← Back to all posts
News

An AI That Breaks Into Hospitals Just Tripled to $2 Billion

August 3, 2026 · 16:11 UTC · News
An AI That Breaks Into Hospitals Just Tripled to $2 Billion

TL;DR

Horizon3 closed a $250 million Series E today at a valuation above $2 billion, roughly tripling the $650 million it carried at its Series D in June 2025. The round was co-led by returning investors NightDragon and NEA. The product, NodeZero, is not a scanner: it is an autonomous attacker that executes real exploit chains inside live production networks at multinational banks, healthcare systems, and classified government agencies. The company says it has run 310,000 of those in production without knocking anything over. The thesis investors bought is a stopwatch, and it is the most interesting thing in the announcement.


The clock is the entire argument

CEO Snehal Antani's pitch reduces to one measurement: how long the same attack chain takes to go from initial foothold to full network control. Three years ago it took 7 minutes and 19 seconds. Last year, 4 minutes and 12 seconds. Today he puts it at 77 seconds, and expects it to reach 30.

"If your security organization can't detect and stop me within seventy-six seconds, the game is already over. By second seventy-seven, I've taken full control of your network."
time to full network compromise, same attack chain 3 yrs ago7m 19s last year4m 12s today77s
Horizon3's own timing of its own attack chain. Treat it as a vendor figure, not an audited benchmark.

That caveat matters. This is one company timing its own tooling against its own chain, with no published methodology and no third party holding the stopwatch. But the direction is not really in dispute, and 77 seconds is well inside the window where a human analyst is still reading the first alert.

What the money actually bought

The oversubscribed round brought in seven new investors, including Acrew, Sapphire, PSG, EDBI, and SAIC, alongside returning backers Craft Ventures, Qualcomm Ventures, Ridge Ventures, and SignalFire. NightDragon founder Dave DeWalt, previously CEO of both FireEye and McAfee, takes a board seat. The company reports 120% year-over-year ARR growth and FedRAMP High authorization, with the NSA and CISA among its customers.

Series D (Jun 2025) vs Series E (Aug 2026) Series D Series E prod pentests run 130,000 310,000 customer orgs 3,000 7,000+ valuation $650M $2B+
Fourteen months between rounds. Series D baselines are from NEA's own investment note.

Antani's framing of the moat is worth noting because it is not "we have better models." It is that the training data comes off customer firewalls, from attacks that actually ran against real production estates, which is not something you can scrape.

The bit that should bother you: agents trip every wire

Buried in Forbes' coverage is the most builder-relevant number of the day. Horizon3 says human hackers take the bait on decoy credentials about 37% of the time. Leading AI models take it roughly 90% of the time.

The decoys are honeytokens, sold in NodeZero as Tripwires: fake AWS keys, Azure tokens, and kubeconfig files scattered on servers and shares an attacker is likely to reach. They do nothing until touched, then fire an alert.

Why the gap is so wide is not mysterious. A human pentester who finds a plaintext root credential sitting in a world-readable share gets suspicious, because they have been burned before and because the find is too convenient. An LLM agent is a very fast intern who was told to go find credentials, has never once been disappointed by one, and has no memory of ever being tricked.

Same caveat as the stopwatch: this is a single-sourced vendor claim from a company that sells the countermeasure, with no published methodology. Antani himself expects the gap to close as models improve. But it points at something structurally true about current agent harnesses, and it is cheap to test yourself.

The green-team bet

The stated roadmap for the capital is autonomous blue-team agents that remediate directly from NodeZero's findings, closing the loop between the attacker and the fixer instead of dumping a report on a human.

the loop Horizon3 says the Series E buys red agent mapsthe attack path blue agent fixesit (not shipped) re-test provesthe fix held humans review by exception
The middle box is the roadmap, not the product. Today the loop still runs through a human.

Antani's version of the endgame is "AI fighting AI, with humans operating by exception." Which is a tidy slogan right up until you remember that both agents are now allowed to make changes to production at a hospital.

It was a $375 million day for agent security

Horizon3 was not alone. Zenity, which does governance and security for AI agents rather than offense, closed a $125 million Series C the same day, led by Norwest with SoftBank Vision Fund 2, Hitachi Ventures, and LG Technology Ventures joining, bringing it to roughly $185 million raised. Microsoft's Project Perception, its red/blue/green agent platform, was also slated to hit public preview today.

Horizon3 is separately a partner in Anthropic's Project Glasswing, the critical-infrastructure vulnerability initiative that has expanded to roughly 200 organizations. The offense-and-defense-by-agent market is consolidating fast enough that the same names now show up on every side of it.

What to do with this if you ship agents

  • Scatter honeytokens, today. They are close to free, they are passive, and if the 90% figure is even directionally right they are the highest-yield detection you can deploy against an autonomous intruder.
  • Then point your own agent at them. If your coding or ops agent happily exfiltrates a fake AWS key from a repo, you have just learned something about your harness that no eval suite told you.
  • Budget your detection window in seconds. A response playbook that assumes a human triages the first alert is a playbook built for the 7-minute era.
  • Read vendor stopwatches skeptically. Both headline numbers here come from the company selling the fix, unaudited. The trend is real; the precision is marketing.

Key Takeaways

  • Horizon3 raised $250M at a $2B+ valuation, roughly tripling from $650M at its June 2025 Series D, co-led by NightDragon and NEA.
  • NodeZero has run 310,000 autonomous pentests inside live production environments across more than 7,000 organizations, including the NSA and CISA, with no reported disruptions.
  • The company clocks the same full-compromise attack chain at 77 seconds today, down from 7 minutes 19 seconds three years ago. Its own measurement, unaudited.
  • Horizon3's research claims AI models fall for decoy credentials about 90% of the time versus 37% for human attackers, which makes honeytokens unusually effective against agentic intruders.
  • The Series E funds autonomous blue-team remediation agents. Those have not shipped; today the loop still ends at a human.
  • Agent security took roughly $375M in a single day, with Zenity's $125M Series C landing alongside and Microsoft's Project Perception entering public preview.

Sources: Horizon3 Series E announcement, TechCrunch, Forbes, SiliconANGLE, NEA Series D note, Fortune on Zenity, Horizon3

AISecurityAgentsPentestingFundingCybersecurityInfrastructureHoneytokens
CONSOLE
$