FuzzingLabs
FuzzingLabs is a Paris-based offensive security firm founded in 2021 that delivers firmware, binary, embedded, and blockchain vulnerability research for industrial, defense, and software-vendor clients via professional services, training, and the FuzzForge AI security platform.
- Company typePrivate
- Founded2021
- HeadquartersParis, France
- Headcount11–50
- GTM typeB2B
- OfferingServices
What FuzzingLabs does
FuzzingLabs is a Paris-headquartered cybersecurity firm founded in 2021 that provides offensive security services and tooling focused on firmware, binaries, embedded systems, and blockchain protocols. The company is led by CEO and founder Patrick Ventuzelo, a former French Ministry of Defense security researcher, with Tanguy Duhamel serving as Lead Developer. Its core commercial product, FuzzForge, is an AI agent orchestration platform for continuous offensive validation across firmware, binaries, and embedded systems, complemented by an in-house research effort called FAAST — a multi-agent system (Vulnerability Spotter, Tracer, Dynamic Exploiter) that combines LLM-based static analysis with dynamic runtime exploitation. The firm also publishes open-source tools (Thoth, Cairo-fuzzer, Sierra-analyzer, Solazy, Beaconfuzz) for blockchain ecosystems including StarkNet, Solana, and Ethereum.
FuzzingLabs monetizes primarily through professional services — security assessments (firmware audits, binary reverse engineering, hardware fuzzing, embedded vulnerability research aligned to CRA, RED Article 3.3, ISO/SAE 21434, IEC 62443, and DO-178C), software security engineering via Forward Deployed Engineers embedding into client SDLC and CI/CD pipelines (with on-premise, air-gapped, and SecNumCloud-compatible deployments), and expert training courses delivered both on-site at security conferences (OffensiveCon, REcon, RingZer0) and online via academy.fuzzinglabs.com. FuzzForge introduces a recurring subscription revenue component to a historically project-led business. Named customers span Meta, Google, Apple, Amazon, Intel, Cisco, CrowdStrike, Palo Alto Networks, Shopify, Coinbase, the Ethereum Foundation, the Worldcoin Foundation, Deloitte, Kudelski Security, and defense-aligned firms. LambdaClass acquired a strategic stake in 2024.
The company's go-to-market is enterprise field sales, leveraging Pwn2Own wins and conference presence at Black Hat, OffensiveCon, REcon, SSTIC, and others to drive inbound demand. Verticals served include industrial leaders, defense contractors, software vendors, blockchain protocols, and Web3 infrastructure providers. Geographic scope is global from a Paris base, with a distinct EMEA anchor. The firm is privately held, founder-led, and has no public funding-round history disclosed beyond the LambdaClass strategic investment.
FuzzingLabs firmographics
Firmographics- Name
- FuzzingLabs
- Legal name
- FuzzingLabs
- Website
- https://fuzzinglabs.com
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- FuzzingLabs is a Paris-based offensive security firm founded in 2021 that delivers firmware, binary, embedded, and blockchain vulnerability research for industrial, defense, and software-vendor clients via professional services, training, and the FuzzForge AI security platform.
- Ownership category
- akta.pro rank
FuzzingLabs industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Custom Computer Programming Services (541511), Software Publishers (5132)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Prepackaged Software (7372)
- akta.pro primary industry
- Model Security Testing & Red Teaming (adversarial ML, jailbreaks) (HDAAAKAC)
- akta.pro secondary industries
- Regulatory Readiness & Audit Automation (e.g., EU AI Act, NIST AI RMF, ISO/IEC 42001) (HDAAAMAE), Audit, Explainability & Accountability Tooling (traceability, reporting) (HDAAAKAL)
Keywords
Where FuzzingLabs is headquartered
LocationHeadquarters
- HQ city
- Paris
- HQ country
- France
- HQ region
- Europe
Offices1 record
Markets served
FuzzingLabs business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Security Assessments: Firmware audits, binary reverse engineering, hardware fuzzing, and embedded systems vulnerability research. Tailored to client stack and aligned with compliance requirements (CRA, RED Article 3.3, ISO/SAE 21434, IEC 62443, DO-178C).
- Software Security Engineering: Forward Deployed Engineers embed with client teams to integrate offensive validation into SDLC and CI/CD pipelines. On-premise, air-gapped, and SecNumCloud-compatible deployments available.
- Expert Training Courses: Hands-on cybersecurity training focused on firmware, embedded, reverse engineering, code security, and program analysis. Offered as on-site sessions and online certifications.
- FuzzForge Product: AI agent orchestration platform for continuous offensive validation, sold as a product to enterprise clients.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| One time/ perpetual license | Multi-year contract | Practical Web Browser Fuzzing Training (OffensiveCon 2025) |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels7 records
FuzzingLabs product offering
Product offeringCore offering
FuzzingLabs delivers offensive security services and the FuzzForge AI agent orchestration platform for continuous vulnerability discovery across firmware, binaries, embedded systems, blockchain protocols, and AI/ML systems. The firm combines elite security researchers with proprietary tooling to provide security assessments, embedded software security engineering, applied research, and expert-led training courses.
Product overview
FuzzingLabs is a cybersecurity company founded in 2021, headquartered in Paris, offering a portfolio of offensive security products and services. Their core commercial product is FuzzForge, an AI agent orchestration platform for continuous offensive validation across firmware, binaries, and embedded systems. Complementing FuzzForge, they provide security assessment services, software security engineering (Forward Deployed Engineers), applied R&D (fuzzers, binary translators, symbolic execution frameworks), and expert training courses. The company also develops open-source security tools including Thoth, Cairo-fuzzer, and Sierra-analyzer for StarkNet smart contract security, and Solazy for Solana analysis. They specialize in serving industrial leaders, defense, and software vendors facing CRA, RED, and IEC 62443 requirements.
Differentiator
Problem solved
Functional benefit
Brands
- FuzzForge: AI agent orchestration platform for continuous offensive validation across firmware, binaries, and embedded systems
Products and services
- FuzzForge AI agent orchestration platform that enables continuous offensive security validation across firmware, binaries, and embedded systems throughout the development lifecycle. Sold to enterprise clients in regulated and critical-infrastructure sectors.
- Security Assessment Services
Quantifiable outcome
- 3 Pwn2Own competition wins demonstrating elite vulnerability research capability
Companies that use FuzzingLabs
Customer profileNamed customers19 records
Segments4 records
Ideal customer profiles4 records
FuzzingLabs technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability6 records
Feature7 records
FuzzingLabs partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core.
- Worldcoin FoundationcoreFuzzingLabs partnered with Worldcoin Foundation for OP-TEE fuzzing to enhance security in the Worldcoin Orb. The partnership focuses on rigorous testing of the OP-TEE security framework, protecting biometric data and transaction processes within the Worldcoin protocol.
- Sui FoundationcoreFuzzingLabs partnered with Sui Foundation to enhance smart contract security on the Sui blockchain. The partnership involves developing and applying fuzzing tools specifically for Sui smart contracts.
- Story ProtocolcoreFuzzingLabs conducted a comprehensive 50 man-day security assessment of Story Protocol, a decentralized Layer 1 blockchain for IP management. Assessment covered execution layer, consensus layer, and smart contract modules.
- Aligned LayercoreFuzzingLabs completed an in-depth security audit of Aligned Layer's smart contracts and batch processing systems. Identified 28 vulnerabilities spanning DoS, race conditions, and access control flaws.
Scale indicators2 records
Recent moves6 records
Expansion highlights6 records
FuzzingLabs competitors and assessment
Company assessmentBroad incumbents
- OpenZeppelin: Established blockchain security and smart contract audit provider with broader product portfolio including developer libraries and security operations tooling. Comparable as a Web3 security incumbent whose audit services overlap with FuzzingLabs' blockchain engagements.
- CertiK: Large-scale Web3 security firm offering smart contract audits, formal verification, and security scoring. Comparable on blockchain security services and the regulatory/compliance angle, though CertiK operates at much greater scale and a more productized model.
- NCC Group: Global cybersecurity services firm offering penetration testing, hardware/embedded security, and red-teaming with strong regulatory and critical-infrastructure coverage. Comparable as a broad incumbent in the same security assessment/engineering space FuzzingLabs serves, with similar expertise in embedded and industrial systems.
Direct peers
- Nethermind Security: Blockchain engineering and security arm of Nethermind, offering smart contract audits, formal verification, and protocol security. Directly comparable on Ethereum/starknet security services and the combination of protocol engineering with offensive security research.
- Trail of Bits: New York-based boutique cybersecurity research firm offering security assessments, cryptography audits, and applied R&D with a similarly elite researcher profile. Directly comparable on services-led model, deep specialization (cryptography, blockchain, low-level systems), and high-end enterprise client base.
- Halborn: Blockchain-native security firm offering smart contract audits, penetration testing, and continuous security services. Directly comparable on the Web3 security positioning and the overlap between FuzzingLabs' StarkNet/Solana tooling and Halborn's smart contract practice.
- Zellic: Research-driven boutique security firm specializing in cryptography, blockchain, smart contracts, and systems-level security. Comparable on founder-led structure, elite talent, and a mix of audit services plus proprietary tooling aimed at continuous security testing.
- Runtime Verification: Formal verification and security firm focused on smart contracts, consensus protocols, and high-assurance systems. Comparable on the academic-grade research profile, K-framework/symbolic execution tooling, and deep overlap with FuzzingLabs' blockchain security engagements.
Emerging players
- Spearbit: Curated network of independent security researchers offering smart contract audits. Comparable on the elite-independent-researcher model and competitive overlap for blockchain/Web3 assessment work, though structured as a marketplace rather than an in-house research firm.
- Lakera AI: AI security startup offering adversarial testing, red-teaming, and guardrails for LLM applications. Comparable on the AI-driven offensive security positioning, particularly FuzzingLabs' FAAST work and its AI/ML security service line, though Lakera is purely product-led rather than services-led.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
FuzzingLabs social profiles
Digital presenceFuzzingLabs financial estimates
Financial estimateRevenue estimate
Valuation estimate
FuzzingLabs leadership team
Management profileNumber of profiles
Profiles2 records
FuzzingLabs funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
FuzzingLabs M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about FuzzingLabs
What does FuzzingLabs do?
FuzzingLabs delivers offensive security services and the FuzzForge AI agent orchestration platform for continuous vulnerability discovery across firmware, binaries, embedded systems, blockchain protocols, and AI/ML systems. The firm combines elite security researchers with proprietary tooling to provide security assessments, embedded software security engineering, applied research, and expert-led training courses.
Is FuzzingLabs a public or private company?
FuzzingLabs is a private company. It is classified as venture growth investor backed and is currently operating.
When was FuzzingLabs founded?
FuzzingLabs was founded in 2021. It employs 11 to 50 people.
Where is FuzzingLabs based?
FuzzingLabs is headquartered in Paris, France, in the Europe region.
How does FuzzingLabs make money?
Four revenue lines are on record. Security Assessments are the primary driver. The others are software Security Engineering, expert Training Courses and fuzzForge Product.
Who are FuzzingLabs's main competitors?
Broad incumbents on record are OpenZeppelin, CertiK and NCC Group. Direct peers are Nethermind Security, Trail of Bits, Halborn, Zellic and Runtime Verification. Emerging players are Spearbit and Lakera AI.
Does FuzzingLabs have an API?
No public API is recorded for FuzzingLabs.
What industry is FuzzingLabs in?
FuzzingLabs's product category is Cybersecurity Services. Its primary akta.pro industry code is HDAAAKAC, Model Security Testing & Red Teaming (adversarial ML, jailbreaks), with a secondary code of HDAAAMAE, Regulatory Readiness & Audit Automation (e.g., EU AI Act, NIST AI RMF, ISO/IEC 42001). Its NAICS code is 541511 and its SIC code is 7370.