China Relaunches Tianfu Cup Hacking Contest with Government Control and Secrecy


China brought back the Tianfu Cup hacking competition in 2026 under Ministry of Public Security oversight. The event ran January 29-30 with heavy restrictions. No public results emerged, unlike past high-profile payouts.

Tianfu Cup started as Pwn2Own rival, paying $1.9M in 2021 for Windows, iOS, Chrome exploits. 2023 focused domestic targets like Huawei. 2024-2025 hiatus preceded this secretive return.

MPS announced January 16. Tianfu X post deleted fast. Official site blocked non-China IPs, then went dark post-event. Total prize pool dropped to CNÂ¥1M ($140K).

Targets spanned smartphones (iPhone 17, Xiaomi 14 Ultra), OSes (Windows 11, Ubuntu), browsers (Chrome, Safari), cloud (VMware ESXi), security (Palo Alto), mail servers, apps (WeChat, Teams), databases, office tools, and AI platforms (Hugging Face, Ollama).

New tracks tested AI vulnerability hunting agents and known vuln reproduction.

China MPS press release confirms CNÂ¥1M total prizes. No individual awards published.

Target Categories Table

CategoryExamplesGoal
SmartphonesiPhone 17, Xiaomi 14 Ultra, Galaxy S24RCE + kernel escape
Operating SystemsWindows 11, Ubuntu, macOSFull compromise
BrowsersChrome, Edge, SafariSandbox escape
Cloud/VirtualizationVMware ESXi, DockerHost privilege gain
AI PlatformsHugging Face, Ollama, LangChainDefault RCE

Secrecy Measures

Site geo-blocked pre-event, offline after. No vendor notifications. X announcements scrubbed. Results classified.

2021 Chinese law mandates zero-day reporting to government. Microsoft links it to state stockpiling.

Historical Payouts

YearTotal PrizesTop TargetsNotes
2021$1.9MWindows, iOS, ChromeGlobal headlines
2023UnknownHuawei, XiaomiDomestic focus
2026$140KiPhone 17, AI toolsMPS control

Strategic Shifts

AI agent track tests automated vuln discovery. Known vuln reproduction emphasizes reliability. Smaller prizes suggest quality over quantity.

Past Tianfu exploits appeared in Chinese espionage. 2026 bugs likely follow suit.

Industry insider notes “rules and targets changed significantly.”

Implications

Government runs premier hacking event. Transparency vanishes. Vendors stay blind. State gains exclusive zero-days.

Pwn2Own pays millions publicly. Tianfu secrecy fuels weaponization fears.

FAQ

Who runs Tianfu Cup 2026?

China’s Ministry of Public Security.

Prize pool size?

CNÂ¥1M ($140K) total.

Key new categories?

AI platforms, AI vuln agents.

Site access now?

Completely offline post-event.

Exploit fate?

Likely state stockpiled per 2021 law.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages