AI Attackers Won 88% of the Time. Corma Raised $60M to Flip That.
The same models that are great at breaking in are lousy at keeping others out. Sequoia just funded the defense.
Corma ran the same AI models as both attacker and defender across hundreds of simulated Fortune 500 networks. Playing offense, the AI won 88% of the time. Playing defense, it caught 12%. That gap is the whole pitch.
On Monday, Corma emerged from stealth with $60 million in seed funding led by Sequoia Capital, with Khosla Ventures and Coatue joining. The company, founded in 2025 and split between Tel Aviv and San Francisco, is building what it calls the first foundation model purpose-built for defensive cybersecurity. CEO Alon Pluda is ex-DeepMind, and the founding team pairs AI researchers with veterans of Israel’s Unit 8200. A $60 million seed is a big number on its own. For a company that shipped its first model about six weeks ago, it’s the kind of check that says investors think they’re buying a category, not a product.
Corma’s argument is structural. General-purpose models got great at offense almost by accident, because finding bugs and writing exploit code lean on the exact reasoning and coding skills those models were trained on. Defense is a different job: sifting oceans of audit logs, catching faint signals over weeks, and making thousands of consistent decisions without slipping once. Corma says its agents, deployed at Fortune 100 and Fortune 500 firms across healthcare, finance, energy, and critical infrastructure, cut threat-response times by more than 94% and widened security coverage 15 times in early use. Those are company-reported figures from its own simulations and early deployments, so treat them as claims, not verdicts. The round didn’t disclose a valuation.
Here’s the model from my book worth naming: Asymmetry.
Most competition isn’t a fair fight, and the sharp move is finding where the payoff is lopsided. Cybersecurity is the textbook case. The attacker has to find one door left open. The defender has to lock every door, every time, forever. Same tools, wildly different odds. When AI supercharged both sides at once, it didn’t level that asymmetry. It widened it, because speed and automation help the side that only has to win once.
Here’s my take.
Most of the AI security noise is about smarter attacks. Corma is betting the bigger opportunity is the unglamorous side of the ledger, the defense that has to be right on the thousandth try, not the first. I spent years as an Army Reserve officer, and asymmetry is one of the first things you learn: the cheaper, faster side sets the tempo, and you don’t beat it by matching it move for move. You beat it by changing the shape of the fight. Whether Corma can actually change that shape is the open question. But its read on where the asymmetry sits looks right to me.
Find the lopsided fight. Then pick the side everyone else is ignoring.
This is for informational and educational purposes only. It isn’t investment, financial, legal, tax, or regulatory advice, and it isn’t an offer or solicitation to buy or sell any security or financial instrument.
If you want the mental models behind breakdowns like this, my book, Mental Models: How to Think, Act, and Win, is on Amazon now.


Compliance and attribution: Figures reflect Corma's August 10, 2026 announcement (ACCESS Newswire), corroborated by Fortune, SecurityWeek, and Calcalist (Ctech). Corma did not disclose a post-money valuation. The 88%/12% simulation results and the 94% response-time and 15x coverage figures are company-reported, drawn from Corma's internal experiments and early deployments, and are not independently verified here. This post is for informational and educational purposes only. It is not investment advice, research, or an offer or solicitation to buy or sell any security.



