Pwn2Own Winners Announcement
OffensiveCon Staff (OffensiveCon / Zero Day Initiative)
OffensiveCon 2025 · Day 2 · Main · Briefings
Overview
Pwn2Own Berlin 2025, held concurrently with OffensiveCon for the first time, awarded $1,078,750 across three days of competition. StarLabs SG from Singapore won the Master of Pwn title with $320,000 and 35 points across six categories, defeating competitors who demonstrated zero-days in ESXi, VirtualBox, and a newly introduced AI category targeting NVIDIA and Redis tooling. ---

Key moments
- 1:33 $1.078M total payout announced — record Pwn2Own prize pool
- 2:00 ESXi attracted two separate exploits for first time
- 3:02 VirtualBox chain: guest OS to host kernel in single exploit
- 4:04 First-ever AI category debut targets NVIDIA Triton and Redis
- 4:30 2,000 lbs of equipment arrived 18 hours before contest start
- 5:44 Viettel nearly missed contest entirely due to visa complications
- 6:11 StarLabs SG wins Master of Pwn, $320,000, 35 points
- 7:17 StarLabs: two present, four members exploited targets from Singapore
Pwn2Own Berlin 2025: $1.08 Million Awarded as StarLabs SG Claims Master of Pwn
Speakers: Dustin Childs and Brian Gorenc (Trend Micro Zero Day Initiative)
Conference: OffensiveCon 2025 — May 16–17, 2025, Berlin
YouTube: https://www.youtube.com/watch?v=kF31SYIVob8
Reading time: ~5 minutes
TL;DR
Pwn2Own Berlin 2025, held concurrently with OffensiveCon for the first time, awarded $1,078,750 across three days of competition. StarLabs SG from Singapore won the Master of Pwn title with $320,000 and 35 points across six categories, defeating competitors who demonstrated zero-days in ESXi, VirtualBox, and a newly introduced AI category targeting NVIDIA and Redis tooling.
Introduction
For the first time in Pwn2Own's nearly two-decade history, ZDI moved its flagship competition out of Vancouver and co-located it with OffensiveCon in Berlin. The format shift was more than logistical: by pairing the contest with one of Europe's premier offensive security conferences, ZDI introduced Pwn2Own to an audience that doesn't always overlap with the North American circuit. The result was an energetic, high-stakes competition that saw zero-day exploits demonstrated against virtualization software, AI infrastructure, and enterprise platforms — and a total payout surpassing $1 million.
Dustin Childs, Head of Threat Awareness at Trend Micro ZDI, and Brian Gorenc, VP of Threat Research at Trend Micro, took the stage at OffensiveCon to announce the results. The announcement highlighted not just the winners but also the contest's evolution, including the debut of an AI/ML category and the particular significance of two successful ESXi exploits.
The Numbers: Over $1 Million in Three Days
The final payout of $1,078,750 across three competition days marked one of the most lucrative Pwn2Own events in recent memory. ZDI shipped nearly 2,000 pounds of equipment from North America to Germany — equipment that was supposed to arrive the Friday before the Thursday contest start date but arrived only the Wednesday night prior at 6:30 PM, leaving organizers scrambling to configure networks, install software licenses, and prepare judging infrastructure overnight.
Despite the logistical pressure, Childs and Gorenc noted that the competition ran cleanly, crediting Binary Gecko and the OffensiveCon team for their support as hosts.
ESXi: A Long-Awaited Target Opens Up
▶ Watch: ESXi Discussion (2:00)
VMware ESXi has been included in Pwn2Own for several years, but historically attracted few registrations. Berlin 2025 was different: two separate teams submitted ESXi exploits. Gorenc attributed the uptick partly to a VMware ESXi vulnerability disclosed in the wild roughly two months before the contest, which may have directed researchers' attention toward the hypervisor's attack surface.
Broadcom (which now owns VMware) was actively involved in the judging process, recommending specific hardware and software builds, assisting with last-minute configuration issues, and participating in disclosure. Childs noted the vendor's engagement as a model for how platform vendors can support the responsible disclosure ecosystem without impeding the competitive dynamics of the contest.
VirtualBox: Guest-to-Kernel-Level Compromise
▶ Watch: VirtualBox Chain (2:50)
One of the technically most notable demonstrations involved Oracle VirtualBox. A competitor achieved not only a guest-to-host escape — crossing the hypervisor boundary from a guest operating system to the underlying host — but also escalated privileges to kernel level on the host OS, all within a single exploit chain.
ZDI's "add-on" scoring mechanism was invoked for this entry: contestants who extend their exploit chain with additional unique zero-days earn bonus prize money. The VirtualBox chain qualified because each component represented a distinct, previously unknown vulnerability. Gorenc described it as "very exciting stuff," noting that going from guest execution to kernel-level access on the host in one chained exploit is a rare and technically demanding achievement.
The AI Category Debut
Berlin 2025 marked the first time ZDI ran a dedicated AI/ML infrastructure category. Targets included the NVIDIA Container Toolkit, NVIDIA Triton inference server, Redis, and Chroma (a vector database). The NVIDIA Triton server attracted the most entries, with multiple teams independently finding and exploiting vulnerabilities in it.
Wiz Research finished fifth overall with $70,000 and seven Master of Pwn points — the highest point total specifically within the AI category. The AI category's debut signals that ZDI, and the broader research community, view AI/ML infrastructure as a serious attack surface deserving structured competitive scrutiny.
The Top Five and Master of Pwn
▶ Watch: Top Five Winners (4:30)
The final standings were:
- StarLabs SG — $320,000, 35 Master of Pwn points
- Viettel Cybersecurity — $155,000 (nearly didn't compete due to visa issues)
- Reverse Tactics — $112,500, 11.25 points
- Synacktiv — $80,000 (VMware Workstation exploit on day three)
- Wiz Research — $70,000 (AI category leader)
StarLabs SG, a Singapore-based research team, won the Master of Pwn title with exploits spread across six categories. In their acceptance speech, Gerard from StarLabs clarified that only two team members were physically present in Berlin — each responsible for a single target — while the remaining four attempts were the work of colleagues back in Singapore: Leti, Billy, Ramdan, Niren, Zung, and Bruce. The team expressed gratitude to their director, Jacob, and promised to return in 2026.
▶ Watch: StarLabs Acceptance (6:00)
Viettel Cybersecurity, a former Master of Pwn winner, finished second despite significant visa complications that nearly prevented their participation altogether.
Looking Ahead
▶ Watch: Closing Remarks (8:00)
Childs and Gorenc used the closing minutes to encourage more researchers from the OffensiveCon audience to register for future Pwn2Own events, emphasizing that ZDI is open to communication early in the process about target configurations and hardware requirements. They also acknowledged that T-shirt and sticker supplies were severely underestimated — a problem they committed to fixing for 2026.
The decision to host Pwn2Own at OffensiveCon reflects a deliberate effort by ZDI to expand the competitive landscape into Europe's elite offensive security community. With over $1 million awarded, two ESXi exploits, a VirtualBox guest-to-kernel chain, and the first AI-category competition, Berlin 2025 established a strong precedent for the format.
Notable Quotes
"One million seventy-eight thousand seven hundred and fifty dollars awarded over three days of competition, and that's a lot, so that's great." — Dustin Childs ▶ 0:46
"To go from a guest OS to the host OS, and not only then execute code, but then pop the kernel underneath — going from guest to kernel-level access all in one exploit chain. Very exciting stuff." — Brian Gorenc ▶ 2:50
"Both of us only had a single target each. The remaining four targets are the efforts of the rest of our team back at StarLabs." — Gerard, StarLabs SG ▶ 6:15
Key Takeaways
- Pwn2Own Berlin 2025 awarded $1,078,750 across three days — one of the highest payouts in the contest's history — with StarLabs SG claiming Master of Pwn at $320,000 and 35 points.
- ESXi attracted two separate exploit submissions in Berlin after years of low registration, partly driven by a real-world VMware vulnerability disclosed two months prior.
- A single VirtualBox exploit chain crossed from guest OS to host kernel level, demonstrating that hypervisor escape and local privilege escalation can be combined into one integrated attack.
- The debut AI/ML category — targeting NVIDIA Triton, NVIDIA Container Toolkit, Redis, and Chroma — saw heavy participation, with NVIDIA Triton being the most contested target.
- OffensiveCon Berlin is now established as the European home of Pwn2Own, with ZDI committing to return and expand the event in 2026.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
This is a press release with a podium, not a research talk. ZDI announcing its own competition results at the conference it co-hosted is the definition of a conflict of interest dressed up as content. The technical highlights — ESXi exploits, a VirtualBox guest-to-kernel chain, the AI category — are real and interesting, but none of the actual research is presented here.
Heather Calloway (CISO) — WEAK
Pwn2Own Berlin 2025 wrapped with $1.08M in payouts and the debut of an AI/ML attack category — NVIDIA Triton was the target. The competition format produces real, validated vulnerabilities, and the AI category entry is a meaningful signal about where the industry is acknowledging attack surface. But as reported here, it stays at competition recap rather than consequence analysis.