Kevin Mandia's Armadin raises $255.5M to build AI agents that hack your company, on purpose
Armadin, which sends swarms of autonomous AI agents to attack customers' networks with permission, has raised $445 million total seven months after emerging from stealth.
Kevin Mandia has sold the same pitch twice, and investors just paid up for the second act. His AI cybersecurity startup Armadin raised $255.5 million in a Series B that values the company at more than $2.5 billion, the company announced Thursday, roughly seven months after it emerged from stealth.
The round was co-led by Andreessen Horowitz and Accel, with new investors Bain Capital Ventures and Redpoint joining existing backers including Google Ventures, Kleiner Perkins, Menlo Ventures and In-Q-Tel. It brings Armadin's total funding to $445 million, following a $24 million seed in late 2025 and a $189.9 million Series A in March, according to SecurityWeek.
Mandia founded Mandiant in 2004, sold it to FireEye for $1 billion a decade later, and watched Google buy the combined company for $5.4 billion in 2022. That track record explains how a company this young commands this price. What Armadin actually sells is a reversal of the usual security pitch: instead of defending networks with AI, it deploys swarms of AI agents trained by career red-team hackers to attack a customer's own systems, with permission, and show them exactly how a real intruder would get in.
Chaining beats scanning
The distinction from a vulnerability scanner is chaining. A scanner lists isolated findings with severity scores; Armadin's agents link several low-severity weaknesses into a complete route from an initial foothold to something valuable, the way an actual attacker would. In an August engagement the company described as the largest autonomous AI attack on record, it ran 1,300 attacks using 26,000 agents and 17 million offensive actions across more than 25,000 assets over three days, producing 238 findings that chained into 38 validated attack paths. Those are company-reported figures, not independently audited, but they sketch the scale investors are underwriting.
"Offense is uniquely advantaged right now," Mandia said in the funding announcement. "AI lets an attacker find and chain weaknesses faster than any human team can respond."
The timing helps explain the money. Frontier models have made finding individual vulnerabilities cheap; the expensive part is figuring out which of the 10,000 medium-severity findings actually leads somewhere. Armadin's bet is that continuous, agent-driven attack simulation replaces the quarterly penetration test the way continuous integration replaced the big-bang release. The announcement names no customers and gives no revenue figure, so the open question is whether technical capability and Mandia's reputation convert into repeatable enterprise revenue fast enough to justify a multibillion-dollar valuation. Investors are betting that autonomous red teaming becomes a category the way endpoint detection did. For everyone building AI agents, the more interesting signal is on the other side of the trade: the offense is automated now, and it is for sale.