Security2 publishers2 min readPublished
Mandia's Armadin raises $255.5 million to point AI attack agents at customers' networks
Kevin Mandia's Armadin raised $255.5 million at a valuation above $2.5 billion, bringing its total to $445 million seven months after launch. Its case against periodic pen tests rests on performance data from an exercise Armadin ran with a partner.
The Watch · Security desk

What happened
- Andreessen Horowitz and existing investor Accel co-led the Series B, with Bain Capital Ventures and Redpoint joining as new investors.
- Armadin's agents probe a customer's attack surface, attempt exploits, and chain minor flaws into paths running from an internet-facing weakness through lateral movement to cloud compromise.
- In a three-day August exercise with TENEX.ai, Armadin says it ran 1,300 attacks using 26,000 agents and about 17 million offensive actions against more than 25,000 services.
- The company says it already runs these agentic attack campaigns in production for Fortune 500 companies and government customers.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Customers running these agents against production systems depend on a vendor-trained safety model to block a harmful action, so its failure modes belong in any procurement review.
- exposure Periodic pen-test engagements and vulnerability scanners are the products Armadin says cannot keep pace, so those vendors are the first to face its competition.
- constraint All of the performance figures come from Armadin's own exercise, so a security team has no independent baseline for comparing its 38 paths with what a periodic pen test finds.
"Offense is uniquely advantaged right now," Mandia said [14]. "AI lets an attacker find and chain weaknesses faster than any human team can respond," he said in the funding announcement [13]. The company's argument targets two product categories. It says that as frontier models cut the time and expertise needed to find and exploit vulnerabilities, periodic penetration tests and vulnerability scanners cannot give an accurate, continuously updated picture of exploitable risk [11]. According to Help Net Security, scanners fall short because they score each finding in isolation [12].
Security operations tooling is outside that argument. TENEX.ai, the exercise partner, sells agentic security operations [20].
The August actions yielded 238 findings, 98 of them rated significant, chained into 38 validated attack paths [8]. That works out to about one finding per 71,000 actions [3], with 41 percent of findings rated significant [4]. "Significant" is Armadin's label. The 38 paths come closer to measuring exploitability, because the company says each was validated as a working chain [8]. Armadin says it shows customers those paths and their blast radius so defenders can fix exploitable risk instead of working through thousands of disconnected findings [21].
The agents ran without privileged credentials, source code access or whitelisting of security controls, the company says [9]. Each action passed through a control layer overseen by a safety model trained on feedback from human security experts [10]. For customers running campaigns in production, that model decides whether an agent's next exploit attempt reaches a live system [10].
The money came in three steps. Armadin surfaced with a $24 million seed in late 2025 [16] and launched publicly in March 2026 with $189.9 million [15]. Add the Series B to the March figure and the sum is $445.4 million [1], matching the reported $445 million total [2]. Counting the seed on top would give $469.4 million [2], so the March figure appears to include it. The new round goes to the agentic platform, research, model training and go-to-market [17].
Investors are paying for the founder as well as the thesis [19]. Mandia founded Mandiant in 2004 and sold it to FireEye for $1 billion in 2014; Google later acquired the firm for $5.4 billion [18]. "Kevin has been on the front lines of the most consequential breaches in history, and he has built a team that pairs elite red teamers with world-class AI engineers," said David George, a general partner at Andreessen Horowitz [19]. Neither release includes revenue, a customer count, the environment the exercise targeted, or evidence that buyers are moving budget off pen tests and scanners.
What to watch
- Independent or customer-published results from Armadin's production campaigns, or any report of an agent causing an outage on a live system.
- Pen-test firms and scanner vendors shipping continuous, agent-driven attack-path testing of their own.
- Revenue or customer numbers from Armadin that would show whether buyers are actually shifting pen-test and scanner budgets.