Skip to main content

Hacker earns $225,000 at Pwn2Own 2015

Pwn2Own 2015: Day 2 Highlights
The 2015 edition of Pwn2Own is over. Participants discovered an incredible 21 critical bugs, resulting in a combined payout of $557,500.

Almost half of the money went to Jung Hoon Lee, aka lokihardt, who demonstrated a nasty attack against Chrome. His hack started with a buffer overflow race condition and then, to break out of the security sandbox that’s supposed to keep exploits from spilling over to Windows, executed attacks against two separate Windows kernel drivers. By the time the dust as settled, Lee had gained full system-level access.

Recommended Videos

That was enough to make him $110,000 richer. He earned $75,000 for breaking into Chrome, $25,000 for escalating to a system-wide attack, and $10,000 for proving the attack works against both the stable and beta versions of the browser.

Please enable Javascript to view this content

Lee also executed an attack against Internet Explorer 11 that earned him $65,000 and demolished Safari with an exploit and sandbox escape that earned him $50,000. In total he took home $225,000. Not bad for a two-day event!

As impressive as Lee’s attacks were, he didn’t earn the record for most won by a single competitor. That honor goes to a French firm called VUPEN, which earned $400,000 in 2014 by demonstrating a range of attacks against Chrome, Firefox, Internet Explorer, Adobe Reader and Adobe Flash that involved 11 zero-day exploits. VUPEN is an organization, though, not an individual; Lee’s winnings are the most earned by a single person thus far.

Pwn2Own is an annual hacking competition hosted by HP that’s been active since 2007. It’s meant to give hackers incentive to reveal new attacks to software developers before they’re used in the wild.

Matthew S. Smith
Matthew S. Smith is the former Lead Editor, Reviews at Digital Trends. He previously guided the Products Team, which dives…
I tried out Google’s latest AI tool that generates images in a fun, new way
Google's Whisk AI tool being used with images.

Google’s latest AI tool helps you automate image generation even further. The tool is called Whisk, and it's based on Google’s latest Imagen 3 image generation model. Rather than relying solely on text prompts, Whisk helps you create your desired images using other images as the base prompt.

Whisk is currently in an experimental phase, but once set up it's fairly easy to navigate. Google detailed in a blog post introducing Whisk that it is intended for “rapid visual exploration, not pixel-perfect edits.”

Read more
Waymo is taking its robotaxis overseas for the first time
Waymo Jaguar I-Pace

Waymo is taking its robotaxis out of the U.S. for the first time as the company begins expanding testing internationally.

A fleet of its autonomous vehicles will be heading first to the busy streets of Tokyo early next year, Waymo announced on Monday.

Read more
The most innovative tech products of 2024
The most Innovative awards graphic.

392. That's how many tech products we've reviewed this year so far, and we're bound to cross the 400 mark by the time January 2025 rolls around.

The vast majority of these tech products take a more iterative approach to their design and technology. We're all familiar with the annual drum beat of small refinement, and don't get me wrong: over time, it produces the very best tech. The kind that we all rely on every day.

Read more