempts but was exploited twice. Both successful chains relied mainly on bugs that were already known.

Oracle Autonomous AI Database was the most attacked AI target. It was breached five times over three days, including a five-bug chain by VinSOC for $40,000 and a seven-bug chain by Ikotas Labs ending in use-after-free and type-confusion flaws.

Why do the bug collisions matter?

At Pwn2Own, a “collision” means a researcher used a bug that the vendor or another entrant had already reported. Collisions earn less money, but they tell defenders something important. In the AI category, both Chroma wins and three of the five Oracle wins included previously known bugs. One Chroma chain used two N-days, meaning flaws that were already public.

A patch for a known bug only helps if it ships and gets deployed. Open-source AI components are often pinned to whatever version a prototype started with and are rarely updated after launch. The fresh zero-days from Cork will be fixed within the 90-day window. The known ones are already sitting in production stacks today.

What it means for US & EU software teams

Treat the model gateway as a crown-jewel system. A proxy like LiteLLM holds keys for every model provider you use and sees every prompt and response. A shell on that box is a shell on your AI spend, your customer data in prompts and often your internal network. It needs the same hardening as an identity provider: no public exposure, least-privilege keys, and logging that leaves the host.

Coding agents need a sandbox, not just a policy. The Codex exploit needed only one bug. Agents that run shell commands should work in isolated containers without production credentials, with outbound network access limited to an allowlist.

Vector stores hold more than embeddings. Chroma and similar databases usually store the source text next to the vectors, and that text often includes contracts, tickets or patient notes. Under GDPR and HIPAA, a breach there is a data breach. It is not a loss of “derived” data.

Your AI stack needs an inventory. You cannot patch what you do not know you run. Many teams have a gateway, an inference server and a vector store that were deployed during a pilot and never added to the asset list.

What to do now

  1. List every AI component in production and staging: gateways, inference servers, vector databases, agent runtimes. Record each one’s version and owner.
  2. Update to current releases of LiteLLM, Chroma and Dynamo, and watch their advisories closely over the next 90 days as the Pwn2Own fixes land.
  3. Remove public exposure. Put gateways and vector stores behind private networking and authentication, even for internal tools.
  4. Scope and rotate keys. Give each app its own provider key with a spend cap, so one compromised gateway does not expose every key you hold.
  5. Isolate coding agents in disposable containers with no production secrets and an egress allowlist.

Frequently asked questions

What is Pwn2Own Ireland?

Pwn2Own is a hacking contest run by Trend Micro’s Zero Day Initiative. Researchers exploit fully patched products live on stage for cash prizes, and the bugs are passed to vendors. The 2026 Ireland edition took place in Cork from 6 to 8 October.

Which AI tools were hacked at Pwn2Own Ireland 2026?

Researchers successfully exploited LiteLLM, OpenAI Codex, NVIDIA Dynamo, Chroma and Oracle Autonomous AI Database. Oracle’s database was breached five times, LiteLLM and Chroma twice each, and Codex and Dynamo once each.

Is LiteLLM safe to use after Pwn2Own?

The flaws were reported privately, and the vendors have 90 days to fix them before details are published. Keep LiteLLM updated, keep it off the public internet, give each app its own scoped provider key and watch the project’s security advisories.

What is a bug collision at Pwn2Own?

A collision means the exploit used at least one bug that the vendor or another researcher had already reported. It pays less, but it shows the flaw was known and still unpatched in the version on stage.

Sources

Zero Day Initiative — Pwn2Own Ireland 2026: Day One Results (6 October 2026)
Zero Day Initiative — Pwn2Own Ireland 2026: Day Two Results (7 October 2026)
Zero Day Initiative — Pwn2Own Ireland 2026: Day Three Results & Master of Pwn (8 October 2026)
BleepingComputer — Hackers exploit 32 zero-days on first day of Pwn2Own Ireland (6 October 2026)
BleepingComputer — Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland (8 October 2026)
Infosecurity Magazine — Pwn2Own Hackers Find 32 Zero-Day Vulnerabilities on Day One (7 October 2026)