We’re excited to share that Craft Ventures has invested in Horizon3’s $250 million Series E at a valuation of more than $2 billion, co-led by NightDragon and NEA. Craft first partnered with Horizon3 in July 2023 when we led the company’s Series C, and this marks our third significant investment in the company.
A lot has changed in the world of AI and cybersecurity in only three short years, but Horizon3 accurately predicted where the world was heading: machine-speed hacking, leading to algorithms fighting algorithms, driving the need for autonomous security. Snehal brought a uniquely informed perspective to that future, having led technology on both the defensive and offensive sides of cybersecurity as CTO of Splunk and later CTO of Joint Special Operations Command. He had seen firsthand how quickly attack and defense capabilities were evolving, and more than 20 CISOs we spoke with reinforced the same conclusion: as attacks became more automated, defense had to become continuous and autonomous. We shared that conviction and partnered with Horizon3 to build the world’s best AI hacker to power a proactive security platform.
When we first invested, frontier models didn’t have notable cyber capabilities and AI hacking was not yet in the mainstream. At the time, we wrote that continuous security management would be the next evolution in cybersecurity and believed Horizon3’s proprietary cyber terrain maps would compound with every test, powering a broader security platform over time. Three years later, both parts of that thesis are playing out.
Today, AI hacking is the white-hot center of both frontier AI and the cybersecurity industry. Post-Mythos models can quickly discover thousands of vulnerabilities and chain low and medium findings into workable exploits. The gap between discovery and real-world exploitability is effectively zero. These capabilities are also more accessible than ever before as the latest open-source models are catching up to frontier labs. In this new world, understanding what is actually exploitable across your organization has become an even more urgent priority.
The rapid advance of AI has created a massive inflection in the market opportunity for Horizon3. Many thought AI hacking was just a tool for red-teamers, a useful but relatively narrow market. The idea that AI hacking would reshape exposure management was still a hypothesis three years ago, but security teams have realized that the only credible way to understand their exposure is to continuously test their defenses the way a real world AI-enabled attacker would. The same shift is happening in application security, where budgets are moving from DAST to agentic penetration testing. The market need has shifted from vulnerability discovery to continuous validation: prove what’s exploitable, fix it, verify the fix, and repeat.
For those reasons, the market of AI hacking has attracted many new startups and venture capital dollars. At BlackHat, there were more than 20 companies mentioning autonomous penetration testing. Over the last two years, there has been over $1 billion in funding across these companies. Horizon3 makes up $350 million, or 35%, of the total capital raised. Horizon3 has captured the lion’s share for a number for reasons, chiefly due to their solution breadth, purpose-built AI architecture, real-life training data accumulated over six years of testing, and the trust that comes along with that experience:
Solution breadth: There is confusion in the market about AI hackers. Most only cover applications. Horizon3 covers the full attack surface across infrastructure, identities, and applications. They are also on the frontier of LLM-based attack defense, specifically around deception techniques. The next paradigm is extending into autonomous defense, closing attack paths with verification running as one continuous learning loop between AI attackers and AI defenders.
Purpose-built AI architecture: Horizon3 combines frontier models with other AI techniques to get large performance gains at a fraction of the cost of token-hungry alternatives, and cost is what determines whether continuous validation is actually viable. Many competitors cannot run continuously or they require human augmentation.
Real-life cyber terrain dataset: Every one of Horizon3’s 310,000 production pentests adds to their Cyber Terrain map, a dataset of real-world cyber terrain that Horizon3 has been accumulating for six years. That loop between attack and defense can’t be recreated with generic models or public data.
Trusted by leading organizations: Horizon3 is trusted to protect over 7,000 organizations globally, including four Fortune 10 enterprises, multinational banks, major healthcare networks, and large classified government agencies. They are actually trusted to run in production because they’ve achieved zero downtime across all production tests, with no humans in the loop.
Horizon3’s North Star has always been to build a closed-loop system where the world’s best AI hacker finds problems, fixes them, and continuously verifies security. Frontier AI has made the attacker’s job easier than ever, and the only adequate response is proactive defense that operates at the same speed and scale. Horizon3 has been building exactly that, and we’re excited to continue backing the team as they define the future of autonomous security.




