Armadin raises $255.5M at $2.5B valuation for AI agents
Armadin, the cybersecurity startup led by Mandiant founder Kevin Mandia, has closed a $255.5 million Series B round. The deal values the company at more than $2.5 billion.
The round brings Armadin's total funding to $445 million. The company publicly launched only seven months ago.
Andreessen Horowitz and existing investor Accel co-led the round. Bain Capital Ventures and Redpoint joined as new investors. Existing backers 8VC, Ballistic Ventures, GV, In-Q-Tel, Kleiner Perkins and Menlo Ventures also took part.
A fast climb from seed to Series B
Armadin first appeared quietly in late 2025 with a $24 million seed investment. It formally launched in March 2026 with $189.9 million in funding. The Series B arrives just months later.
The company is based in Palo Alto, California. It says the new money will go toward expanding its agentic security platform and scaling its research, model training and go-to-market operations.
Mandia is Armadin's chief executive. He founded Mandiant in 2004 and built it into an incident response and threat intelligence firm. FireEye bought Mandiant in a $1 billion deal in 2014, and Google later acquired Mandiant for $5.4 billion.
His co-founders at Armadin are:
- Travis Lanham, CTO
- Evan Peña, chief offensive security officer
- David Slater, chief architect
Built for AI-powered attackers
Mandia started Armadin because he sees a growing gap between attackers who use AI and the tools defenders still rely on. Frontier models cut the time and skill needed to find and exploit vulnerabilities. That trend has also shown up in data on AI speeding up exploitation.
Given that shift, the company argues that periodic penetration tests and vulnerability scanners no longer give organizations an accurate, current view of their exploitable risk.
"AI lets an attacker find and chain weaknesses faster than any human team can respond," Mandia said in the funding announcement.
Swarms of agents acting like adversaries
Armadin does not look at vulnerabilities one at a time. Its platform sends out swarms of specialized AI agents that are designed to behave like skilled attackers. The agents probe an organization's attack surface, try to exploit weaknesses, and link small, seemingly harmless issues into validated attack paths.
These paths can start at an internet-facing vulnerability, continue through lateral movement (an attacker moving from one compromised system to others inside a network), and end with the compromise of cloud resources or sensitive systems.
The platform shows customers those paths and the potential blast radius, meaning how much damage an attacker could do from a given entry point. The idea is that defenders fix the risks that can actually be exploited instead of working through thousands of unrelated findings.
Armadin says it already runs agentic attack campaigns in production for Fortune 500 companies and government customers.
17 million offensive actions in three days
In August, Armadin teamed up with TENEX.ai, a provider of agentic security operations, for a live AI cyberattack during a three-day exercise. The numbers from that test:
- 1,300 attacks launched
- 26,000 agents involved
- About 17 million offensive actions
- More than 25,000 services targeted
- 238 security findings, 98 of them described as significant
- 38 validated attack paths built from those findings
According to the company, the agents had no privileged credentials, no access to source code, and no whitelisting of security controls. In other words, they started roughly where an outside attacker would.
Armadin says every action went through a control layer overseen by a safety model. That model was trained using feedback from human security experts.
The Bigger Picture
For security teams, Armadin's round is less about one startup's valuation and more about where investors think defense is heading. Raising $445 million in about seven months after launch suggests that backers see automated, continuous offensive testing as a serious category, not a side feature.
The pitch fits a wider pattern. AI agents are already being used offensively in the wild, as the DIVD breach by an autonomous AI agent showed, and large vendors are pointing AI at bug hunting, such as Google's Gemini 4 Argon. If attackers chain flaws at machine speed, an annual pentest looks increasingly thin.
Still, the August exercise figures come from Armadin itself. It is worth watching whether independent customers or researchers confirm the quality of those attack paths, and how well the safety layer holds up when thousands of agents run against production systems. Letting AI agents loose on live networks carries its own risks, and organizations will likely want clear evidence before handing that much autonomy to any platform.
