Skip to content

Kevin Mandia's Armadin Raises $255M For AI Attack Agents

Armadin, led by Kevin Mandia, is worth $2.5bn a year after launch, selling swarms of AI agents that chain minor flaws into the attack paths a real intruder would use.

Kevin Mandia's Armadin Raises $255M For AI Attack Agents
Image courtesy: CNBC

Armadin, the offensive security company founded by Kevin Mandia, has raised $255.5 million in a Series B round that values it at more than $2.5 billion, roughly a year after it emerged from stealth. The round was co-led by Andreessen Horowitz and Accel, with Bain Capital Ventures and Redpoint joining and existing investors including GV, Kleiner Perkins, Menlo Ventures, In-Q-Tel and Ballistic Ventures returning, taking total funding to $445 million.

Mandia founded Mandiant in 2004, sold it to FireEye for $1 billion in 2014 and saw it bought by Google for $5.4 billion in 2022, which goes some way to explaining how a company this young reached this valuation. Armadin raised $24 million in seed funding in late 2025 and $189.9 million in a Series A in March.

"Offense is uniquely advantaged right now," Mandia said. "AI lets an attacker find and chain weaknesses faster than any human team can respond."

What The Product Actually Does

Armadin deploys large numbers of AI agents that behave like an attacker inside a customer's environment, mapping systems and users and then working out how an intruder would move through them. The difference from a vulnerability scanner is the chaining: rather than listing isolated findings with severity scores, the agents link several low-severity weaknesses into a complete route from an initial foothold to something valuable.

The scale is the selling point. In one engagement in August, the company ran 1,300 attacks using 26,000 agents and 17 million offensive actions across more than 25,000 assets, producing 238 findings that chained into 38 validated attack paths. Armadin describes it as the largest autonomous AI attack on record.

That output is closer to what a red team produces than what a scanner does, which matters because most security teams drown in scanner findings. A list of 10,000 medium-severity issues tells nobody what to fix first; 38 proven routes to the crown jewels does.

Running This In Production

Armadin says it runs these campaigns in production environments for Fortune 500 companies and government customers, which is the part buyers should examine most closely. Simulated attacks against live systems carry real risk of disruption, and neither the company nor the coverage of this round has set out what controls keep an agent swarm from breaking something.

Any organisation considering this class of tool should ask what the agents are permitted to do, how actions are bounded, what happens when something goes wrong mid-campaign, and who is accountable if a test takes down a production service.

A Crowded And Well-Funded Field

Armadin is not alone in betting that offensive security is where AI lands first. Horizon3, whose NodeZero platform runs autonomous penetration tests in live environments, raised $250 million in August at a valuation above $2 billion, more than triple its mark a year earlier, and says it has run over 300,000 production-safe tests for customers including the NSA and CISA. XBOW applies large language models to the same problem, while Pentera, Picus, AttackIQ and SafeBreach come at it from automated testing and control validation.

The common argument across these companies is that defence cannot keep pace manually. Horizon3's chief executive, Snehal Antani, frames it as "AI fighting AI, with humans operating by exception," and points to a sharp compression in how fast attacks move once a foothold is established.

What separates the companies is less the pitch than the data. Antani argues that operational data from real production tests is the durable advantage over generic foundation models, which is the same argument Armadin's scale figures are meant to support.

Why Offensive Security Is The First Real AI Security Market

Security vendors have attached AI to their marketing for a decade, mostly in detection, where a model's false positives land on an already overloaded analyst. Offensive testing is different because the work is naturally agentic and the output is verifiable.

An attack path either works or it does not. The agent proves it by walking the route, which removes the trust problem that dogs AI in defensive products, and that explains why this is where the money is going.

The same capability is why governments are nervous. Google restricted its Gemini 4 Argon model to vetted defenders through its Fairwind programme, which counts Armadin among its partners, precisely because a model good at finding and fixing flaws is also good at finding them for someone else.

What Buyers Should Weigh

For security leaders, the practical question is what this replaces. An annual penetration test from a consultancy gives a point-in-time view, while a continuous agent-driven campaign gives something closer to a live map of exposure, which is more useful and harder to act on, since the findings keep arriving.

Organisations should also think about whether their remediation capacity matches the discovery rate. A tool that reliably produces 38 validated attack paths a quarter is only worth buying if the team can close them, a constraint that applies across every environment where AI agents act faster than the people responsible for them.

The Attacker's Advantage Is The Business Model

Armadin's valuation rests on a single proposition: that AI has shifted the balance towards attackers, and that the only sensible response is to run the same technology against yourself first. Investors have backed that view heavily, with more than $500 million flowing into two companies in this niche in two months.

The proof will come from customers rather than funding rounds. If agent swarms find routes that experienced red teams missed, and do it without breaking production systems, the annual penetration test becomes a relic. If they mostly produce impressive numbers of actions and findings that teams cannot act on, this will look like another well-funded answer to a problem security teams already had.

Add Morning Tick on Google