Skip to main content
  1. Home
  2. Computing
  3. Web
  4. News

Hacker earns $225,000 at Pwn2Own 2015

Add as a preferred source on Google

The 2015 edition of Pwn2Own is over. Participants discovered an incredible 21 critical bugs, resulting in a combined payout of $557,500.

Almost half of the money went to Jung Hoon Lee, aka lokihardt, who demonstrated a nasty attack against Chrome. His hack started with a buffer overflow race condition and then, to break out of the security sandbox that’s supposed to keep exploits from spilling over to Windows, executed attacks against two separate Windows kernel drivers. By the time the dust as settled, Lee had gained full system-level access.

Recommended Videos

That was enough to make him $110,000 richer. He earned $75,000 for breaking into Chrome, $25,000 for escalating to a system-wide attack, and $10,000 for proving the attack works against both the stable and beta versions of the browser.

Lee also executed an attack against Internet Explorer 11 that earned him $65,000 and demolished Safari with an exploit and sandbox escape that earned him $50,000. In total he took home $225,000. Not bad for a two-day event!

As impressive as Lee’s attacks were, he didn’t earn the record for most won by a single competitor. That honor goes to a French firm called VUPEN, which earned $400,000 in 2014 by demonstrating a range of attacks against Chrome, Firefox, Internet Explorer, Adobe Reader and Adobe Flash that involved 11 zero-day exploits. VUPEN is an organization, though, not an individual; Lee’s winnings are the most earned by a single person thus far.

Pwn2Own is an annual hacking competition hosted by HP that’s been active since 2007. It’s meant to give hackers incentive to reveal new attacks to software developers before they’re used in the wild.

Matthew S. Smith
Matthew S. Smith is the former Lead Editor, Reviews at Digital Trends. He previously guided the Products Team, which dives…
Claude went rogue during a test and broke into three real companies
Claude website open on laptop

Just a few days after it was revealed that ChatGPT hacked multiple services, Anthropic has also published an uncomfortable admission. During routine cybersecurity testing, its Claude models broke out of what were supposed to be sealed-off practice environments and ended up hacking into the real systems of three different companies.

So what actually happened?

Read more
Google’s AI is digging up Chrome bugs that humans missed for years
Here's how Google is using Gemini AI to find, triage, and patch Chrome security bugs faster than ever.
Google Chrome safety feature.

I've always assumed Chrome's endless update notifications were just routine housekeeping with a batch of actually useful features every now and then. Turns out some of them are patching bugs that have been quietly sitting in the browser's code for over a decade.

So how exactly is AI catching these bugs?

Read more
The Best Password Managers for 2026
As online security evolves, so should the way you protect your accounts
password manager on a mac.

Think about how many online accounts you use in a typical week. Between work, banking, shopping, streaming, social media, and everything in between, it's easy to end up managing dozens of passwords. Remembering a different, secure password for every account simply isn't realistic, which is why so many people fall back on reusing the same login across multiple websites. That's a recipe for disaster, if you ask any cybersecurity expert.

If you're in a conundrum on how to safely handle digital privacy, password managers are a reliable solution. Rather than trying to remember every single password yourself, a credentials manager tool securely stores your login details, creates stronger passwords for new accounts, and automatically fills them in whenever you need them.

Read more