THE PWN2OWNTM CONTEST ("CONTEST") IS CONDUCTED SOLELY IN ACCORDANCE WITH AND SHALL BE CONSTRUED AND EVALUATED ACCORDING TO APPLICABLE LAW. THE CONTEST IS VOID IN WHOLE OR PART WHERE PROHIBITED BY LAW. ENTRY IN THIS CONTEST CONSTITUTES ACCEPTANCE OF THESE CONTEST RULES (THE "CONTEST RULES"). TREND MICRO INCORPORATED ("TREND MICRO") IS THE SPONSOR OF THIS CONTEST ("SPONSOR").

1. ELIGIBILITY.

Employees of Trend Micro Incorporated, and their respective affiliates, subsidiaries, related companies, advertising and promotional agencies, and the household members of any of the above are not eligible to participate in the Contest. This Contest is void where prohibited by law.

Contestants must be at the age of majority in their country, province or state of residence at the time of registration in order to participate and may not be a resident of any United States embargoed or sanctioned country or otherwise be listed on any United States denied or barred persons list. Any software or technology that attendees bring or cause to be transferred for purposes of the Contest to the country in which the Contest is held (“Contest Location”) may be subject to the export controls of attendee's country of residence or travel origin or subject to the import and export requirements of the Contest Location. Attendees are responsible for compliance with any applicable import and export controls as a result of their attendance at the Contest.

Sponsor shall have the right at any time to require proof of identity and/or eligibility to participate in the Contest. Failure to provide such proof may result in disqualification. All personal and other information requested by and supplied to the Sponsor for the purpose of the Contest must be truthful, complete, accurate, and in no way misleading. The Sponsor reserves the right, in its sole discretion, to disqualify any contestant should such contestant at any stage supply untruthful, incomplete, inaccurate, or misleading personal details and/or information.

If you are a public sector employee, it is critical that you verify the ethics code, laws, and/or regulations that govern your ability to accept items of value from companies with whom you conduct business. Please obtain the necessary approval from your organization before participating in the Contest and/or accepting any item of value from Sponsor. In addition, public-sector employees, employees of K-12 public and private education institutions and all libraries, including public, private school, college or university, research, and private libraries can participate in the Contest only if you are doing so outside of your official status and not as part of your employment with those entities.

2. CONTEST PERIOD.

The Contest will be held October 6th– 9th, 2026 in Cork, Ireland.

3. HOW TO ENTER.

This Contest is open to all but is subject to the eligibility requirements herein.  No purchase is required to participate in the Contest. Contestants must be on-site at the Contest location to demonstrate their entry.

The contestant can register for the contest by contacting Sponsor via e-mail at pwn2own@trendmicro.com and indicating in which categories the contestant wishes to participate.

All contestants must sign up for a TrendAITM Zero Day InitiativeTM ("ZDI") Researcher account in order to participate.

Eligibility. Contestants must have received aggregate bounty payment from the Sponsor totaling at least $15,000 during their life-time participation in the TrendAITM Zero Day InitiativeTM Researcher Program. Notwithstanding the foregoing, the Sponsor may accept up to ten (10) entry registrations from individuals, teams or companies who have not satisfied this eligibility requirement, in Sponsor’s sole discretion.

The contestant can register multiple entries for a given category, but each entry must be for a different target in that category (See Section 4 below for categories, targets, and prizes). The contestant can only register once per target. The contestant may only register up to a maximum of 5 entries across all categories. Every entry must be a separate and unique exploit chain. Specific details about the targets (software, versions, configurations, chipsets, etc.) will be communicated to contestants during the registration process. If the contestant represents a company, they must identify which company they represent during the registration process. Each company is limited to one registration. Each contestant may only register once as either an individual, a team or company.

The Sponsor reserves the right to deny registration to entries that do not comply with the rules during the registration process. To complete registration, you must complete the Registration Questionnaire form along with opening a placeholder case and complete a Case Entry form for each target you are registering against. Contest registration closes upon the earlier of: (i) the receipt of eighty (80) complete registrations or (ii) at 5:00 p.m. Irish Standard Time on October 1st, 2026.

4. PRIZES.

Trend Micro is offering cash and prizes during the competition for vulnerabilities and exploitation techniques against the listed targets in the categories below. The first contestant to successfully compromise a target within the selected category will win the prize amount indicated for that specific target. All prizes are in US currency.

Sponsor reserves the right, in its sole discretion, to add or modify the device list if a new version of one of the devices is released, recalled, or reaches end-of-life between the release of the rules and the contest.

Categories and Prizes:

The contest has seven categories consisting of:

Each category has a set of targets that can be selected by the contestant during the registration process. All entries must compromise the target(s) and demonstrate arbitrary code execution or retrieve sensitive information (as defined by the Sponsor during the registration process) from the target(s).

If the contestant's attempt is successful, it might be eligible for an Add-on Bonus. This Add-on Bonus results in additional monetary prizes and Master of Pwn points. The contestant must identify which Add-on Bonus they are attempting during the registration process. It is possible to remove the Add-on bonuses during the attempt as long as the attempt meets the requirements of the original category without the Add-ons. If the Add-on bonus is removed during the attempt, this will impact the potential Master of Pwn points award as defined in the Master of Pwn section below.  The eligibility requirements for the various Add-on Bonuses are documented in each category below.

Mobile Phone Category

Target

Vector

Cash Prize

Master of Pwn Points

Samsung Galaxy S26

Remote

$50,000 (USD)

5

USB

$35,000 (USD)

3.5

Google Pixel 10

Remote

$300,000 (USD)

30

USB

$75,000 (USD)

7.5

Apple iPhone 17

Remote

$300,000 (USD)

30

USB

$75,000 (USD)

7.5

 

USB-based attacks must target the USB port that is openly exposed to the end user. Any other exposed USB ports and target disassembly are not in scope. The target will remain locked during the attack. The target can be either in “Before First Unlock” state or in “After First Unlock” state when starting the attempt. Spoofing attacks that use synthetic biometric data (fake masks, fingerprints, etc.) are not eligible.

 

A successful entry for the USB vector must either obtain arbitrary code execution or unlock the target and allow the attacker to further interact with the target in an unrestricted login session.

 

A successful entry for the Remote vector must compromise the device by browsing to web content in the default browser for the target under test or by communicating with the following radio protocols: near field communication (NFC), Wi-Fi, Bluetooth, or Baseband.

Smart Home Category

An attempt in this category must be launched against the target’s exposed network services, RF attack surface, or exposed features from the contestant’s laptop within the contest network

 

 

Target

Vector

Cash Prize

Master of Pwn Points

Philips Hue Bridge Pro

Remote Code Execution

$40,000 (USD)

4

Home Assistant Green

Remote Code Execution

$30,000 (USD)

3

Sonos Era 300

Remote Code Execution

$50,000 (USD)

5

 

Entries that require physically pressing any button on the target, or the use of any information, code or PIN printed on the device, are out of scope. Entries that require the contestant to be paired to the target prior to the start of the attempt is not in scope.

 

Wellness Category

An attempt in this category must be launched against the target’s exposed network services, RF attack surface, or exposed features from the contestant’s laptop within the contest network.

Target

Vector

Cash Prize

Master of Pwn Points

Dexcom Stelo

Remote Code Execution

$20,000 (USD)

2

Garmin Index BPM

Remote Code Execution

$20,000 (USD)

2

Oura Ring 5

Remote Code Execution

$20,000 (USD)

2

 

Entries that require physically pressing any button on the target, or the use of any information, code or PIN printed on the device, are out of scope. Entries that require the contestant to be paired to the target prior to the start of the attempt are not in scope.

 

Entries that require the contestant to be paired with the target device prior to the start of the attempt are not in scope.

Printer Category

An attempt in this category must be launched against the target’s exposed network services from the contestant’s device. 

Target

Vector

Cash Prize

Master of Pwn Points

Lexmark CX532adwe

Remote Code Execution

$20,000 (USD)

2

Canon imageFORCE 1643F Multifunction Copier

Remote Code Execution

$20,000 (USD)

2

Brother MFC-L8970CDW

Remote Code Execution

$20,000 (USD)

2

 

 

Messaging Category

All valid entries must use vulnerabilities reachable via WhatsApp and must not depend on other applications. An attempt in this category requires the contestant to compromise the target device and get arbitrary code execution by communicating with the targeted WhatsApp client running on the targeted device.

Target

Options

Cash Prize

Master of Pwn Points

WhatsApp

Zero-Click
Remote Code Execution

$300,000 (USD)

30

One-Click
Remote Code Execution

$200,000 (USD)

20

 

Available target devices and target WhatsApp clients are documented below:

WhatsApp Client

Target Device

Android Consumer

Android Business

Samsung Galaxy S26

Google Pixel 10

iOS Consumer

iOS Business

Apple iPhone 17

 

 

Zero-Click / One-Click

 

A Zero-Click entry should require no user interaction in order to trigger the exploit chain. If required, the target device can be pre-staged to be viewing the conversation thread with the attacker.

 

A One-Click entry may require multiple taps from the victim, but performs one logical action. For example, if upon tapping a media file WhatsApp presents a warning dialog that must be accepted/dismissed to trigger a bug, this is a valid entry requiring two taps but one logical action. A victim accepting a VOIP call and sharing their screen is two or more taps, but at least two logical actions and is not a valid entry. Sponsor reserves the right, in its sole discretion, to determine what is a logical action and will be agreed to with the contestant during the registration process.

 

Examples of invalid entry include:

·      A zero-click information disclosure obtained via SMS from the target device’s default SMS application chained with an RCE vulnerability in WhatsApp.

·      A one-click exploit delivered via a media file that must be opened in another application on the target device.

 

If required, the contestant is allowed to add the attacker phone number to the victim’s contacts before attempting their entry. Additionally, a vulnerability only reachable when viewing a chat thread does not count against the number of clicks. For example, an exploit chain that is only triggered while viewing a chat thread will still be considered a zero-click exploit. If that exploit chain requires interacting with a message, such as tapping on an image or playing a video, it is considered one-click.

Zero-Click / One-Click Remote Code Execution

 

An entry targeting the Zero-Click / One-Click Remote Code Execution option must be demonstrated on the WhatsApp Consumer client and are limited to the following target devices:

·      Samsung Galaxy S26

·      Google Pixel 10

·      Apple iPhone 17

 

A valid remote code execution entry may target vulnerabilities in any code WhatsApp depends on that is loaded into its application’s address space, including those provided by the target platform operating system.

If an exploit chain targets WhatsApp resources (code or data) and requires an application restart to trigger some part of the exploit chain, an application restart is permitted in order to trigger the required condition so long as no further user interaction is required beyond launching the application again.

All Other Options


An entry targeting the Remote Zero-Click Account Take-over option, the entry must demonstrate the ability to receive messages sent to the target device by registering as their phone without having access to confirmation codes. Social engineering is not within the scope of the contest.

An entry targeting the Remote Zero-Click Access to Microphone or Video Feed option, the entry’s payload must access the raw microphone or video feed of the target device without any user interaction.

An entry targeting the Remote Zero or One-Click Access to User Sensitive Data option, the entry must leak the chat history, backup, the user’s exact location or media the WhatsApp app has access to via a vulnerability in WhatsApp. Leaking through cloud storage is not in scope.

An entry targeting the Zero-Click Impersonation of Other Users option, the entry must demonstrate the ability to modify other user’s messages, or send a message as another user, or the appearance of doing so. The message must show up on the UI as a separate chat bubble, originating from the impersonated account. Replies and quoted messages are not in scope.

AI Infrastructure Category

An attempt in this category must be launched from the contestant’s laptop within the contest network

Target

Prize

Master of Pwn Points

Chroma

$20,000

2

Postgres pgvector

$30,000

3

Oracle Automatous AI Database

$40,000

4

LiteLLM

$40,000

4

Dynamo

$40,000

4

 

The Dynamo target will be installed on Ubuntu 24.04 x64.

 

Authentication mechanism will be configured if available. A successful entry in this category must bypass authentication of the target.

 

Coding Agent Category

A successful entry must interact with a contestant-controlled resource (e.g. web page, repository, media file) to exploit a vulnerability within the coding agent. The attack vector of the entry must be a common coding agent use case. An attempt must obtain arbitrary code execution and perform actions outside of target’s intended sandbox and permissions boundaries.

An entry in this category may require multiple user interactions with the target to demonstrate the vulnerability. An entry may leverage the use of read-only tools. Other permitted contestant/target interactions will be determined during the registration process at the sole discretion of the Sponsor.

The target will be running in its default configuration and will be installed on  Microsoft Windows 11 25H2. Sandbox and isolation features will be enabled in their default configuration; no unsafe execution modes (e.g., --dangerously-skip-permissions or equivalent) will be active.

The following are out of scope:

·      UI spoofing or misrepresentation unrelated to permission prompts

·      Model jailbreaks or prompt outputs that do not cross security boundaries

·      Vulnerabilities that require unsafe or permissionless modes

·      Exploitation of intended functionality of the target. Intended functionality of the target or its underlying development tools (e.g., git hooks, filter drivers, fsmonitor).Underlying tool functionality may be used as an exploitation technique or to demonstrate code execution. A valid entry must  leverage a separate, qualifying vulnerability in the coding agent itself.

·      Use of aliased commands or other environment-configured settings (e.g., stored credentials) to bypass permission prompts

·      Third-party extensions or MCP servers not bundled with the target

·      Prompts that coerce a model into performing malicious actions. Prompts for an in-scope entry should be model-agnostic.

 

Permitted Attack Scenarios:

An entry in the Coding Agent Category must conform to one of the following permitted attack scenarios. The specific scenario for each entry will be confirmed during the registration process. Sponsor reserves the right, in its sole discretion, to accept or reject any proposed attack scenario  during registration.

CLI - Trusted Workspace.

·      The target coding agent will be pre-configured and running in a Sponsor-designated trusted directory (e.g., `C:\Users\<user>\Desktop\zdi_trusted\`). The entry must exploit a vulnerability in the coding agent within a single continuous coding agent session. The contestant must provide the required steps in detail. The contestant must not terminate, restart, or re-initialize the target coding agent during the attempt. All exploit actions must occur within the boundaries of that single session. Permitted prompts are limited to  common-use-case commands and benign instructions to the coding agent.     

CLI - Untrusted Workspace

·      The attempt begins by launching the target coding agent in a contestant-controlled repository that has not been granted trust. The entry must exploit a vulnerability in the coding agent's code flow prior to or during the display of any trust or permission prompt. The contestant may not manually grant trust to the repository prior to or during the attempt.

GUI - Project Open

·      The attempt begins by opening a contestant-controlled project in the target coding agent. The entry must exploit a vulnerability triggered by the target's processing of the project contents prior to or during the display of any trust or permission prompt.

Other Vectors

Entries leveraging alternative attack surfaces (e.g., deeplink or URI handlers, web content processed by the target, protocol handlers) are eligible provided the entry exploits a vulnerability in the coding agent and meets all other requirements of this category. Contestants must describe the proposed attack scenario in detail during registration. Acceptance of alternative attack scenarios is at the sole discretion of the Sponsor.

Target

Prize

Master of Pwn Points

Anthropic Claude Code

$40,000

4

OpenAI Codex

$40,000

4

 

Master of Pwn:

The contestant with the highest total points at the end of the contest ("Master of Pwn") will receive 65,000 ZDI reward points (estimated at $25,000 (USD)). Total points are calculated by the sum of the successful entries based on the allocated Master of Pwn points in the tables above.

For example, if a contestant has a successful remote vector entry on the Google Pixel 10 and a successful remote vector entry in the Apple iPhone 17 then their total points would be 60. If two or more contestants have the same number of points at the end of the contest, each of these contestants will receive 65,000 ZDI reward points (estimated at $25,000 (USD)).

If the contestant decides to remove an Add-on Bonus during their attempt, the Master of Pwn points for that Add-on Bonus will be deducted from the final point total for that attempt. If the contestant decides to withdraw from the registered attempt after the start of the contest, the Master of Pwn points for that attempt will be divided by 2 and deducted from the contestant's point total for the contest.

Along with the prize money, the first-round winner for a given category will win the device (estimated value of $500 (USD)) unless otherwise stated in the Category description in Section 4. Winners of these prizes are not entitled to the difference, if any, between the actual prize value and the estimated prize value. The estimated prize value is as of the date of printing of these Contest Rules.

It is possible that a category may have no winner. If a category has no winner, Sponsor may, in its sole discretion, choose to use the prize money from that category to offer additional prize(s) in another above listed category that may be equal to or less than the initial prize offering for such category. The odds of winning depend on the number of eligible participants in a category and the ability to meet the requirements of this skills-based Contest. Prizes will be distributed within eight (8) weeks after each winner has fulfilled the requirements set out herein.

Prizes must be accepted as awarded and cannot be transferred, assigned, substituted, or redeemed for cash except at the sole discretion of Sponsor. Any unused portion of a prize will be forfeited and has no cash value. Sponsor reserves the right, in its sole discretion, to substitute a prize of equal or greater value if a prize (or any portion thereof) cannot be awarded for any reason. Taxes on prizes, if any, are the sole responsibility of the winner.

Sponsor reserves the right, in its sole discretion, to add or modify the categories if a new version of one of the targets or devices are released, updated, hardened, updated, or recalled between the release of the Contest Rules and the Contest.

The Sponsor shall not assume any liability for any lost or misdirected prizes.

5. WINNER SELECTION.

If more than one contestant registers for a given category, the order of the contestants will be drawn at random. Based on the contestant order, the first contestant will be given an opportunity to attempt to compromise the selected target. If unsuccessful, the next randomly drawn contestant will be given an opportunity. This will continue until a contestant successfully compromises the target using an entry that meets all the requirements of a successful entry defined below. The first contestant to successfully compromise a selected target with a successful entry will win the prize money for that target in the category. After a winner of a target has been determined, the contest for that category is over and no other contestants will participate in the contest for that category (unless Sponsor has offered an additional winner option, which would be announced at the Contest, if applicable).

A successful entry must leverage a vulnerability to modify the standard execution path of a program or process in order to allow the execution of arbitrary instructions. The entry is required to defeat the target's techniques designed to ensure the safe execution of code, such as, but not limited to, Data Execution Prevention (DEP), Address Space Layout Randomization (ASLR) and/or application sandboxing. If a sandbox is present, a full sandbox escape is required unless otherwise stated in the Category description in Section 4.

The sensitive information that the exploit must retrieve is defined by the Sponsor and will be information normally inaccessible from the application's sandbox. The exact details of the information to retrieve in the attempt will be communicated to the contestant prior to the contest.

A contestant has up to three (3) attempts to succeed. Each of the three (3) attempts will be individually limited to a time period of ten (10) minutes. For an attempt to be deemed successful, all elements of the attempt must complete within the 10-minute attempt window. All three (3) attempts must be completed within thirty (30) minutes, excluding the time needed to setup the device prior to the attempt. Notwithstanding the foregoing, Sponsor may extend a contestant’s time period, in Sponsor’s discretion. For example, if during an attempt, the contestant experiences any connection issues caused by inaccessible or unavailable networks, servers, Internet Service Providers, or other connections that are outside of contestant’s or Sponsor’s control.

If the attempt to compromise the target is unsuccessful, the execution of all exploit scripts and programs must be terminated. After a failed attempt, the contestant may forgo attempt time window(s) in the remaining 30-minute window to troubleshoot and modify their exploit. During this troubleshoot period, the target may be turned off or disconnected from the contest network.

A successful entry against these targets via a contestant-initiated attempt must require no user interaction beyond the action required to launch the attempt and must occur within the user's session with no reboots, or logoff/logons. For example, having to interact with a dialog in order to successfully complete the exploit or writing a malicious file to the Startup folder is not allowed. attempt is not allowed.

A successful entry against these targets via a contestant-initiated attempt must be fully automated and launched in one command. The contestant is not allowed to interact with the exploit after the attempt has started. For example, manually copying the leaked admin password from the output of the first stage of the exploit, pasting the password as a parameter in the terminal to manually launch a second stage exploit is not allowed. After an attempt has started, the contestant is only allowed to interact with the exploit again to demonstrate execution of arbitrary instructions on the target to the Sponsor. Unless prior agreed to with the Sponsor, any other interactions with the exploit after an attempt has started shall be deemed as declaration of unsuccessful attempt by the contestant.

The initial vulnerability utilized in the entry must be in the registered target.  The sandbox escape utilized in the entry must be in the registered target (unless the entry leverages a kernel privilege escalation). All vulnerabilities in the entry must be in the Sponsor installed version of the software or firmware of the target.

A given vulnerability may only be used once across all categories. The vulnerabilities utilized in the attack must be unknown, unpublished, and/or not previously reported to the vendor or the Sponsor. If the entry leverages a previously known vulnerability, as evidenced by the vendor or Sponsor, Sponsor may, in its sole discretion, choose to accept the entry(ies) and offer the prize(s) at a value less than the initial prize offering for a given category.

If authentication is present, the exploit must occur prior to authentication to the service or include an authentication bypass. If the entry requires a man-in-the-middle attack, ARP spoofing attack, or software downgrade attack, Sponsor may, in its sole discretion, choose to accept the entry(ies) and offer the prize(s) at a value less than the initial prize offering for a given category. Contestants may contact the Sponsor prior to the Contest to obtain a determination regarding prize eligibility for proposed entries that require such techniques.

The targets will be running on the latest, fully patched version of the operating system available on the selected target (Apple iOS, Google Android, Red Hat Enterprise Linux, etc) unless otherwise specified in the Category description in Section 4. All targets will be installed in their default configurations and fully operational state when the attempt begins. All targets will be fully set up and configured in their normal operating states. Entries that require the target to be in an initial-setup, pairing, or otherwise uninitialized state are out of scope. Sponsor reserves the right, in its sole discretion, to allow non-default configurations if the Sponsor deems them to be in the normal use case of the target under test. 

Whitepaper Requirements

A whitepaper for a successful entry must include all of the following criteria:

·      The whitepaper must be provided in Markdown format.

·      The whitepaper must describe any preconditions that affect the success of the entry.

·      The whitepaper must detail the steps required to execute the exploit.

·      The whitepaper must provide explanation(s) for all exploit techniques used in the entry.

·      The whitepaper must include all relevant version information of the target.

·      The whitepaper must include the Common Weakness Enumeration (CWE) categorization for each of the vulnerability(ies) within the entry.

·      The whitepaper must contain code listing(s) of the vulnerability mechanism for each of the vulnerability(ies) used in the entry.

·      All code listing(s) must include contain line number(s).

·      All code listing(s) must be provided in text. Code listing(s) provided in image format is not acceptable.

·      The whitepaper must include contestant-authored comment(s) on the provided code listing(s), highlighting vulnerability mechanism(s).

 

Upon successful demonstration of the exploit, the contestant will immediately provide Sponsor with a fully functioning exploit, a whitepaper, PCAP files, and associated artifacts explaining the vulnerabilities and exploitation techniques used in the entry. In the case that multiple vulnerabilities were exploited to gain code execution, details about all of the vulnerabilities (memory corruption, infoleaks, privilege escalations, etc.) leveraged and the sequence in which they are used must be provided to receive the prizes. Vulnerabilities and exploit techniques revealed by contest winners will be disclosed to the affected vendors and the exploits and whitepapers will become the property of the Sponsor in accordance with the ZDI researcher agreement. Failure to provide a whitepaper will be deemed as an incomplete entry and the entry will be disqualified from the Contest.

Sponsor reserves the right to solely determine what constitutes a successful entry. The Sponsor may, in its sole discretion, choose to accept the entry(ies) and offer the prize(s) at a value less than the initial prize offering for a given category if the Sponsor deems that part of the exploit chain fails to meet the above rules.  For example, if the entry contains a previously known vulnerability, and the vendor has not yet released a patch, Sponsor may accept the entry(ies) and offer the prize(s) at a value less than the initial prize offering for a given category.

6. INDEMNIFICATION BY CONTESTANT.

By entering the Contest, contestant releases and holds Sponsor harmless from any and all liability for any injuries, loss, or damage of any kind to the contestant or any other person, including personal injury, death, or property damage, resulting in whole or in part, directly or indirectly, from acceptance, possession, use, or misuse of any prize, participation in the Contest, any breach of the Contest Rules, or in any prize-related activity. The contestant agrees to fully indemnify Sponsor from any and all claims by third parties relating to the Contest, without limitation.

7. LIMITATION OF LIABILITY.

Contestant acknowledges and agrees that Sponsor assumes no responsibility or liability for any computer, online, software, telephone, hardware, or technical malfunctions that may occur. The Sponsor is not responsible for any incorrect or inaccurate information, whether caused by website users or by any of the equipment or programming associated with or utilized in the Contest or by any technical or human error which may occur in the administration of the Contest. The Sponsor is not responsible for any problems, failures, or technical malfunctions of any telephone network or lines, computer online systems, servers, providers, computer equipment, software, e-mail, players, or browsers, on account of technical problems or traffic congestion on the Internet, at any website, or on account of any combination of the foregoing. The Sponsor is not responsible for any injury or damage to the contestant or to any computer related to or resulting from participating or downloading materials in this Contest. Contestant assumes liability for injuries caused or claimed to be caused by participating in the Contest, or by the acceptance, possession, use of, or failure to receive any prize. The Sponsor assumes no responsibility or liability in the event that the Contest cannot be conducted as planned for any reason, including those reasons beyond the control of the Sponsor, such as infection by computer virus, bugs, tampering, unauthorized intervention, fraud, technical failures, or corruption of the administration, security, fairness, integrity, natural disaster, or proper conduct of this Contest.

8. CONDUCT.

As a condition of participating in the Contest, each contestant agrees to be bound by these Contest Rules and indicates consent as part of the registration process. Contestant further agrees to be bound by the decisions of the Sponsor, which shall be final and binding in all respects. The Sponsor reserves the right, in its sole discretion, to disqualify any contestant found to be: (a) violating the Contest Rules; (b) tampering or attempting to tamper with the Contest or any of the equipment, the Contest website or Contest programming; or (c) acting in an unsportsmanlike or disruptive manner that interferes with any portion of the Contest; or (d) engaging in any form of harassing, offensive, discriminatory, or threatening speech or behavior, including (but not limited to) relating to race, gender, gender identity and expression, national origin, religion, disability, marital status, age, sexual orientation, military or veteran status, or other protected category. CAUTION: ANY ATTEMPT TO DELIBERATELY UNDERMINE THE LEGITIMATE OPERATION OF THE CONTEST MAY BE A VIOLATION OF CRIMINAL AND CIVIL LAWS. SHOULD SUCH AN ATTEMPT BE MADE, THE SPONSOR RESERVES THE RIGHT TO SEEK REMEDIES AND DAMAGES TO THE FULLEST EXTENT PERMITTED BY LAW, INCLUDING BUT NOT LIMITED TO CRIMINAL PROSECUTION.

9. PRIVACY / USE OF PERSONAL INFORMATION.

By participating in the Contest, contestant: (i) grants to the Sponsor the right to use his/her name, likeness, mailing address, telephone number, and e-mail address ("Personal Information") for the purpose of administering the Contest, including but not limited to contacting and announcing the winners; and (ii) acknowledges that the Sponsor may disclose his/her Personal Information to third-party agents and service providers of the Sponsor in connection with any of the activities listed in (i) above.

Sponsor will use the contestant's Personal Information only for identified purposes, and protect the contestant's Personal Information in a manner that is consistent with Sponsor's Privacy Policy at: trendmicro.com/privacy

10. INTELLECTUAL PROPERTY.

All intellectual property, including but not limited to trademarks, trade names, logos, copyrights, designs, promotional materials, web pages, source code, drawings, illustrations, slogans, and representations are owned by Sponsor and/or its affiliates. All rights are reserved. Unauthorized copying or use of any copyrighted material or intellectual property without the express written consent of its owner is strictly prohibited.

11. TERMINATION.

Sponsor reserves the right, in its sole discretion, to terminate the Contest, in whole or in part, and/or modify, amend, or suspend the Contest, and/or the Contest Rules in any way, at any time, or any reason without prior notice.

12. LAW.

These are the official Contest Rules. The Contest is subject to applicable laws and regulations. The Contest Rules are subject to change without notice in order to comply with any applicable laws or the policy of any other entity having jurisdiction over the Sponsor and/or the Contest. All issues and questions concerning the construction, validity, interpretation, and enforceability of the Contest Rules or the rights and obligations as between the contestant and the Sponsor in connection with the Contest shall be governed by and construed in accordance with the laws of Ireland including procedural provisions without giving effect to any choice of law or conflict of law rules or provisions that would cause the application of any other jurisdiction's laws.

13. PRECEDENCE.

In the event of any discrepancy or inconsistency between the terms and conditions of the Contest Rules and disclosures or other statements contained in any Contest-related materials, the terms and conditions of the Contest Rules shall prevail, govern, and control.

 

© 2026 Trend Micro Incorporated. All rights reserved. PWN2OWN, ZERO DAY INITIATIVE, ZDI, ZERO DAY INITIATIVE, TrendAI, and Trend Micro are trademarks or registered trademarks of Trend Micro Incorporated. All other trademarks and trade names are the property of their respective owners.