AI Agent Security: A $20 Breach, a $32B Exit, and the Category That Just Got Created
The Convergence
Three events in a single cycle just defined AI agent security as the next multi-billion-dollar cybersecurity category. A red-team startup called CodeWall broke into McKinsey's internal AI platform — 20,000 agents, 46.5 million chats, 500,000 prompts per month — in two hours for $20 in API tokens. The vulnerability? A SQL injection that McKinsey's own scanners missed for two years in production. The agent had write access to all 95 system prompts governing Lilli's behavior across 30,000 consultants serving Fortune 500 clients.
Simultaneously, Google closed its $32 billion acquisition of Wiz — the largest-ever VC-backed exit — confirming that hyperscalers will buy, not build, critical security infrastructure. And new scan data shows 66% of 1,808 MCP servers expose security issues while 93% of audited AI agents use unscoped API keys stored in environment files.
When the cost of breaching an enterprise AI platform drops to $20 and the largest tech acquirer in history pays $32B for security, the category creation signal is unambiguous.
The Business Model Shift Underneath
The AI security opportunity sits atop a broader ransomware business model pivot. Successful encryption deployments collapsed from 54% to 36% in a single year — but data exfiltration now occurs in 77% of intrusions, up from 57%. Data leak site posts surged 48% to 7,784. Attackers haven't been beaten — they've found a more capital-efficient model. This reprices the entire cybersecurity investment map:
- Backup/recovery companies whose ransomware thesis depended on encryption face weakening value propositions — you can't restore your way out of stolen data being published
- Data security and DLP move from compliance-driven to existential urgency, with TAM uplift from the business-model shift
- AI-native SOC platforms become an existential necessity when HexStrike exploits thousands of Citrix instances in under 10 minutes while CISA's patch timeline sits at 15 days
Who's Moving First
Onyx Security launched with a $40M war chest as the first purpose-built AI agent governance platform — discovering, monitoring, and governing autonomous agents across cloud, endpoints, code, and SaaS. Maze (AI remediation agents), Cotool (AI-agent SOC operations), and Sondera (centralized agent supervision) represent three distinct entry points. Anthropic published an attack-agent security blueprint this week — acknowledging the problem but not building the full commercial solution.
The pattern is identical to cloud security circa 2015: the platform builders acknowledge the risk, third parties build the security layer, and the first movers capture disproportionate value. Wiz was the outcome of that cycle. The $32B question: who becomes the Wiz of AI agent security?
The Post-Wiz Vacuum
Wiz inside Google loses multi-cloud neutrality. Every AWS and Azure customer running Wiz will reconsider. This opens a displacement window for remaining independents and puts pressure on AWS and Microsoft to make their own acquisitions. The entire cloud security valuation ceiling just repriced upward — and the AI agent security category sits one layer above it.
What to do
Source 3-5 AI agent security startups building runtime governance, MCP security, or autonomous defensive agents — target Series Seed-A before category gets named
Issue portfolio-wide advisory requiring AI agent security posture review and AI-specific pen test within 30 days for any company deploying internal AI agents
Map remaining independent cloud security companies for acquisition arbitrage following Wiz's $32B exit — benchmark valuations against this new ceiling
Re-evaluate backup/recovery portfolio positions against pure data exfiltration scenarios — demand board-level strategy if exfiltration defense is weak