Armadin raises $255.5M at a $2.5B-plus valuation for its AI attack platform

Armadin's $255.5M Series B brings its disclosed funding to $445M, with Andreessen Horowitz and Accel co-leading.

By · Published

Primary source: Reuters

Why it matters

Armadin's $255.5 million round backs a founder-led attempt to turn expert red-team work into continuous AI software. Its valuation makes execution and evidence of repeatable customer value the next test.

An unmarked investment folder rests on a table before server racks, representing Armadin’s cybersecurity funding.

Armadin, Kevin Mandia's AI cybersecurity startup, raised $255.5 million in a Series B co-led by Andreessen Horowitz and Accel, valuing the company at more than $2.5 billion. The October 1st financing brings Armadin's total funding to $445 million, according to the company. It backs a demanding premise: security teams should test their defenses continuously with software that behaves like an attacker.

Mandia has tried to move the security industry toward that attacker-first view before. He founded Mandiant in 2004, later led FireEye, and built a company known for investigating major intrusions. Google completed its acquisition of Mandiant in September 2022. At Armadin, Mandia is applying that operational background to a different proposition: use autonomous software to reproduce red-team work at a scale that periodic human-led assessments cannot match.

The bet now has substantial backing. Alongside co-leads Andreessen Horowitz and Accel, the Series B includes new investors Bain Capital Ventures and Redpoint, plus returning investors 8VC, Ballistic Ventures, Google Ventures, In-Q-Tel, Kleiner Perkins and Menlo Ventures. Accel also led Armadin's $189.9 million combined seed and Series A announced on March 10th.

A red team built to run continuously

Armadin's product, which it calls the "Ultimate Attacker," uses specialized AI agents to map an organization's attack surface, probe systems and chain weaknesses into paths that could lead to compromise. The goal is to show security teams how separate vulnerabilities might combine into a working attack, rather than simply hand them a list of scanner findings.

That product thesis draws on the founding team's experience. Co-founder and chief technology officer Travis Lanham previously worked as a principal engineer and technical lead for Google Cloud Security Operations. Co-founder and chief offensive security officer Evan Pena spent 13 years at Mandiant and helped build and lead its red-team organization. Armadin says that group grew to more than 200 consultants under his leadership. Co-founder and chief architect David Slater, a Stanford computer science graduate, led engineering work on Google's SecOps data platform.

In March, Mandia described the motivation in a post introducing Armadin: he expects attackers to use AI to automate and scale attacks, and argues that defenders must continuously identify attack paths before adversaries do. The Series B announcement repeats that core argument, saying faster vulnerability discovery and exploit development are narrowing the time available to respond.

Armadin says it is already running attack campaigns in production for Fortune 500 enterprises and government customers. Its platform page lists 443,000 agents launched against real targets, zero false-positive findings and a fastest reported path to domain compromise of 119 seconds. Those are Armadin's own figures. The round announcement does not name the customers behind its production deployments, and the metrics describe company-reported platform activity rather than independent performance testing.

A table of Armadin-reported platform metrics: 443,000 agents launched against real targets, zero false-positive findings, and a fastest reported path to domain compromise of 119 seconds. The figures are company-reported, not independent testing.
Armadin reports these platform figures and says it runs production campaigns for Fortune 500 and government customers; the round announcement does not name them - AI explanatory infographic, not documentary evidence. RuntimeWire - AI-generated infographic.

Investors are backing a crowded category

Armadin is entering a market where established cybersecurity vendors and younger startups are selling versions of continuous, autonomous security testing. Horizon3 announced a $250 million Series E at a valuation above $2 billion on August 3rd. The financing puts Armadin in the same valuation neighborhood while it is still early in its operating history.

The investor case rests on both the software thesis and the people building it. Armadin combines engineers with operators who have worked on enterprise security systems and red-team engagements. That mix could help turn specialized offensive-security judgment into a repeatable product. It also puts pressure on Armadin to show that an AI system can do more than generate a dramatic attack-path demonstration: customers need safe, reliable tests that lead to fixes security teams can prioritize.

Armadin says it will use the capital to expand its platform, research, training and go-to-market efforts. Its funding announcement points to enterprise and government deployments as evidence of demand, while the headline valuation reflects investors' willingness to fund the prospect of continuous machine-speed testing. The test for Mandia and his co-founders is whether those deployments become a durable software business, rather than a high-end service wrapped around an ambitious AI claim.

Reuters reported the valuation following the round.

Reader comments

Conversation for this story loads after sign-in.