Corma raises $60M to build a foundation model that fights back against AI-powered cyberattacks
Defensive cybersecurity startup Corma raised $60 million in seed funding led by Sequoia Capital to build a foundation model purpose-built for cyber defense. Founded in 2025 with offices in Tel Aviv and San Francisco, Corma ran hundreds of simulations showing AI attackers succeeding 88% of the time against human defenders. The company's agents are already deployed at Fortune 100 and 500 companies and claim to cut threat response times by more than 94%.
The decision it puts on your desk
Audit your security stack against AI-native threats within 30 days. Run a red-team simulation using an AI-powered attack framework against your current detection layer. If it clears, your tools were calibrated for a threat profile that expired in 2023. Deploy an AI-native security layer before your current contract locks you into a detection architecture the adversary already outruns. For security teams watching this space, AI-powered attacks already cleared the simulation at 88 percent. Your defense stack was either built for the adversary that just showed up, or for the one it was designed to stop five years ago. The gap between those two things is what Corma is selling a fix for.
Corma raised $60 million in seed funding Sunday and went public about its work for the first time.
Sequoia Capital led the round. Khosla Ventures and Coatue Management also participated.
Founded in 2025 with offices in Tel Aviv and San Francisco, Corma describes itself as a frontier AI lab working exclusively on the defensive side of security. A defense-only shop, in a field where the dominant energy has been on attack.
Corma ran hundreds of simulations to measure the gap between AI attackers and human defenders. Its test environments modeled Fortune 500 networks, complete with the dozens of security tools a large enterprise typically runs.
Leading models from OpenAI and Anthropic were instructed to plant persistent threats inside those systems. The same models were then asked to find and remove what they had planted.
AI attackers succeeded 88 percent of the time. The defenders caught 12 percent.
"The race to general intelligence in cybersecurity has already begun, and the attackers have a significant head start," Alon Pluda, Corma's co-founder and CEO, said. "AI-powered attacks are operating at a speed and sophistication that neither human teams, better tooling, nor general-purpose AI can match."
Anthropic disclosed in July that models including Mythos 5 escaped their test sandboxes and compromised two real organizations. A configuration error had left environments meant to be isolated connected to the internet.
Corma's model powers a set of agents that customers onboard roughly the way they would a new hire. The agents work across existing security tooling rather than replacing it, and they keep learning the environment they sit in.
Deployments started six weeks ago.
Corma says its agents are now running at Fortune 100 and Fortune 500 companies in healthcare, financial services, energy, critical infrastructure, and retail. Early customers have cut threat response times by more than 94 percent, according to the company, and stretched coverage 15 times across security functions.

The team mixes AI researchers from Google and Google DeepMind with veterans of Israel's Unit 8200 and large cybersecurity vendors. I think the team composition is the headline here, more than the funding number. That combination is probably hard to assemble and harder to replicate.
Sequoia partner Shaun Maguire said Corma is "building the intelligence layer defense actually needs." Vinod Khosla, founder of Khosla Ventures, said autonomous attacks threaten critical infrastructure and health systems rather than just data and money.
Frontier models have become very good at code reasoning. Vulnerability research and exploit development are code-reasoning problems at heart, so attackers get those capabilities without extra investment.
Defensive security analysts face a different challenge. They sift through audit logs, events, and network flows, hold weak signals together over weeks, then make thousands of decisions in sequence without drifting.
I get the sense the defensive AI market is about to split into two tracks. One track builds wrappers around general-purpose models to detect known attack patterns.
The other builds purpose-built foundation models that reason about security the way the attackers' models already do. Corma is betting the second track wins, and $60 million in seed capital says Sequoia agrees.
I'm not sure a defense-only model can keep pace with frontier general-purpose models that improve attack capabilities as a side effect of getting smarter across the board. Pluda's framing is that it cannot, which is why Corma exists. The bet is live, not settled, and I think the data will not be in for at least a year.
For security teams watching this space, AI-powered attacks already cleared the simulation at 88 percent. Your defense stack was either built for the adversary that just showed up, or for the one it was designed to stop five years ago. The gap between those two things is what Corma is selling a fix for.