NEW
Postmortem: how an AI found the $116M Coldcard flaw first
Read →
Vallum
Platform
Threat Intel
Open Source
Docs
Sign in
Book a call
14,208 AUTOMATED ATTACKS BLOCKED TODAY
The security proxy built for the age of AI attacks
One DNS change puts a machine-speed firewall between your infrastructure and agentic recon, LLM-driven exploit discovery, and credential sweeps.
Start blocking free
Book a call
No credit card required · One DNS change · SOC 2 Type II
Traffic
HUMANS + AGENTS
→
Cloudflare / CDN / WAF
YOUR EXISTING LAYERS
→
Vallum Proxy
DETECT · JAMBLE · BLOCK
OPEN SOURCE CORE
→
Your origin
UNTOUCHED
Drops into your existing stack — compatible with
Cloudflare
·
Fastly
·
CloudFront
·
nginx
·
HAProxy
— or runs standalone.
PROTECTING
Ledgerline
Nodeworks
Signal&Co
Vaultic
Meridian Pay
Archon Cloud
41B+
requests inspected monthly
<0.8ms
added latency at the edge
99.98%
detection precision
92s
to fingerprint a new attack agent
INCIDENT LOG
AI-powered attacks are already here
View all incidents
ONGOING · AUG 2026
HARDWARE WALLETS
Coldcard exploit drains $116M in Bitcoin — attacker likely used AI to find a 5-year-old entropy flaw
Coinkite says it must assume advanced AI models reviewed its open-source firmware and found the flaw its own AI-assisted audits missed — 1,596 BTC swept from 5,200+ addresses without touching a device.
Read the analysis →
FEB 2025 · EXCHANGE
Bybit loses $1.5B in the largest crypto heist in history
Lazarus Group compromised a cold-wallet signing flow with a manipulated interface — faster than humans could react.
Read →
JUL 2026 · AI INFRA
Hugging Face breached by an autonomous AI agent
Production infrastructure compromised end-to-end — agentic attackers moved from research papers to live incidents.
Read →
SEP 2025 · ESPIONAGE
First large-scale cyber-espionage campaign run by AI agents
~30 organizations targeted, with AI autonomously executing 80–90% of attack tasks — recon to exfiltration.
Read →
THE PLATFORM
A reverse proxy that thinks at machine speed
01
Behavioral fingerprinting
Profiles every session in real time — tool-loop cadence, token-timing signatures, and navigation entropy that separate LLM agents from humans, even behind residential proxies.
02
Adaptive counter-agents
Defensive models red-team your own surface continuously, finding the exposed endpoint before an attacker's model does — closing the gap that sank Coldcard.
03
Machine-speed response
On detection, Vallum rewrites the rules of engagement in milliseconds — rotating challenges, poisoning recon output, quarantining campaigns across every edge at once.
04
Drop-in deployment
A single DNS change or sidecar. No SDK, no code changes. Full inspection on every request with sub-millisecond overhead across 96 edge locations.
05
NEW
API response jambling
Preventive measures on every API response: field names, orderings, and structures are selectively scrambled for unverified agents — humans and your apps see clean data, while LLMs parsing your API get noise they can't learn from.
06
Stacks with your existing proxies
Fully compatible with Cloudflare, Fastly, CloudFront, nginx, HAProxy, and any load balancer. Vallum slots in as another hop — keep your WAF, CDN, and TLS setup exactly as they are.
OPEN SOURCE
The core proxy is open source
Audit every line that touches your traffic. Self-host the MIT-licensed core, or let us run the edge network and threat-intel feed for you. No black boxes in your request path.
★ Star on GitHub
Read the docs
vallum/vallum-proxy
★ 18.4k
MIT
# deploy the open-source core
$ git clone github.com/vallum/vallum-proxy
$ vallum up --origin=api.internal --jamble=strict
✓ edge live · 0.8ms overhead · agents jambled
NO PRICING PAGES. NO SALES MAZE.
Just book a call
30 minutes with an engineer, not a rep. We'll scope your stack and quote flat.
Vallum Security
Intro call — scope & quote
⏱ 30 min
🎥 Google Meet
🌐 Your timezone
POWERED BY CAL.COM
August 2026
‹
›
MON
TUE
WED
THU
FRI
SAT
SUN
27
28
29
30
31
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
Fri, Aug 7
10:00
10:30
11:00
13:30
15:00
© 2026 Vallum Security, Inc.
Privacy
Terms
Security
Status
ALL SYSTEMS DEFENDED ●