V12, an AI security startup founded by two former capture-the-flag champions, disclosed a $10 million seed round on July 30, led by Electric Capital. The financing comes weeks after the company said one of its AI agents earned a $2.5 million bug bounty for discovering a critical blockchain vulnerability, which V12 described as the largest bounty ever awarded to an autonomous system.
The round attracted a peculiar mix of backers: on-chain investigator ZachXBT, crypto security researcher samczsun, and Cognition co-founder Walden Yan participated alongside Thomas Shadwell from OpenAI and Sampriti Panda from Cognition. Investor listings on CoinCarp and CypherHunter show varying participant counts, though precise numbers remain unclear. V12 structured the deal as a postmoney YC SAFE with no board seats or warrants, the company said.
Luna Tong and Jasraj "Jazzy" Bedi, who co-founded V12, arrived at the startup after running Zellic, a security consultancy, and establishing perfect blue, a capture-the-flag team that finished first globally on CTFtime in 2020. Tong spent time researching iPhone vulnerabilities at Dataflow Security and later worked at Two Sigma. Bedi handled Android security at Google. Their competitive hacking background shows in the product, which eschews theoretical flaws for exploitable bugs.
V12 runs against GitHub repositories and attempts to produce working proof-of-concept exploits for critical vulnerabilities. Users connect a repository, trigger a scan, and receive findings with source-code links, reproducible exploits, and suggested fixes. An "Autopilot" mode reviews every push and pull request automatically. The platform includes an API, CLI, and a Model Context Protocol server that integrates with Claude Desktop, Cursor, and VS Code.
Benchmark data published by V12 in June 2026 showed 62.6 percent recall on 289 ground-truth vulnerabilities across Solidity, Rust, C++, and Go. The company claimed its system outperformed test harnesses built on Claude Code and what it referred to as "Codex," though that data is now several months old and the competitive landscape for AI-powered security tools has shifted considerably since spring.
Since the funding announcement, V12 has released vulnerability disclosures targeting Signal's contact-discovery enclave and a class of WebKit cross-site scripting bugs affecting iOS applications. In late August, the startup detailed two critical object-lifetime vulnerabilities that allowed a compromised host to break Signal's SGX enclave boundary; Signal patched both issues. A mid-September disclosure outlined a default WKWebView configuration enabling HTML injection or XSS in what V12 estimated were thousands of apps.

The company's homepage displays logos for Zcash, LayerZero, Ethereum Foundation, Firefox, kernel.org, Redis, Ripple, Signal, Stripe, Hugging Face, and Phantom beneath the tagline "Securing the code behind systems that cannot afford to fail." V12 did not specify which of these organizations are paying customers, and the logos appear in a marketing section without explicit customer designation, a common practice among early-stage security vendors assembling credibility through association.
V12 enters a crowded field of startups applying large language models to offensive security. Simbian emerged from stealth with a $10 million seed in April 2024, positioning itself as a builder of what it called a "fully autonomous security platform." Magnitude raised $10 million in June 2026 for an autonomous AI workforce focused on third-party risk, according to reports at the time.
Bug bounty programs have started recalibrating in response to the deluge of AI-generated submissions. GitHub restructured its bug-bounty program in late July 2026 to address what security news outlets reported as a flood of low-quality, machine-generated reports. Days later, Coinbase adjusted its bounty tiers "in the age of AI," tightening criteria and raising the bar for payouts, the company said on its blog.

The company's stated ambition is grandiose: to "build a cyber nuke," a system capable of finding every exploitable flaw in a codebase. Whether that vision materializes or remains aspirational, V12 offered $100 of free usage to new signups for seven days following its July funding announcement, a standard customer-acquisition tactic in the DevSecOps market.
Other investors in the round include a cluster of crypto founders and security researchers: Sam Blackshear, Diogo Mónica, Emin Gün Sirer, and Felix Wilhelm, according to investor listings on CoinCarp and CypherHunter. Electric Capital, a venture firm known for its thesis on crypto infrastructure, led the financing. The firm declined to comment on the deal terms.
