A company whose product is an AI that hacks your network has just tripled in value. It did so in the same week that AI hacking stopped being hypothetical. Horizon3 has raised a $250m Series E at a valuation above $2bn, up from $650m a year ago. The timing is the story.
Days earlier, OpenAI and Anthropic each disclosed that their models had breached companies outside their intended scope. That is the anxiety Horizon3 is selling into. The company announced the round on Monday, billing it as the “AI vs. AI” era. If AI can now break in, its pitch runs, you should be the one turning it loose on your systems first.
The round was co-led by returning backers NightDragon and NEA. NightDragon’s Dave DeWalt, who once ran FireEye and McAfee, is joining the board. Strategic investors include Singapore’s EDBI, the defence contractor SAIC and Qualcomm. That spread says the buyers are not confined to tech.
Autonomous, but on a leash
Horizon3’s platform, NodeZero, runs what the company calls autonomous penetration tests. It attacks a live network without taking it down. It chains small weaknesses into a full path to sensitive data. Then it proves the break and checks the fix. Unlike an annual audit that samples a slice of the network, it runs continuously across the whole thing.
The important detail is what the AI is not allowed to do. Despite the “AI Hacker” branding, Horizon3 says its generative models never write or fire the exploits. The attacks themselves are deterministic and pre-validated. The AI picks targets, ranks attack paths and writes the summaries, while the dangerous part stays scripted and constrained.
That design is a direct answer to the week’s news. The lab breaches raised the question of whether any AI can be trusted to run loose in a live system. Horizon3’s pitch is that you get the attacker and defender in one tool. The AI is kept on a shorter leash than the ones that just escaped.
The numbers, and the catch
The business case is real, if company-reported. Horizon3 says it has run 310,000 production tests without disruption. Recurring revenue has grown 120% year on year. It counts more than 7,000 customers, including four Fortune 10 firms. It argues the shift is from finding endless flaws to proving which ones an attacker could actually chain. That is the gap traditional scanners and AI-written code keep widening.
The next step is where the caution returns. Horizon3 plans autonomous “blue-team” agents that do not just find holes but fix them. They would rotate credentials and change configurations on their own. That is a continuous loop of AI attacking and AI fixing. It is also the exact kind of automation that needs hard human guardrails. Otherwise a well-meaning fix becomes its own outage.
For now the money is betting on the controlled version. Horizon3 will spend the round on sales, on expansion into Singapore, Australia and Europe, and on that attacker-defender loop. The raise is really funding one question.
Does autonomous testing stay a faster audit, or become a system that quietly rewrites your defences? That still has to be proven safe.
Get the TNW newsletter
Get the most important tech news in your inbox each week.