Socket, which helps companies safeguard open-source code against hackers, raised $60M led by Thrive Capital at a $1B valuation
Socket, a cybersecurity startup that sells technology to help safeguard open-source code against hackers, has raised a new round of funding that values the company at $1 billion.
Context & Ripple Effects
Socket’s latest financing follows a $20M Series A in 2023 and a $40M Series B in 2024, showing a rapid progression for a company focused on finding vulnerabilities in open-source code.
The company sits in an established but still heavily funded open-source security category: Snyk reached a $1B-plus valuation in 2020, while Chainguard also raised a sizable Series B for software supply-chain security.
First-order effects
- Socket gains $60M of additional capital and a $1B valuation, giving it more resources to build and sell its open-source code-security products.
- Thrive Capital becomes the lead investor in Socket’s newest round, tying its capital to a security vendor in the developer-software ecosystem.
Second-order effects
- Socket’s better-funded position raises pressure on open-source security rivals, including Snyk and supply-chain-focused vendors such as Chainguard, to differentiate their tooling and maintain investment in product development.
- Enterprise buyers evaluating open-source risk may see a stronger set of well-capitalized vendors competing for security budgets, increasing the importance of demonstrable vulnerability detection and software-supply-chain coverage.
Third-order effects
- If follow-on funding continues, open-source security is likely to become a more durable standalone software-security segment rather than a feature set confined to broader developer tools.
- The category could increasingly concentrate around vendors able to sustain product investment across the open-source software lifecycle, though the coverage does not establish which company will emerge as the long-term leader.
The trend: Security for the open-source software supply chain is attracting sustained late-stage capital as companies treat code dependencies as a core attack surface.