Armadin Raises $255.5 Million to Deploy AI Agent Swarms That Attack Networks First

Armadin Raises $255.5 Million to Deploy AI Agent Swarms That Attack Networks First

Most cybersecurity startups sell a tool that tells a company where it might be vulnerable. Armadin sells an army of AI agents that actually break in first, so defenders know exactly how an attacker would get through before one ever tries.

Armadin, founded by Mandiant founder Kevin Mandia, closed $255.5 million in Series B funding co-led by Andreessen Horowitz and Accel, with participation from Alphabet's GV, Bain Capital Ventures and Redpoint, at a valuation exceeding $2.5 billion. The round brings Armadin's total funding to roughly $445 million. The platform deploys swarms of AI agents that map a company's internal systems, scan its assets, and identify realistic attack paths, in one customer deployment, 26,000 agents scanned more than 25,000 assets and uncovered 38 verified attack paths. The company plans to use the new capital to expand its research, AI training and go-to-market efforts.

Why Agent Swarms Change the Economics of Offensive Security

Traditional penetration testing relies on human security researchers manually probing a company's systems, a slow and expensive process that can only cover a fraction of a large organization's attack surface in any given engagement. Replacing that process with tens of thousands of AI agents operating in parallel means Armadin can run the equivalent of a continuous, full-scale penetration test rather than a periodic, sampled one, a structural shift in coverage that explains why investors are willing to underwrite a valuation above $2.5 billion for a company still built around offensive security testing rather than a broader platform.

Why Mandia's Background Matters for Investor Conviction

Kevin Mandia built and sold Mandiant, one of the most recognized names in incident response and threat intelligence, before founding Armadin, giving him direct, repeated exposure to how real attackers actually operate inside compromised networks. An investor backing a second company from a founder with that specific track record is underwriting pattern-matched credibility: Mandia has already demonstrated he understands the attacker's playbook well enough to build one defensive company investors trusted at scale, and is betting he can do it again with an AI-native approach.

What This Means for Founders

For founders building in AI-native security or offensive security tooling, Armadin's raise signals that investors remain willing to back highly technical, agent-based approaches to historically labor-intensive security disciplines, provided the founding team carries genuine, demonstrated domain credibility. Founders pitching a similar agent-swarm approach to other technical domains, not just security, should note how central Mandia's specific operating history was to this round's conviction, since a technically similar pitch from a less established team would likely face a meaningfully higher bar for proof before investors commit at comparable scale.

Browse the cybersecurity investor directory and AI and machine learning investor directory for more active funds in the category, read the baseline mechanics of a post-money valuation and how it compounds across funding rounds if the concept is new, or explore active capital on AngelLinx @ angellinx.ai/register.


AngelLinx Intelligence | angellinx.ai