Most corporate security teams spend their days worrying about phishing emails and software patches. Eclypsium wants them looking several layers deeper—at the firmware and hardware chips that power on before Windows or Linux even wake up.
The Portland cybersecurity firm announced Thursday it has closed a $25 million strategic financing round led by PEAK6 Strategic Capital, bringing its total raised past $100 million. What makes the round noteworthy isn't just the size: one of the participants is what Eclypsium described only as a "top three US bank," a sign that firmware security—long relegated to niche corners of enterprise IT—may finally be getting boardroom attention.
For Eclypsium, the money arrives at a moment when two forces are converging in its favor. Financial institutions, still scarred by supply chain breaches and increasingly stringent regulatory scrutiny, are hunting for tools that protect the parts of their infrastructure traditional antivirus can't reach. And the explosion of AI hardware—GPU farms, edge processors, specialized inference chips—has created an entirely new attack surface at the firmware level, one that didn't exist at scale even three years ago.
"We're seeing a shift," said the company in a statement accompanying the March 19 announcement. The focus: doubling down on financial services and AI infrastructure, two verticals where a compromised baseboard management controller or rogue firmware update could mean millions in losses or, worse, a compliance nightmare.
The Intel Pedigree
Eclypsium's founders didn't stumble into this space. Yuriy Bulygin and Alex Bazhaniuk spent years at Intel—Bulygin leading security threat analysis, Bazhaniuk developing CHIPSEC, an open-source framework that became something of a standard for poking at platform-level vulnerabilities. When they left to start Eclypsium in 2017, their thesis was almost boringly logical: as operating systems and applications hardened, attackers would go lower. Into the BIOS. Into network card firmware. Into the management interfaces that IT teams use to remotely power-cycle servers at 3 a.m.
That was the bet, anyway. And for a while, it was a tough sell. Firmware security lacked the visceral urgency of ransomware or the headline appeal of zero-days in popular software.
But a few high-profile incidents helped. Supply chain compromises—where malicious code entered hardware before it ever reached a buyer—shifted the conversation. So did the discovery of vulnerabilities in widely deployed server management tools, the kind that let an attacker own a data center from the inside out. Suddenly, the "below the OS" pitch didn't sound so esoteric.
Today, Eclypsium's platform scans endpoints, servers, network gear, and—critically—GPUs and AI accelerators for supply chain tampering and firmware anomalies. In 2025, the company joined NVIDIA's Inception program, a move that added capabilities specifically for assessing generative AI infrastructure. And in August 2023, it struck a partnership with Lenovo to bake Eclypsium's tech into ThinkShield Firmware Defense, embedding the product directly into enterprise hardware.
A Funding Velocity That Suggests Traction

Fourteen months. That's how long it's been since Eclypsium's last raise—a $45 million Series C on January 28, 2025 that blended equity and debt and pulled in Qualcomm Ventures, Pavilion Capital (the venture arm of Singapore's Seviora Group), and Singtel Innov8. Also on board: earlier backers Andreessen Horowitz, Ten Eleven Ventures, and Madrona Venture Group.
Before that came a $25 million Series B in October 2022, led by Ten Eleven and featuring new checks from KDDI Open Innovation Fund and J-Ventures. The company had raised an $8.75 million Series A in December 2018 and $13 million in additional funding in October 2020.
By Eclypsium's own accounting at the time of the Series C, total funding stood at $85 million. The PEAK6-led round pushes the total past $100 million—a pace that suggests either genuine traction or investor conviction that firmware security is about to go mainstream. Perhaps both.
Why a Bank—and Why Now

PEAK6's involvement makes strategic sense. The Chicago-based firm has a track record in fintech and enterprise infrastructure, and financial services institutions are under pressure from regulators and auditors to account for risks buried in their supply chains. A corrupted firmware update in a payment processing server isn't theoretical; it's the kind of scenario that keeps compliance officers awake.
The unnamed bank's participation—disclosed but not identified—signals demand from the sector, though one has to wonder if the secrecy reflects reluctance to publicly acknowledge firmware vulnerabilities or simply standard strategic investment confidentiality.
Either way, the company says the fresh capital will fuel sales expansion in financial services, fund R&D aimed at AI infrastructure, and support ongoing research into supply chain security. Eclypsium distributes through partners like SHI, World Wide Technology, GuidePoint Security, and Myriad360.
The company's headcount, based on third-party estimates from early this year, hovers somewhere between 108 and 129 employees. Not huge, but sizable enough to suggest an organization moving past pure startup mode into operational scale.
What remains to be seen is whether the broader market will follow where Eclypsium's investors are betting. Firmware security is no longer a fringe concern, but it's not yet a default line item in most IT budgets either. The company is wagering that AI infrastructure and financial sector scrutiny will change that calculus. If they're right, this $25 million may look modest in hindsight.
