Socket, which sells a scanning tool for detecting vulnerabilities in open-source code, raised a $20M Series A led by a16z, taking its total funding to $24.6M
Open source is the bedrock upon which all modern applications are built. FinSMEs : Socket Raises $20M in Series A Funding Twitter: Wei Lien Dang / @weiliendang : Congrats @feross on @SocketSecurity's Series A! I remember huddling up together when you were just starting out and hearing your vision - it's super exciting to see Socket secure OSS software for everyone. @Unusual_VC is grateful to be part of your journey! @intenex : Huge congrats to @feross and everyone at Socket for raising an incredible $20 million Series A in like, the hardest fundraising environment ever! A true testament to just how incredible @SocketSecurity is - if you aren't using them already, start now!! https://techcrunch.com/... @feross : 🚀 Huge news! @SocketSecurity has raised $20M Series A funding led by Andreessen Horowitz (@a16z). ⭐️ This funding fuels our mission to make open source safer for everyone! 🚀🚀🚀 We're also announcing 4 new products this week as part of Socket Launch Week! ✨ 🧵 1/10 Satish Talluri / @satishtalluri : Very few people understand Javascript + DevX + Security well. @feross and @SocketSecurity is one of those rare teams. Super excited to be partnering with them to make software more secure. Danny Crichton / @dannycrichton : My college roommate is so much more productive than me. Congratulations @feross, and anyone interested in open-source software security or code supply chain attacks should check out @SocketSecurity: Arram Sabeti / @arram : Congrats to @SocketSecurity on their $20M Series A. @feross is one of the most formidable engineers I know. https://techcrunch.com/... David Gobaud / @davidgobaud : Congrats to @feross and the @SocketSecurity team! I was an early customer with Passfolio (fintech) and am a huge fan - was always worried about thousands of node packages... You can start protecting @github repos for free in <2 minutes https://github.com/... no reason not to! @feross : We will use the new funding to: 1️⃣ Improve our product capabilities - More languages, features, and powerful analysis 2️⃣ Grow our team - See open roles here: https://socket.dev/careers 🟧 Read the a16z announcement here: https://a16z.com/... 4/10
Context & Ripple Effects
Socket's $40M Series B and its later $60M raise at a $1B valuation make this 2023 round look like the entry point of a fast compounding story: a16z's $20M bet on open-source supply chain security was made in what contemporaries called the hardest fundraising environment, and the follow-on rounds validate the thesis.
The round also fits a16z's broader pattern of defending and backing open source — the firm signed a joint letter with Meta, Nvidia, and Microsoft defending open-source AI — making Socket both a portfolio bet and a strategic position on OSS as critical infrastructure.
First-order effects
- Socket gains $20M to scale its vulnerability-scanning tool beyond the $4.6M previously raised, with a16z taking a lead seat in a category it has publicly staked out.
Second-order effects
- Security-testing incumbents face new pressure: PortSwigger's later $112M first outside investment signals that buyers are funding dedicated code-security tooling rather than relying on general-purpose scanners, forcing the field toward specialization.
Third-order effects
- If the pattern holds — Series A to Series B to a billion-dollar valuation in roughly three years — open-source supply chain security consolidates into a recognized infrastructure category where enterprise budgets treat dependency scanning as table stakes rather than optional hygiene.
The trend: Venture capital is institutionalizing open-source supply chain security as a standalone category, with Socket's rapid funding cadence as the clearest early proof point.