{"id":106270,"title":"Fabraix: The Frontier Agent that Hacks Customer-facing AI.","tagline":"Fabraix builds AI red-teaming agents that continuously detect security vulnerabilities in customer-facing AI. We already found vulnerabilities in agents at dozens of Fortune 500 companies.","body":"**TL;DR**: Fabraix builds AI red-teaming agents that continuously detect security vulnerabilities in customer-facing AI. Our product, Nyx, has already found vulnerabilities in agents at dozens of Fortune 500 companies, and hits a 78% attack success rate on AgentHarm (leading offensive AI security benchmark) vs. 67% for GPT-5.6 Sol.\n\n**Ask**: If your team ships customer-facing AI agents (chat, voice, browser, or coding) and needs to continuously test them for security vulnerabilities, find us at [founders@fabraix.com](mailto:founders@fabraix.com).\n\n\u003chttps://www.youtube.com/watch?v=WHmJIMIuAEM\u003e\n\n**The Problem**\n\nAI agents introduce new vulnerabilities not present in traditional software..\n\nIn order for agents to be truly useful, they must be trusted to interact with untrusted surfaces like MCPs, websites and files, take real actions, and have access to confidential data. You can’t tell your defenses are sound by just reading your prompts since the agent's behaviour is not deterministic. The best thing to do is run your agent and really try to break it.  \n\nDoing this red-teaming process manually is time consuming, costly, and you are unlikely to catch everything. And as soon as the agent is updated, you need to repeat it. Security teams simply don’t have the bandwidth to keep up with the rapid deployment inside organisations.\n\n**Our Solution**\n\nNyx is our red-teaming agent that tests customer-facing AI agents, via direct interaction and also indirectly via its environment. It requires no access to your agent’s source code in order to test.\n\nNyx is highly adaptive when attacking. Rather than cycling through hard coded payloads like existing tools, it dynamically adjusts its attack strategies based on your agents defenses and responses. It probes your agent over a wide surface area of attack vectors, and deep dives This adaptive approach makes it 20x more effective as a red-teamer compared to other solutions.\n\nWe maintain a library of over 10,000 attack strategies and jailbreaks. These are high level strategies which are used by Nyx to generate dynamic adaptive attacks, over multiple turns. \n\nEvery finding includes the attack steps, the agent’s responses, and the resulting failure for you to reproduce. You can then rerun the same test after a release to check whether the failure remains fixed. \n\nOn the AgentHarm benchmark, Nyx achieved a 78% attack success rate, compared with 67% for GPT-5.6 Sol. Nyx has also found exploitable failures in public-facing agents operated by dozens of Fortune 500 companies.\n\nWe also built ACE (Adversarial Cost to Exploit), a benchmark that measures AI security in terms of how much it costs attackers to break an AI system; providing a game-theoretic framework to understand how motivated a rational attacker would be in exploiting the system.\n\n**The Team**\n\nWe both have a lot of experience building and securing AI agents at scale.\n\nIbrahim built AI agents at Meta that diagnosed and fixed production errors. Before that, he built compilers and database engines in Fintech. He graduated from Oxford in the top 8% of his cohort.\n\nAhmed led international payments fraud team at Monzo. Before that, he was the first data scientist at a Sequoia-backed startup, where he built its fraud engine from scratch into processing more than $1B in annual B2B transactions and preventing tens of millions in losses for Fortune 150 companies. He has published several peer-reviewed research papers in Q1 journals.\n\nWe previously worked together, and have known each other for almost four years.\n\n![uploaded image](/media/?type=post\u0026id=106270\u0026key=user_uploads/693526/5f437cbd-2009-40cc-8c69-746da9ea8300)\n\n**The Ask**\n\nIf you ship a customer-facing (chat, voice, browser, or coding) agent, we can help you find all the failure modes and built a self-healing loop to discover, triage, and maintain secure AI agents.\n\n[founders@fabraix.com](mailto:founders@fabraix.com)","slug":"Re2-fabraix-the-frontier-agent-that-hacks-customer-facing-ai","created_at":"2026-07-20T15:06:58.917Z","updated_at":"2026-07-22T14:03:35.491Z","total_vote_count":112,"url":"https://www.ycombinator.com/launches/Re2-fabraix-the-frontier-agent-that-hacks-customer-facing-ai","share_image_url":"https://www.ycombinator.com/media/?type=post\u0026id=106270\u0026key=user_uploads/693526/5f437cbd-2009-40cc-8c69-746da9ea8300","company":{"id":32624,"name":"Fabraix","slug":"fabraix","url":"https://fabraix.com","logo":"https://bookface-images.s3.amazonaws.com/small_logos/d3d83aa2013bbe6b22b37f316b294d0c717eea35.png","batch":"Summer 2026","industry":"B2B","tags":["Reinforcement Learning","Cybersecurity","AI"],"search_path":"https://bookface.ycombinator.com/company/32624"}}