Commercial platform
SwarmAttacker vs XBOW
The closed-source, vendor-hosted platform that topped HackerOne's US and global leaderboards in 2025.
- Vendor
- XBOW Inc.
- Licence
- Proprietary SaaS
- Pricing
- Usage-based, by quote. A self-serve Pentest On-Demand tier launched at ~$4,000 per test and was deprecated in July 2026.
- Checked
- September 2, 2026
| Capability | XBOW1 of 8 | |
|---|---|---|
| Free | Not found. | |
| Runs on a ChatGPT subscription | Not applicable. | |
| Custom prompts & skills | Partial. | |
| Safety-refusal handling | Not applicable. | |
| Parallel multi-agent swarm | Yes. | |
| MIT-licensed open source | Not found. | |
| Black-box from a URL | Partial. | |
| Model-agnostic | Not found. |
- yes
- not found or only partly
Hover a mark for the evidence. A cross means the capability was not found, or only partly found, on XBOW's public pages or repository on September 2, 2026, not that it is technically impossible.
Profile
What is XBOW?
XBOW is a Seattle offensive-security company founded in 2024 by Oege de Moor, the founder of Semmle. Its product is a closed-source, vendor-hosted platform that continuously pentests web applications and APIs. Public descriptions cite thousands of short-lived agents, each with a narrow objective, orchestrated by a persistent coordinator and confirmed by independent validators, plus a separate Guardian model that vets every action. XBOW chooses models per task, naming Claude, GPT and Gemini families and integrating GPT-5.5 in June 2026; customers cannot bring their own model.
Customers configure targets in a console with scope rules, authentication, rate limits, free-text attack hints and priorities, optional source-code upload for gray-box runs, and canary tokens; there are no user-defined skills or rules. The company ranked number one on HackerOne's US leaderboard in mid-2025 and globally that August.
XBOW has raised more than $270 million, including a $120 million Series C at over a billion-dollar valuation in March 2026, and reports 100 or more enterprise customers. Pricing is usage-based by quote; the self-serve Pentest On-Demand tier launched around $4,000 per test in November 2025 and was marked deprecated in July 2026. It is the best-funded company in the category.
In SwarmAttacker's favour
Where it stands out.
- 01You run it yourself. SwarmAttacker is a free MIT tool on your machine; XBOW is a closed hosted service sold by quote, and even its self-serve tier was retired in July 2026.
- 02Model choice and no per-token bill: SwarmAttacker runs on a ChatGPT plan or your own keys, while XBOW picks the model for you with no bring-your-own option.
- 03User-injectable skills and prompts, where XBOW allows only hints and canaries.
- 04Refusal handling is built in, because SwarmAttacker drives the model directly.
In XBOW's favour
Where it is stronger.
- 01Validated real-world results: roughly 1,060 HackerOne submissions, the number-one US and global rankings, and three critical Microsoft CVEs.
- 02Independent validators and near-zero-false-positive claims, with full audit trails.
- 03Production-safety controls: rate limits, test windows, protected URLs and a per-action safety judge.
- 04Enterprise footprint: 100 or more customers, cloud-marketplace availability and a compliance posture.
- 05Scale: thousands of parallel agents and more than $270 million in funding.
Verdict
Which one should you pick?
Pick XBOW if you are an enterprise buying a validated, production-safe, continuously running service and price is not the constraint. Pick SwarmAttacker if you want to run a capable black-box agent yourself, for free, on a ChatGPT plan, and read the code rather than take a vendor's word.
Sources
What this page was checked against.
All checked on September 2, 2026.
Turn a URL into a security report.
Open source, MIT licensed, and it runs on the ChatGPT plan you already pay for. Install it and point it at a target you own.
brew install joloooo/swarm/swarm