V12 lands $10M seed after its AI agent won US$1.62M bug bounty
What's the deal? V12, an AI-first offensive security startup, has raised US$6.47M seed round to build autonomous systems that find and exploit software vulnerabilities at scale. The round included participation from crypto security and research figures alongside other angels; V12 did not disclose a valuation or institutional backers.
Why now? The raise follows V12's AI agent independently earning US$1.62M bug bounty for finding a critical flaw in a major blockchain that put more than $100 million in user funds at risk, according to a company post.
What's the endgame? V12 positions itself as an AI-native vulnerability research system focused on white-box code auditing, not generic pentesting. Its agent has reportedly found multiple critical 0days, including Linux privilege escalations, a QEMU escape, Firefox UXSS, and bidirectional RCEs in Postgres and Redis. The team describes its goal as a "cyber nuke" — a system that reasons over large codebases, invents new bug classes, and produces working exploits.
The founders previously built Zellic, which performed more than 1,500 security reviews for over 500 clients including exchanges, L1s, bridges, and wallets. Before that, they led CTF team perfect blue, which held the top global ranking for three years.
The product: V12 is making its tool self-serve, offering new users $200 of free credits for one week. The new capital will fund its research agenda and package the AI into products that embed into developer workflows across Slack, GitHub, command-line interfaces, and agent frameworks.
What could go wrong? V12 is openly critical of traditional responsible disclosure, arguing embargoes and long patch gaps are untenable when anyone can rebuild exploits from public commits. It advocates open disclosure and near-instant patching — a stance likely to draw pushback from defenders reliant on gated safety models.
The signal: V12 is using crypto as its wedge, arguing onchain projects are among the few verticals forced to prioritise real bug-finding over compliance. It claims more than $500 million has been stolen in crypto hacks this year and expects AI-accelerated offence to push every sector toward treating all code as high-assurance — while traditional bug bounties shrink to niche markets as autonomous tools mine out bugs pre-ship.
Read more: CryptoRank
Image credit: Visual Content