AI Agent V12 Raises $10M After Securing Largest Bounty

Key Takeaways

Security AI agent V12 secured a $10 million seed round led by Electric Capital. The funding follows a $2.5 million payout for a critical blockchain flaw, signaling a shift from human-led audits to automated, high-volume vulnerability discovery in crypto i

Woofun AI reports that security AI agent V12 has completed a $10 million seed funding round, a milestone driven by its recent discovery of a critical flaw in a major public blockchain. The round was led by crypto venture capital firm Electric Capital, with backing from prominent industry figures including on-chain investigator ZachXBT, white-hat researcher samczsun, and Walden Yan, co-founder of Cognition. Additional support came from over thirty individual investors associated with security research, Anchorage Digital, Avalanche, OpenAI, Jupiter, and Mysten Labs. This capital injection underscores the growing investor confidence in AI-driven security tools capable of identifying high-value risks autonomously.

The financial details of the round were disclosed on July 30 via Twitter, highlighting the strategic alignment between traditional venture capital and emerging AI security paradigms. The investor roster reflects a broad coalition of interests, ranging from pure-play crypto entities to generalist tech investors. This diverse backing suggests that the market perceives V12’s technology not merely as a niche tool for blockchain audits, but as a scalable solution applicable to broader software security challenges. The speed at which this round was closed indicates strong demand for automated security capabilities in an increasingly complex digital landscape.

Central to V12’s valuation is its proven ability to generate significant returns through vulnerability discovery. Earlier in the month of the funding announcement, V12 independently identified a vulnerability on a major public blockchain that posed risks exceeding $100 million. For this discovery, the agent received a $2.5 million bounty, a sum described as "the largest vulnerability bounty ever received by an AI agent." The vulnerability was subsequently patched through collaboration between V12 and the project team. This event serves as a concrete proof-of-concept for the economic viability of AI agents in the security sector.

The team behind V12 possesses a deep history in competitive cybersecurity, tracing its roots to Perfect Blue, a group that topped CTFtime’s annual points rankings three times. Perfect Blue won independently in 2020 and 2021, and again as the merged team Blue Water in 2023. CTFtime is recognized as the most credible ranking system in the Capture The Flag (CTF) community, scoring teams based on consistent performance across dozens of public competitions weighted by team size. While CTFtime operates separately from DEF CON CTF, considered the highest-standard event in the field, Blue Water reached the finals in 2025, finishing as runner-up. This track record demonstrates sustained excellence in offensive security techniques over nearly a decade.

Two core members of Perfect Blue, Luna Tong (co-founder and CEO of Zellic) and Jasraj Bedi (also known as Jazzy, co-founder and CTO), established Zellic, an agency specializing in auditing smart contracts and emerging technologies. According to their disclosures, Zellic has completed over 1,500 security audits, serving more than 500 high-risk clients. These clients include exchanges, cross-chain protocols, public blockchain projects, and open-source operating systems. The transition from competitive CTF teams to a commercial audit firm provides V12 with a robust foundation of real-world security expertise and industry connections.

V12 first emerged in September 2025 as an "internal tool of Zellic," hosted at v12.zellic.io. The U.S. Patent and Trademark Office records show that the V12 trademark was applied for in March 2026 by the newly registered entity Zellic AI Inc. The tool was later moved to an independent domain, v12.sh, accompanied by an independent X account. Zellic’s official website still lists Tong and Bedi as co-founders of both companies. V12 claims all its team members come from the CTF or vulnerability research field, citing achievements such as three named Linux privilege escalation 0days (Fragnesia, Pintheft, DirtyDecrypt), one QEMU virtual machine escape vulnerability, and a bidirectional remote code execution vulnerability between Redis and Postgres.

Additional findings include issues related to MariaDB and AnyDesk. These vulnerabilities are considered high-risk or fatal under traditional standards: Linux Local Privilege Escalation (LPE) allows ordinary users to obtain root privileges; QEMU escape enables bypassing virtualization isolation to attack the host machine, affecting other tenants in multi-cloud environments; and bidirectional remote code execution between Redis and Postgres allows external control of critical database services. This breadth indicates V12’s capabilities extend far beyond smart contract auditing.

Woofun AI data shows that the crypto industry faced significant losses in the first half of 2026, with hack attacks causing approximately $972 million to $1.1 billion in damages. TRM Labs estimates $972 million across 207 incidents, while Blockaid estimates over $1.1 billion across 212 incidents, marking an all-time high for that period. V12 argues that bounties for serious vulnerabilities in crypto can range from tens to hundreds of millions of dollars, whereas $50,000 is considered substantial outside the sector. To support this, V12 cites code complexity metrics: the Solana client Firedancer contains around 722,000 lines of C code, while Geth and Prysm combined have about 1.1 million lines of Go code, with complexity comparable to general-purpose software like Postgres. This volume of code creates a vast attack surface that manual auditing struggles to cover effectively.

In terms of product design, V12 operates as a self-registration web application alongside command-line tools. New users receive a $200 free credit valid for 7 days. The web interface includes modules for Runs, Findings, Artifacts, and Autopilot, with discoveries categorized by severity. As of the time of writing, V12’s official blog and product page do not mention any token issuance or airdrop plans. Instead, its business model relies on a subscription fee charged according to usage. This structure aligns the company’s incentives with customer success, ensuring that revenue is generated through sustained engagement rather than speculative asset distribution.

V12’s ethical stance on disclosure challenges traditional security norms. The team admits that "it is wrong to irresponsibly release attack capabilities before the world is ready for them," yet argues that current "controlled access" and "security qualification checks" often serve as public relations tactics to prevent ordinary developers from gaining attack-defense capabilities. V12 believes that widespread access to vulnerability-finding tools is the most effective way to ensure quick discovery and fixes.

This philosophy is illustrated by the team’s own discovery of three Linux privilege escalation 0days, whose patches were leaked through public submission records before integration into the main Linux kernel. V12 argues that coordinated disclosure and embargo periods will eventually phase out, citing the case of the open-source project curl. Daniel Stenberg, maintainer of curl, announced on January 21, 2026, that the bounty program, which had run for about six years and paid out approximately $86,000, would end due to an overwhelming volume of low-quality AI-generated reports.

This suggests the traditional bounty model is being exploited in reverse by AI efficiency.

The theoretical limits of V12’s approach are acknowledged by the team, which notes that proving a system is "vulnerability-free" is mathematically equivalent to the "halting problem," proposed and proven by Turing in 1936. This problem states that no universal algorithm can determine whether any program will run forever, serving as a classic example of unsolvable computational problems. V12 points to the 2024 incident involving XZ Utils, which infiltrated OpenSSH’s dependency chain and nearly became a large-scale backdoor, as evidence of supply chain attacks spreading from crypto to fundamental software.

This perspective is shared by other funded entities: Beacon Security completed a $13 million seed round in 2026 to organize security telemetry data for human analysts and AI agents, while Onyx Security completed an $113 million Series B round to regulate AI agent behavior within enterprises. Although these companies operate in different fields, they share the belief that AI will reshape the security industry. The success of this bet depends on V12’s assessment that the security system built on the assumption of "scarcity of attackers" is becoming ineffective.

When AI significantly reduces the cost of discovering vulnerabilities, traditional mechanisms like bounty programs and voluntary disclosure, designed for an era of scarce attack-defense capabilities, will fail. The window for developers to adjust their security strategies is likely shorter than anticipated, marking a definitive end to the era of human-centric security scarcity.

Vote

Will AI agents reshape blockchain security?

0 people voted

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions