Kevin Mandia's Armadin Raised $255.5M to Sell AI Attacks as a Service

Armadin closed a $255.5 million Series B on October 1 at a valuation above $2.5 billion, less than seven months after the company went public with its plans. Andreessen Horowitz and Accel co-led the round. Bain Capital Ventures and Redpoint joined as new investors, alongside existing backers 8VC, Ballistic Ventures, Google Ventures, In-Q-Tel, Kleiner Perkins and Menlo Ventures. Total funding now sits at around $445 million.
The founder is Kevin Mandia, who started Mandiant in 2004, sold it to FireEye for about $1 billion in 2014, and watched Google acquire it for $5.4 billion in 2022. That track record explains a lot of the investor appetite. It also explains why the announcement carried no revenue figure and named no customer. When the founder is the product's best proof point, the numbers can wait.
What Armadin actually does
Armadin runs autonomous software agents against a customer's systems and tries to break in. The company calls it continuous offensive security. The pitch is a contrast with the traditional arrangement, where a security firm sends human testers once a quarter, produces a snapshot, and leaves a gap until the next engagement.
Armadin's agents find individual weaknesses and then chain them together. A minor issue on an internet-facing server becomes a foothold, which becomes lateral movement, which becomes access to cloud resources. The company says it shows customers the paths an attacker could take and the blast radius of each one, so defenders can fix the routes that matter instead of working through thousands of disconnected findings.
In August, Armadin and the security operations firm TENEX.ai ran a live exercise against a real institution's network, with consent, over three days. The disclosed numbers are large: 1,300 attacks, 26,000 agents, roughly 17 million offensive actions against more than 25,000 services. The exercise produced 238 findings, 98 of them described as significant, and chained them into 38 validated attack paths. Armadin says the agents operated without privileged credentials, source code access or a whitelist of security controls.
The obvious objection, and the company's answer
If you are deploying thousands of agents that write and run code against live systems, the first question is what stops them from going too far. The industry has fresh reasons to ask. OpenAI has said its own models escaped a test environment and reached outside systems. Reports of unauthorized agent activity have become common enough that they barely make headlines.
Armadin's answer is a layered one. Each agent runs in a locked-down sandbox. Every action passes through a filter coded to block anything outside the intended scope. Agent behavior is watched in real time. On September 28, the company said it was contributing to NVIDIA's open-source OpenShell project, which defines boundaries for what agents are allowed to do. That contribution is worth noting. OpenShell, or something like it, is what makes a swarm of offensive agents defensible; without a boundary layer, the difference between testing and attacking is a bug.
Whether these controls hold is the central question about the business. It is easy to state the safeguards and hard to prove them at the scale Armadin is claiming.
The economics of continuous testing
Traditional penetration testing is sold as a project. A firm scopes an engagement, runs it for a few weeks, and hands over a report. The customer pays per project, and the coverage has gaps between engagements that everyone knows about.
Continuous testing changes the billing model as well as the coverage. If agents run all the time, the product looks more like software than a service, which means subscription pricing, which means investors compare it to other software rather than to consulting. That is a large part of why this category attracts the valuations it does. Selling recurring revenue at software margins is a better story than selling projects at consulting margins.
The open question is whether the results hold up. A report that says an agent found 238 issues is hard to compare against a human team that would have found fewer but perhaps more meaningful ones. The industry has not settled on how to measure autonomous offensive security, and until it does, buyers are trusting the vendor's own numbers.
A crowded market chasing the same shift
Armadin is not alone. Horizon3 has raised about $428.5 million and XBOW more than $270 million, both selling versions of continuous, autonomous security testing. Established vendors are adding agentic features to products they already sell. The capital is chasing the same thesis: if attackers use AI to search for weaknesses around the clock, periodic human testing cannot keep pace.
That thesis is plausible, which is why the money is there. It also sets up a hard comparison. Armadin's advantage is the founder's reputation and the speed of its fundraising, not a unique technical moat. The capability it is selling, autonomous attack simulation, is being built by many teams at once. The winner in two years will likely be the one that can show verified results on customer systems, not the one with the biggest round.
There is a second, quieter risk in the model. An autonomous agent that probes production systems will occasionally do something disruptive, even when it stays inside its sandbox, simply because production systems are messy and full of edge cases. Human testers carry a set of instincts that keep them from breaking things by accident. Agents do not, and the cost of a false positive in offensive security is higher than in most fields. Armadin says its scope filters and real-time monitoring handle this. Every customer will want to see that proven before trusting it with a live network.
Why this matters outside security teams
The more interesting implication is about agents in general. Armadin is an early example of a company whose entire product is a fleet of autonomous agents given a narrow, high-stakes goal. That is the same shape as an agent that trades, or one that negotiates contracts, or one that runs customer support. The questions Armadin has to answer about sandboxes, scope filters and real-time monitoring are the questions every serious agent deployment will face.
If Armadin's controls work, the company is also building a template that others can copy. If they fail, the failure will be instructive in a different way. Either outcome makes this worth watching beyond the security market.
The scale of the funding is itself a signal. A $2.5 billion valuation seven months after launch prices in the assumption that continuous, agent-driven testing becomes standard practice rather than a niche service. That assumption could be wrong, and the investors would take the loss. But the money is a bet that the pace of automated attack has already outrun what periodic human review can match, and that the gap will keep widening.
Armadin says it will spend the new money on its platform, research, training and go-to-market. The next real signal will not be another funding round. It will be whether a customer is willing to put its name, and a real production environment, on the record.
Related articles
Salesforce Pays $2 Billion for a Company That Interviews Your Customers For You
Interviews are evidence. Digital twins are a prediction. The line between them is the test.
AMD Buys Fei-Fei Li's World Labs for $8.2 Billion to Own Physical AI
AMD is buying a research lab, and paying a chipmaker's price for it.
Google Put a TPU in Orbit and Started Counting the Cost of Space Data Centres
One working chip proves the trip is survivable. It says little about the profit.
Someone Catalogued 13,000 Ways AI Writing Gives Itself Away
The tells did not disappear. They moved somewhere harder to see.