Socket raises $60M at $1B valuation as supply chain security heats up
What's the deal? Socket, a cybersecurity startup that protects companies from software supply chain attacks, has raised $60M in a Series C led by Thrive Capital (Josh Kushner) at a $1B valuation — crossing the unicorn threshold. Existing investors Andreessen Horowitz and Abstract Ventures participated alongside new backer Capital One VenturesDealroom has a profile for this one. Try Dealroom →.
Socket proactively scans open-source packages for malicious behaviours including backdoors, typosquatting, and obfuscated code. With over 90% of modern applications built on open source, the attack surface is vast and growing.
Why now? Nation-state actors and criminal groups have increasingly targeted open-source supply chains — a vector that legacy Software Composition Analysis tools were not designed to catch. Socket reported 300% year-over-year revenue growth and recently acquired Sequoia-backed CoanaDealroom has a profile for this one. Try Dealroom → to push into broader application security.
Its previous round — a $40M Series B in October 2024 led by Abstract Ventures, Elad GilDealroom has a profile for this one. Try Dealroom →, and a16z — already drew heavy backing from tech founders including Bret Taylor, Jerry Yang, and Tobias Lütke.
What could go wrong? Cybersecurity is a crowded market. Larger players like Snyk, Sonatype, and GitHub's own Dependabot offer competing supply chain security tools. Socket must sustain its growth pace and prove its detection approach scales as attackers adapt.
The signal: A $1B valuation for an open-source security startup signals that the software supply chain has become a board-level concern. As AI-generated code accelerates the volume of dependencies, expect more capital to flow toward companies that can tell clean code from compromised code — fast.
Read more: Bloomberg