Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

China’s Tianfu Cup hacking contest returned on January 29–30, 2026, after skipping 2024 and 2025. SecurityWeek reported that the Ministry of Public Security (MPS) organized the event, whose public footprint was unusually limited: an announcement on the contest’s X account was reportedly removed, the website was briefly inaccessible outside China, and it later went offline. Those facts establish reduced visibility, not the organizers’ motive.

What happened at the 2026 Tianfu Cup?

The MPS announced the competition on January 16, according to SecurityWeek’s February 13, 2026 report by Eduard Kovacs. The event ran January 29–30 and followed the 2023 edition, creating a two-year gap.

SecurityWeek described a short-lived public presence. A Tianfu Cup post on X was reportedly deleted; the official site became unavailable to visitors outside China the next day and was completely offline after the event. No public 2026 rulebook or official results page was available in the report.

Why is it described as being under increased secrecy?

The description rests on observable access and disclosure limits rather than proof of a classified program. The removed social-media post, restricted website access and post-event shutdown made it harder for outsiders to verify targets, rules, results or vulnerability handling.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An unnamed industry source told SecurityWeek that “rules and targets have changed a lot this year,” but provided no further detail. The source’s identity was not disclosed, and the comment does not establish what changed or why.

What products and systems were targeted?

SecurityWeek reported an unusually broad target list. Inclusion on the list does not mean that every product was successfully compromised.

Category Reported examples
Mobile devices iPhone 17, Xiaomi 14 Ultra, Honor Magic 7 Pro, Samsung Galaxy S24 Ultra, Google Pixel 9 Pro XL, Vivo X300 and Oppo Find X9 Pro
Desktop operating systems Windows 11, Ubuntu, macOS, UOS and KylinOS
Browsers Chrome, Edge and Safari
Cloud, virtualization and containers VMware ESXi, VirtualBox, ZStack Cloud, QEMU and Docker Engine
Mail and collaboration Microsoft Exchange, Coremail, WeChat, Feishu, Teams, Zoom and DingTalk
Databases PostgreSQL, Dameng, TiDB, KingbaseES, GBase and Redis
Office and PDF software Office and PDF applications were included in the reported scope, although the article did not provide a complete product-by-product list.
AI development and inference Ollama, vLLM, Dify, LangChain and ComfyUI

What changed in the contest format?

AI-assisted vulnerability identification

SecurityWeek reported a track involving AI agents that identify vulnerabilities. The available account does not specify the agents’ permitted tools, scoring method, disclosure requirements or whether human researchers had to validate findings.

Reproducing known exploits

A separate reported track required participants to reproduce exploits for known vulnerabilities. Public reporting did not provide the vulnerability set, success criteria or handling rules.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How large was the prize pool?

Edition Figure What it represents
2026 CN¥1 million The total prize pool attributed by SecurityWeek to an MPS press release.
2021 CN¥1.9 million Aggregate participant earnings reported by SecurityWeek, not the 2021 prize pool.

Because these figures measure different things and come from different years, they should not be treated as a like-for-like change in the competition’s budget.

What happens to vulnerabilities found at Tianfu Cup?

The public record does not answer that question for the 2026 event. No official rules document or independently confirmed account identified which findings were sent to vendors, retained by authorities or used in operations.

China’s vulnerability-reporting regulations implemented in 2021 require Chinese citizens who discover a zero-day to report details to the government and prohibit disclosure to third parties outside China. That legal context is relevant to how researchers may handle findings, but it does not prove what happened to any particular Tianfu Cup exploit.

SecurityWeek quoted Natto Thoughts arguing that the MPS’s central role, earlier episodes that raised suspicions and the absence of transparent coordinated-vulnerability-disclosure rules “suggests a system oriented toward vulnerability retention and state control rather than on vendor notification or coordinated disclosure.” This is an analyst’s assessment, not a verified account of every 2026 result.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How does Tianfu Cup compare with Pwn2Own?

Both contests are high-profile vulnerability competitions, but the available 2026 reporting supports only a limited comparison:

Comparison point Tianfu Cup 2026 Pwn2Own
Organizer Reportedly organized under China’s Ministry of Public Security. Run by the Zero Day Initiative.
Public rules and targets 2026 rules were not publicly available in the reporting; the site later went offline. A current, directly comparable rulebook and prize schedule were not established by the available source.
Prize information CN¥1 million reported total pool. No like-for-like current figure was established.
Target scope Mobile, desktop, browser, cloud, security, collaboration, database, office and AI systems were reported. Not compared here because a matching current target list was not available.
Disclosure process No transparent 2026 coordinated-disclosure process was identified. No current process details were established in the available reporting.

That evidence is insufficient to declare either competition superior. The key difference for readers is how much each organizer publicly documents about targets, rules, prizes and vendor notification.

What is known—and still unknown?

Established by reporting

  • The event ran January 29–30, 2026, after a two-year hiatus.
  • The MPS announced it on January 16.
  • SecurityWeek reported limited website and social-media availability.
  • The reported target list covered a wide range of consumer, enterprise and AI technologies.
  • The reported format included AI-assisted identification and known-exploit reproduction.
  • The reported 2026 prize pool was CN¥1 million.

Not established publicly

  • The complete rules, scoring system and target-by-target results.
  • Which vulnerabilities were disclosed to vendors.
  • Whether authorities retained or operationalized any 2026 exploit.
  • The organizers’ reason for restricting or removing public information.

The 2026 Tianfu Cup is therefore best understood as a major vulnerability contest whose return was publicly documented only in fragments. Increased secrecy is a description of that limited visibility, while claims about state retention remain analysis rather than demonstrated outcomes for specific findings.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.