Kevin Mandia, the cybersecurity entrepreneur who built incident-response firm Mandiant and sold it to Google for $5.4 billion in 2022, has raised $255.5 million for his new security startup Armadin at a valuation of more than $2.5 billion, the company announced Thursday.
The Series B was led by Andreessen Horowitz and Accel, with a participant list that reads like a summit of the security and enterprise investing establishment: Bain Capital Ventures, Redpoint, 8VC, Ballistic Ventures, Google Ventures, In-Q-Tel, Kleiner Perkins, and Menlo Ventures all joined the round. The raise comes just six months after Armadin's $190 million Series A in March, bringing the company's total funding to more than $445 million. Few founders can command that kind of velocity, and fewer still can draw In-Q-Tel and Kleiner Perkins into the same round — the backing is a wager that Mandia can repeat his Mandiant trick in the agentic-AI era, and it lands amid a broader funding surge for AI security startups that we track at aibuzzwire.news.
Agent Swarms That Hack You First
Armadin is selling a reimagining of offensive security testing for the AI era. Traditional penetration testing works on a rhythm: hired experts attempt to break into a company's systems on schedule, then deliver a report on the weaknesses they found. The gaps between those engagements are exactly when attackers strike.
Armadin instead runs always-on swarms of AI agents that chain vulnerabilities together and attempt to hack into customer systems continuously. The idea, as TechCrunch described the company's pitch, is to find and seal holes before "any bad guys (or even AI labs with rogue agents)" can turn the same agentic techniques against them. In other words, the startup is betting that the only defense against autonomous attackers is autonomous defenders that never stop probing.
The Old Model Leaves Windows Open
The weakness Armadin is attacking is structural. A penetration test is a point-in-time snapshot — valuable on delivery day, but increasingly stale as new code ships and new vulnerabilities emerge week after week between engagements. Automated scanners narrowed that gap, but they mostly catalogue known issues rather than behaving the way a real intruder does: probing an environment, pivoting from machine to machine, and chaining several minor flaws into a working path inside the network. Mandia's argument is that AI agents finally make continuous, attacker-like testing practical at scale — software that mimics the adversary's creativity, every day, at machine speed, and reports what it found while the hole is still open.
Why Investors Are Paying Up
Mandia's track record does most of the explaining. He founded Mandiant, which became the go-to firm for investigating state-sponsored breaches — the company that identified Chinese military units behind commercial hacking campaigns — before selling to Google for $5.4 billion in 2022. Security buyers already trust his judgment on where attacks are heading, and that credibility compresses the risk of an unproven approach.
The round's composition matters too. In-Q-Tel, the strategic investor that works with the US intelligence community, joined alongside the venture establishment, a signal that government buyers are watching the agentic-security space closely. And the pace is notable: $445 million raised in roughly six months puts Armadin among the fastest-funded security startups in recent memory.
Agentic AI Is Reshaping Both Sides of the Battlefield
The funding lands at a moment when autonomous AI agents are transforming offensive security. The same capabilities that let software agents code, plan, and act independently also let them probe targets, chain exploits, and adapt when blocked — without human patience or human working hours. Security teams have spent 2026 absorbing a string of incidents involving agents that exceeded their intended boundaries, and defenders are scrambling for tooling built for that reality.
Armadin's thesis flips the threat into the product: if agents are going to attack systems, agents should be attacking them first, around the clock, in a controlled way that surfaces weaknesses before adversaries do. The company says the capital will go toward scaling what it calls effective autonomous security — turning a research-stage concept into infrastructure enterprises can run daily.
What Comes Next
The company has not detailed a launch timeline, but the scale of the round suggests an aggressive build-out: more agents, broader coverage, and a push into enterprise deployments. Competitors are moving too — the continuous, automated security testing market is attracting both startups and incumbents who see human-paced pentesting as a relic.
For Mandia, the raise is a second act with a familiar shape: spot the shift in how attacks happen before the market does, and build the firm that names it. The last time, the shift was state-sponsored intrusion and the answer was incident response. This time the shift is autonomous attack, and the answer, he is betting, is a swarm — one that never sleeps, never bills by the engagement, and never stops knocking.
---
Stay Ahead of AIGet the latest AI news, analysis, and breakthroughs — all in one place.
Read more AI news →