Technology

A Million-Dollar Challenge: Find a Zero-Click Exploit in WhatsApp at Pwn2Own!

2025-08-04

Author: John Tan

Security Showdown: Pwn2Own Offers Unprecedented Prize

Attention, cybersecurity enthusiasts! The Pwn2Own competition is set to return to Cork with a jaw-dropping $1 million prize for those who can uncover a zero-click exploit in WhatsApp. This isn’t just another hacking challenge; it’s a golden opportunity for researchers to showcase their skills and potentially cash in big!

Zero-Click Exploits: The Holy Grail of Hacking

Organized by Trend Micro’s Zero Day Initiative (ZDI), the competition has specific criteria: only zero-click vulnerabilities that lead to code execution will be eligible for the million-dollar bounty. Smaller prizes will also be available for other types of WhatsApp exploits, making it a thrilling event for all types of hackers.

A Million-Dollar Motivation?

Dustin Childs, head of threat awareness at ZDI, expressed hope that the allure of a hefty cash prize will encourage participation. "We introduced this category last year, but it didn’t attract any interest. Perhaps a number with two commas will provide the needed motivation," he stated. With a million on the line, interest is sure to spike!

Event Highlights: What to Expect at Pwn2Own 2023

Running from October 21 to 24, this year’s Pwn2Own marks the second occurrence of the competition in Ireland. The event will focus on various consumer products across eight categories, including: - Mobile Phones - Messaging Apps - Smart Home Devices - Surveillance Systems - Printers - NAS Devices - Wearables - The SOHO Smashup.

Big Sponsors, Bigger Stakes!

Meta leads the sponsorship this year, joined by Synology and QNAP, contributing both funds and technical support to contestants. This event is more than just a competition; it's a collaborative effort to enhance security across popular consumer technology.

Responsible Disclosure and Virtual Patches

As always, the goal is to encourage the world's most talented security researchers to find vulnerabilities, which will then be responsibly disclosed for vendors to address. In the meantime, Trend Micro will provide virtual patches to protect its customers until full fixes are deployed.

A Twist in Mobile Security!”},{