Funding

Hadrian raised $40M. Armadin raised $255.5M. Agentic pentest is a category now. Its pricing isn’t settled.

Three agentic offensive-security rounds in six days, from a €4M Paris pre-seed to a $2.5B-plus Mandia unicorn. The thesis is sound. Only one valuation is public. Here’s how to tell a category from a feature, and what to test before you buy.

Oct 6, 2026 · 4 min read

In six days, three companies raised money to do the same thing: point AI agents at your attack surface and prove which weaknesses actually work. Armadin raised $255.5M at a valuation of over $2.5B on October 1 (per Armadin). Fleuret AI raised a €4M pre-seed in Paris on Monday (per Tech.eu). On Tuesday, Amsterdam’s Hadrian raised $40M, co-led by Forgepoint Capital International and Smartfin, bringing its total to $65M (per SiliconANGLE). Hadrian’s valuation: Undisclosed. Fleuret’s: Undisclosed.

Same thesis. Round sizes more than six times apart at the top of the range, and only one price on the table.

Why the thesis works. Scanners score each finding in isolation. Hadrian’s own figures: just 0.47% of scanner findings turn out to be exploitable, and 87% of organizations still rely on manual pentests (company claims, per SiliconANGLE). An annual pentest is a snapshot. Attackers aren’t. Armadin’s release says it straight: frontier models compress the time between disclosure and working exploit, so periodic testing can’t keep pace.

The week supplied a clean example. Horizon3.ai used Anthropic’s Mythos model to find CVE-2026-61500 in Rejetto HFS, a CVSS 9.3 flaw. The file server leaks outputs of Math.random() at login and derives its cookie-signing key from the same generator. Collect a few login responses, rebuild the generator state, recover the key, forge an admin cookie, reach RCE. Found in June, patched July 13, probed in the wild starting October 2 (per SecurityWeek, citing VulnCheck). AI found the bug. Attackers showed up about four months later. A team that tests once a year is behind by design.

Our POV on the funding gap. Armadin’s premium isn’t mainly for the technology. It’s for Kevin Mandia, a16z and Accel, and Fortune 500 and government customers running “agentic attack campaigns in production” seven months after launch (per Armadin). Over $2.5B on $445M raised is a bet on owning the category. Armadin revenue: Undisclosed, so nobody can call that a revenue multiple.

Hadrian is the more grounded pitch. It pairs continuous external attack-surface mapping (Atlas) with on-demand agentic pentests (Nova) on shared context, and it names customers: McKesson, NBCUniversal, TotalEnergies (per SiliconANGLE). Smartfin’s partner says the plan is to “build a nine-figure revenue business.” Read that carefully. It tells you where revenue is going, not where it is.

We’d question the gap from both sides. If agentic offense is a real category, a $40M round looks small for a team founded in 2021 with named Fortune-scale customers. If it’s a feature, over $2.5B looks rich, because every scanner and exposure-management vendor will ship “validated exploitability” soon. Our read: the category is real and the feature risk is real. The winners will own the remediation loop, not just the exploit.

Who gets squeezed. Speculation, labeled. The annual services pentest, whose price is set by consultant days. An agent that re-tests after every fix resets that price. The first wave of automated pentest and breach-and-attack simulation vendors also face harder renewals, because buyers now have a $2.5B reference point that says this is where the market is going.

What we’d test before buying. Run a bake-off on your own perimeter, not a demo range. Count three things: validated exploitable findings, false positives your team had to triage, and time from fix to re-test. Ask where exploit traffic originates and where evidence is stored. Fleuret is selling agents that run on European infrastructure for exactly that reason (per Tech.eu). Get written rules of engagement for production: what the agents will never do, such as destructive payloads, credential stuffing against real users or data exfiltration. Ask how a finding becomes a ticket with the proof attached.

Then do the one check that separates a control from a report. Pick a validated kill chain, fix the first link, and ask the agent to try again the same day. If it can’t, you bought a scarier PDF. If it can, you bought the thing these rounds are actually pricing: proof, on demand, that your fix worked.

Sources