The 2025 Pwnie Awards

Ian Roos, Mark Trumpbour

DEF CON 33 · Day 1 · Main Stage

Overview

The 2025 Pwnie Awards, presented at DEF CON, served as a vibrant and often humorous retrospective on the most significant achievements, spectacular failures, and critical vulnerabilities discovered within the cybersecurity landscape over the past year. Hosted primarily by Ian Roos and Mark Trumpbour, with a rotating cast of community presenters, the awards celebrate the researchers, engineers, and hackers who push the boundaries of offensive and defensive security. Far from a conventional awards ceremony, the Pwnies are a purely volunteer-driven effort, known for their candid commentary, inside jokes, and a genuine appreciation for groundbreaking work.

Watch on YouTube

Visual summary for The 2025 Pwnie Awards by Ian Roos, Mark Trumpbour
Visual summary for The 2025 Pwnie Awards by Ian Roos, Mark Trumpbour

Key moments

  1. 0:00 Welcome to the 2025 Pwnie Awards
  2. 1:13 Best Desktop Bug award presentation begins
  3. 3:03 Entry sign wins Best Desktop Bug Pwnie
  4. 4:14 Best Cryptographic Attack award presentation
  5. 5:00 Kai's humorous crypto and NIST back door take
  6. 7:00 Entry sign wins second Pwnie for Cryptobug
  7. 8:40 Best Song Award: No winner this year
  8. 9:10 Most Innovative Research award category introduced

The 2025 Pwnie Awards

Speakers: Ian Roos; Mark Trumpbour

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=Gpx6JsZ0Vzw

Overview

The 2025 Pwnie Awards, presented at DEF CON, served as a vibrant and often humorous retrospective on the most significant achievements, spectacular failures, and critical vulnerabilities discovered within the cybersecurity landscape over the past year. Hosted primarily by Ian Roos and Mark Trumpbour, with a rotating cast of community presenters, the awards celebrate the researchers, engineers, and hackers who push the boundaries of offensive and defensive security. Far from a conventional awards ceremony, the Pwnies are a purely volunteer-driven effort, known for their candid commentary, inside jokes, and a genuine appreciation for groundbreaking work.

This year's Pwnies highlighted a diverse array of security challenges, from deeply technical cryptographic blunders and intricate kernel race conditions to novel mobile exploits and the emerging security implications of artificial intelligence. The event underscored the critical importance of diligent research, responsible disclosure, and the continuous arms race between attackers and defenders. It also didn't shy away from calling out "epic fails" and "lamest vendor responses," fostering a culture of accountability and learning from mistakes within the industry.

The Pwnie Awards are more than just a ceremony; they are a critical barometer of the cybersecurity community's focus, identifying trends, recognizing unsung heroes, and providing valuable insights into the evolving threat landscape. By spotlighting both triumphs and tribulations, the Pwnies offer a unique educational opportunity, reminding attendees and the wider industry about the types of vulnerabilities that have the most impact, the research that drives innovation, and the defensive strategies that are most urgently needed.

Background

▶ Watch: Welcome to the 2025 Pwnie Awards (0:00)

The Pwnie Awards originated as a way for the security community to celebrate and lampoon the most notable security exploits, researchers, and incidents of the year. Conceived as a playful, yet serious, counterpoint to more formal industry accolades, the Pwnies have become a staple at major conferences like DEF CON, known for their distinctive "pony" trophies and unvarnished commentary. The awards are organized by the Summercon Foundation, emphasizing their grassroots, volunteer-driven nature, where the only paid individuals are the bartenders—a running gag that highlights the community-first ethos.

The philosophy behind the Pwnies is to acknowledge that "some of the best bugs each year are the bugs that we don't hear about," while still recognizing publicly disclosed, impactful research. The categories span a wide range of security domains, from desktop and mobile bugs to cryptographic attacks, privilege escalation, and remote code execution. Beyond technical prowess, the Pwnies also feature "negative" awards like "Lamest Vendor Response" and "Most Epic Fail," which serve to hold organizations accountable and provide valuable, albeit often humorous, lessons in operational security and responsible disclosure. This unique blend of celebration, critique, and community engagement makes the Pwnies a highly anticipated event, reflecting the hacker ethos of breaking things in new ways, questioning assumptions, and driving the industry forward.

Key Findings

▶ Watch: Entry sign wins Best Desktop Bug Pwnie (3:03)

The 2025 Pwnie Awards revealed several overarching themes and critical findings across the spectrum of cybersecurity research. A significant highlight was the recurrence of cryptographic weaknesses, exemplified by AMD's Entry Sign bug, where a NIST example key was used in production for over seven years, underscoring fundamental flaws in cryptographic implementation and supply chain trust. This was paired with other crypto-related issues like X509 DOSs, demonstrating the fragility of certificate parsing.

Operating system vulnerabilities continued to be a fertile ground for high-impact bugs. The Linux kernel vis quadruple race condition showcased the complexity of exploiting intricate timing bugs for privilege escalation, while Bit Unlocker pointed to issues in Windows recovery mechanisms for sensitive data extraction. Mobile platforms remained a highly competitive and difficult area for exploitation, with the Samsung Galaxy S24 being successfully compromised at Pwn2Own through sophisticated multi-bug chains.

Network infrastructure proved to be ripe for critical flaws, with Qualys's Regression revealing a pre-authentication RCE in OpenSSH—a cornerstone of secure communications—after nearly two decades. Similarly, the Hardy Bar Charging Station Mess exposed severe vulnerabilities in critical EV infrastructure, accessible via both physical and unauthenticated network vectors, highlighting overlooked attack surfaces. The emerging field of AI security also made its mark, with Prompt Injection as Defense demonstrating novel ways to exploit LLM vulnerabilities for defensive purposes, marking a shift in how AI can be both a threat and a tool in cyber warfare.

Finally, the "negative" awards underscored persistent issues in the industry. The Linux CVE CNA received the "Lamest Vendor Response" for dismissing a critical out-of-bounds write, illustrating challenges in coordinated vulnerability disclosure. The "Most Epic Fail" went to Signalgate, a stark reminder of operational security failures leading to the leakage of classified material, proving that even advanced secure communication tools can be undermined by human error and poor configuration.

Technical Deep Dive

▶ Watch: Kai's humorous crypto and NIST back door take (5:00)

The 2025 Pwnie Awards celebrated and dissected a range of highly technical vulnerabilities and research, offering a granular view into the state of offensive and defensive security.

Best Desktop Bug was awarded to Entry Sign, a critical flaw where AMD was found to have been using an example cryptographic key directly from the NIST specification for over seven years in its processors. This wasn't merely a theoretical weakness; it represented a profound failure in cryptographic hygiene and supply chain integrity, potentially undermining the security assurances of countless systems relying on AMD hardware. Another notable nominee was Bit Unlocker, researched by Alain Leviev and Netanel Ben Simon, which leveraged Windows recovery mechanisms to extract BitLocker secrets. This highlighted that even robust disk encryption can be bypassed by exploiting underlying OS functionalities designed for system recovery, emphasizing the need for comprehensive security postures that consider the entire system lifecycle.

In the Best Cryptographic Attack category, Entry Sign again took the pony, reinforcing its significance as a fundamental cryptographic misstep. Other nominees included X509 DOSs, where Bing Xi and team exploited crafted X509 certificates to uncover denial-of-service vulnerabilities. This research demonstrated how malformed or specially constructed certificates could trigger resource exhaustion or crash conditions in parsers, impacting systems relying on X509 for authentication and secure communication. Untangling the Knot by Xenonhao also received a nomination for breaking access controls in home wireless mesh networks, revealing weaknesses in how these increasingly common systems secure inter-device communication and user access.

Most Innovative Research recognized Haunted by Legacy, discovered and exploited by Angelos Beias, for its work on vulnerable tunneling hosts. This research likely unveiled novel ways to compromise systems by exploiting weaknesses in tunneling protocols or their implementations, allowing attackers to pivot through seemingly secure network boundaries. Bit Unlocker was also nominated here, acknowledged for its clever approach to data exfiltration. Another intriguing nominee was Invitation is All You Need by Ben Nasi, Stop Cohen, and Orier, which explored invoking Gemini for workspace agents with a simple Google calendar invite. This research delved into the emerging attack surface of AI-powered agents and their integration with enterprise communication platforms, highlighting how seemingly innocuous actions can be weaponized against LLM vulnerabilities.

The Most Underhyped Research category brought to light less-publicized but equally impactful work. The pony went to Scheduled Disclosure by Wen Chan, Isabella Su, and Ricardo Pockinella. This groundbreaking research demonstrated that remote power side channel attacks are not only still possible on modern x86 CPU architectures but are also more effective and can work even without frequency side channel leakage. This finding challenges long-held assumptions about the resilience of modern CPUs against such attacks, suggesting new vectors for data exfiltration. Other nominees included Kernel Snitch by Lucas Mah, described as the first side channel attack to leak Linux kernel heap pointers without any memory corruption, and Hardy Bar Charging Station Mess by Stefan VBook. The latter exposed critical EV infrastructure vulnerabilities that could be exploited through both physical and unauthenticated network access, underscoring the severe security neglect in a rapidly expanding sector.

For Best Mobile Bug, the award went to exploiting the Samsung Galaxy S24 at Pwn2Own by Ken Ganon of NCC Group. This represented a sophisticated multi-bug chain, demonstrating the immense effort and expertise required to achieve compromise on cutting-edge mobile devices. The complexity typically involves chaining several vulnerabilities, such as browser exploits, kernel bugs, and privilege escalations, to achieve a full system compromise. Another nominee was a profile pin bypass in Geo Hotstar by Ravensb, indicating weaknesses in application-level security controls on mobile platforms.

Best Privilege Escalation Bug was awarded to the Linux kernel vis quadruple race condition, discovered by @v4bell and @twertypo. This intricate exploitation required precisely orchestrating a race among four threads to trigger a use-after-free vulnerability, highlighting the extreme difficulty and precision involved in exploiting modern kernel bugs. The award winner, who accepted on behalf of Hanuk Kim, emphasized the challenge and the satisfaction of finding such a complex flaw. Other nominees included Bad Successor, a vulnerability impacting Microsoft's implementation of DMSA, enabling low-privileged users to compromise any user in Active Directory, and Microsoft Windows MSI installer repair to system, which resulted in multiple local privilege escalation advisories, harking back to historical Windows LPE vectors.

The Best Remote Code Execution pony went to Regression by Qualys, which uncovered a signal handler race condition leading to exploitable heap corruption and the first pre-authentication RCE in the default OpenSSH server configuration in nearly 20 years. This was a monumental discovery, given OpenSSH's ubiquitous role in securing remote access and its long-standing reputation for robustness. Another formidable nominee was Mad License by Xiinyang Pang Ver and Zashan Lean, a zero-click pre-authorization RCE impacting all versions of Windows Server from 2003 to 2025, achieved by exploiting a single memory corruption vulnerability and bypassing mitigations on the latest Windows Server 2025. This demonstrated an extraordinary level of skill in finding and exploiting vulnerabilities across a wide range of Windows Server versions.

The Lamest Vendor Response was "awarded" to the Linux CVE CNA for dismissing a critical out-of-bounds write in HFS Plus. This decision caused significant frustration within the community, highlighting ongoing issues with vulnerability assessment and disclosure processes in open-source projects. Geo Hotstar also received a nomination for flat-out denying the profile pin bypass and marking it as "informative, known, not applicable." These responses underscore the challenges researchers face when engaging with vendors, particularly regarding the recognition and remediation of security flaws.

The Most Epic Fail went to Mike Waltz for Signalgate, a "novel signal bypass" that involved leaking classified material by simply adding targets to a group chat. This incident served as a stark reminder that even the most technically secure communication tools can be compromised by human error and lapses in operational security. The "creepy stalkerware industry" was also nominated for its never-ending data breaches, with TechCrunch reporting that at least 26 companies in this sector have been hacked or had customer/victim data leaked online since 2017, highlighting a persistent and ethically dubious security failure.

Finally, the Epic Achievement award recognized Qualys for uncovering not one but two vulnerabilities in OpenSSH. This dual discovery in such a critical and widely trusted software tool was a testament to their deep expertise and relentless pursuit of security flaws in foundational technologies. Other nominees for Epic Achievement included Prompt Injection as Defense by Corneropouloolis, which demonstrated a clever twist that turns AI against itself by exploiting LLM vulnerabilities to defend against cyber attacks, achieving over 95% success against real-world LLM agents. MyFare Classic by Celeb Tuan was also nominated for finding ways to break these previously considered unbreakable smart cards without prior knowledge and discovering hardware backdoors in the process, exposing broad implications for hotel access cards and other critical infrastructure.

Demo / Proof of Concept

▶ Watch: Entry sign wins second Pwnie for Cryptobug (7:00)

While the Pwnie Awards itself is a ceremony celebrating past achievements rather than a live demonstration platform, the very essence of the awards lies in recognizing and validating impactful proofs of concept (PoCs) and successful exploitations. Each winning and nominated piece of research inherently involved the development and execution of such PoCs to confirm the viability and severity of the discovered vulnerabilities.

For instance, the "Best Mobile Bug" winner, exploiting the Samsung Galaxy S24 by Ken Ganon of NCC Group, was explicitly demonstrated at Pwn2Own, a premier hacking competition where researchers showcase live exploits against fully patched devices. This involves a direct, public demonstration of a multi-bug chain achieving a full system compromise. Similarly, the Linux kernel vis quadruple race condition and the OpenSSH Regression RCE would have required meticulously crafted PoCs to prove their exploitability, often involving precise timing, memory manipulation, and bypasses of modern mitigations. The "Prompt Injection as Defense" research also explicitly mentions demonstrating "over 95% success against realworld LLM agents," indicating practical, verifiable PoC development. Even the Entry Sign bug, concerning AMD's use of a NIST example key, implies a PoC to verify the key's presence and its potential impact on cryptographic operations. Thus, while no specific live demos were performed during the Pwnie Awards presentation, the entire event is a tribute to the rigorous development and successful execution of cutting-edge security PoCs.

Defensive Implications

▶ Watch: Most Innovative Research award category introduced (9:10)

The insights from the 2025 Pwnie Awards offer critical guidance for defenders looking to strengthen their security posture against evolving threats.

  1. Fundamental Cryptographic Hygiene: The Entry Sign vulnerability in AMD processors serves as a stark warning: never reuse example keys from specifications in production environments. Organizations must implement rigorous supply chain security audits, verifying cryptographic implementations in hardware and software components. Developers must be educated on secure cryptographic practices, and robust key management policies are paramount.
  2. Patch Management and Timely Updates: The OpenSSH Regression RCE, Linux kernel vis quadruple race condition, and Windows vulnerabilities (like those affecting MSI installer) emphasize the continuous need for diligent patch management. Critical infrastructure, servers, and endpoints must be updated promptly to mitigate known exploitation vectors. The "Lamest Vendor Response" for Linux CVE CNA highlights the need for better communication and prioritization of fixes, but defenders cannot wait indefinitely.
  3. Advanced OS and Mobile Exploitation Awareness: The sophisticated multi-bug chains seen in the Samsung Galaxy S24 Pwn2Own exploit, Bit Unlocker, and kernel race conditions demand a multi-layered defense. Mobile device management (MDM) should enforce strong configurations, and organizations handling sensitive data on mobile devices should assume advanced adversaries. For operating systems, exploit mitigation technologies must be fully utilized, and system hardening should go beyond default settings.
  4. Side-Channel Attack Mitigation: Research like Scheduled Disclosure (remote power side channels) and Kernel Snitch (kernel heap pointer leakage) indicates that side-channel attacks are not a relic of the past. Defenders should be aware of the potential for these attacks, especially in environments handling highly sensitive data. While direct mitigation can be challenging, minimizing shared resources, employing constant-time algorithms, and monitoring for unusual power consumption patterns (where applicable) can help.
  5. Critical Infrastructure Security: The Hardy Bar Charging Station Mess underscores the often-neglected security of critical infrastructure. Organizations managing EV charging stations, industrial control systems (ICS), or other operational technology (OT) must prioritize security by design, implement strict network segmentation, enforce strong authentication for both physical and network access, and conduct regular security audits.
  6. AI Security Best Practices: The Prompt Injection as Defense research highlights the emerging attack surface of Large Language Models (LLMs) and AI agents. Defenders integrating AI into their operations must be aware of LLM vulnerabilities like prompt injection, data poisoning, and model inversion. Implementing input validation, sanitization, and robust access controls for AI systems is crucial.
  7. Operational Security (OpSec) Training: Signalgate serves as a stark reminder that even the most secure technical tools are only as strong as their weakest human link. Comprehensive and continuous OpSec training for all personnel, especially those handling sensitive information, is essential. This includes best practices for communication channels, group chat management, and data handling policies.
  8. Vendor Accountability and Disclosure: The "Lamest Vendor Response" awards implicitly call for better vendor accountability. Defenders should factor vendor security practices and responsiveness into procurement decisions. When reporting vulnerabilities, researchers and organizations should persist in advocating for proper remediation and disclosure.

Key Takeaways

  • Cryptographic fundamentals are non-negotiable: Reusing example keys from specifications (e.g., AMD's Entry Sign) is a critical security failure, undermining trust and requiring deep scrutiny of all cryptographic implementations in hardware and software.
  • Operating system kernels remain complex and vulnerable: Intricate race conditions and use-after-free bugs (e.g., Linux kernel vis quadruple race condition) continue to be discovered, requiring highly skilled exploitation and emphasizing the need for robust patching and kernel hardening.
  • Mobile exploitation is a sophisticated arms race: Compromising modern mobile devices (e.g., Samsung Galaxy S24 at Pwn2Own) involves complex multi-bug chains, highlighting the high bar for mobile security and the need for continuous vigilance.
  • Foundational network services are not immune: The discovery of a pre-authentication RCE in OpenSSH (Regression) after nearly two decades underscores that even the most trusted software can harbor critical, long-standing vulnerabilities, demanding constant review and auditing.
  • Side-channel attacks are evolving and impactful: New research (Scheduled Disclosure, Kernel Snitch) demonstrates that power-based and other side-channel attacks can bypass modern CPU mitigations and leak sensitive information, even without memory corruption.
  • Critical infrastructure and AI present new, significant attack surfaces: Vulnerabilities in EV charging stations (Hardy Bar Charging Station Mess) and the emerging field of LLM vulnerabilities (e.g., Prompt Injection as Defense) show that overlooked areas and new technologies are rapidly becoming targets.
  • Operational security and vendor responsiveness are paramount: Human error (Signalgate) can negate advanced technical security, and poor vendor engagement (Linux CVE CNA, Geo Hotstar) impedes effective vulnerability remediation across the ecosystem.

About the Speaker(s)

The 2025 Pwnie Awards were primarily hosted by Ian Roos and Mark Trumpbour. Ian Roos served as one of the main presenters, guiding the audience through the various award categories with characteristic wit and insight. Mark Trumpbour, identified as the Executive Director of the Summercon Foundation, the non-profit organization that stewards the Pwnie Awards, played a crucial role in the event, particularly in presenting the "Most Epic Fail" award. Their combined efforts, alongside a rotating cast of community members who presented individual awards (including Emma, Kai, Winona, Enquit, Perry, Mark Griffin, and Dakota Kerry), ensured a lively and engaging ceremony. While detailed individual biographies were not provided in the transcript, their roles highlight their deep involvement and standing within the cybersecurity community, reflecting the Pwnie Awards' volunteer-driven spirit and commitment to recognizing the industry's best and most infamous moments.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

The Pwnie Awards are an institution, not a talk — a community ritual that functions as a year-in-review for people already living in this space. What's here is a competent write-up of a ceremony, not research, and should be judged accordingly: it surfaces real signal (AMD Entry Sign, regreSSHion, the quadruple race condition LPE) with enough technical color to be useful, but it's inherently retrospective and derivative by design.

Heather Calloway (CISO) — PASS

The Pwnie Awards are a legitimate community tradition, and several of the recognized findings — the AMD example-key failure, the OpenSSH pre-auth RCE, Signalgate — are genuinely consequential. But this is a ceremony, not a session, and it doesn't belong in my lane.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33