Socket, which helps companies safeguard open-source code against hackers, raised $60M led by Thrive Capital at a $1B valuation
Context & Ripple Effects
Socket’s latest round follows a $40M Series B in 2024 and a $20M Series A in 2023, extending a funding trajectory around tools that identify vulnerabilities in open-source code.
The company sits in an established software-supply-chain security category alongside Chainguard and earlier open-source vulnerability specialists such as Snyk. The $1B valuation signals that investors see Socket as a scaled contender rather than a point-tool startup.
First-order effects
- Socket gains $60M to expand its effort to protect companies’ use of open-source code, with Thrive Capital becoming the lead backer of the new round.
- The financing resets Socket’s market position at a $1B valuation, giving it a stronger capital base relative to other vendors targeting open-source and supply-chain security.
Second-order effects
- Competing security vendors will face greater pressure to demonstrate differentiated coverage across open-source dependencies, rather than only vulnerability detection.
- Corporate buyers evaluating software-supply-chain tools may gain another well-capitalized vendor option, increasing competition for security budgets in this segment.
Third-order effects
- If funding and valuations continue concentrating in this category, open-source security is likely to become a more distinct strategic software-security market, with vendors competing to own the developer-to-production workflow.
- The pattern could favor platforms that turn dependency visibility into actionable safeguards; whether standalone vendors remain independent or consolidate is still uncertain from the available coverage.
The trend: Socket’s round is one data point in the maturation of software-supply-chain security from vulnerability scanning into a higher-value platform market for governing open-source code risk.