For the first time, the world's most prominent hacking contest put AI coding assistants on its target list. They did not last long. At Pwn2Own Berlin 2026, held alongside the OffensiveCon conference from 14 to 16 May, security researchers walked away with $1,298,250 after demonstrating 47 previously unknown vulnerabilities, and the tools that have reshaped how software gets written were among the casualties.

The opening day set the tone. Researchers earned $523,000 for 24 zero-days, and a cluster of those bugs landed squarely on the AI stack, according to Security Affairs.

The AI toolchain becomes a target

OpenAI's Codex was compromised by two independent teams, Compass Security and maitai of Doyensec, each collecting $40,000. The researcher k3vg3n chained a server-side request forgery flaw with a code injection bug to break LiteLLM, a widely used model-routing library, for another $40,000. STARLabs SG took $40,000 for an exploit against LM Studio, the popular desktop app for running models locally. Satoki Tsuji of Ikotas Labs picked apart NVIDIA's Megatron Bridge through an overly permissive allow list, and the vector database Chroma fell to a researcher going by haehae. Anthropic's Claude Code and the Cursor editor were also on the schedule, per BleepingComputer.

The pattern matters more than any single bug. These are not the chatbots most people picture. They are the plumbing of modern AI development: routers, local runtimes, vector stores, and the agents that read and write code on a developer's behalf. Each new component is another door, and Berlin showed how many of those doors were unlocked.

The old guard still ran the scoreboard

AI tools were the newcomers, but the biggest rewards still went to classic enterprise targets. Taiwan's DEVCORE won the Master of Pwn title with 50.5 points and $505,000, and its researcher Orange Tsai earned the event's single largest payout of $200,000 by chaining three bugs into remote code execution with SYSTEM privileges on Microsoft Exchange. STARLabs SG finished second with $242,500.

What happens next

Every vulnerability shown at Pwn2Own is disclosed privately to the vendor, which then has 90 days to ship a fix before the details go public, under the Zero Day Initiative's rules. So the Codex, Claude Code and LiteLLM flaws are already in the hands of the companies that need to patch them.

The lesson for anyone wiring these tools into a production workflow is worth sitting with. An AI agent that can run commands, fetch URLs and edit files is powerful precisely because it can act, and that is the same reason it widens the blast radius when something goes wrong. We covered OpenAI's new governance framework for frontier models last week. Berlin is a reminder that governance has to reach down into the everyday developer tooling too, not just the headline models.

Sources

  1. i. securityaffairs.com
  2. ii. www.bleepingcomputer.com
  3. iii. www.thezdi.com
  4. iv. hackread.com

Commentarii · 0

Add · a · Comment