Company profile / AI security

The Password Game That Became an AI Security Business

Lakera invited the internet to trick a chatbot into giving up a password. The resulting attack data helped build a guardrail business - and became part of Check Point’s bid to secure the AI workplace.

The wizard had a secret. Your job was to make him tell you. Gandalf, a deceptively simple online game from Zurich startup Lakera, gave players a chatbot with a hidden password and a series of increasingly stubborn defenses. A player could ask nicely, impersonate an authority, invent a crisis, or bury an instruction in a longer prompt. The prize was only the next level. The lesson was much bigger: language itself had become a way into software.

The short version
  • Lakera turned Gandalf’s public prompt-injection attempts into research for its AI guardrails.
  • Its runtime product checks AI inputs, outputs and agent tool interactions against policy.
  • Customers including Dropbox and Nubank use its technology in enterprise AI work.
  • Check Point bought Lakera in 2025 and expanded the portfolio from applications to employees, agents and firewalls.

Most cybersecurity stories begin with somebody trying to keep attackers out. Lakera’s memorable move was to invite them in, provided the target was a game. By 2023 Gandalf had drawn more than half a million players. Check Point now says over a million people have played and that the project has gathered more than 80 million adversarial prompts. These are company-reported figures, but the underlying idea is easy to grasp. A rule written in a conference room can imagine only so many tricks; a crowd will try jokes, translations, false emergencies and things no policy writer expected.

Lakera founders David Haber, Matthias Kraft and Mateo Rojas-Carulla together
Three founders, one awkward question for every chatbot: what happens when a stranger asks for the thing it was told to keep secret?

A game with a second job

David Haber, Matthias Kraft and Mateo Rojas-Carulla founded Lakera in 2021. Their earlier machine-learning work included aerospace and healthcare, where a model’s mistakes can carry costs beyond an embarrassing answer. As large language models moved into business software, the team saw a familiar problem in a new costume: an AI application might follow instructions from data it should treat as untrusted. The stranger need not be the person chatting with the bot. The instruction could be tucked into a webpage, document, search result or tool response.

Gandalf made this failure visible. Players attempted to extract a password through persuasion rather than a traditional code exploit. Lakera used the resulting attack patterns, along with its own research and public datasets, to improve detectors. Then it packaged the protection as Lakera Guard, a runtime API released publicly in 2023. Developers could send a conversation to the service and receive a policy decision before the application proceeded. The company also offered Lakera Red, for testing systems before and after deployment. Gandalf was the laboratory; Guard and Red were the products.

That loop is a useful way to understand the company’s place in the market. A conventional web firewall looks for hostile traffic patterns. AI security has to interpret meaning and context: is a customer asking a legitimate question, or is a retrieved document instructing an agent to disregard its owner? The difference is sometimes a sentence, not a suspicious file extension. Lakera’s bet was that fast, specialized screening could sit close enough to an application to decide while the conversation was still happening.

The expensive part is being useful

A detector that blocks everything would be secure in the way a permanently locked shop is secure. Enterprises need the bot to keep working. Dropbox, for example, describes a self-hosted, bespoke AI architecture that required one central place to monitor and protect multiple generative AI applications. It chose Lakera Guard after a technical evaluation that weighed speed, deployment flexibility and false positives. The protection was integrated into its central LLM library, so product teams could use it across different applications. Dropbox says the system caught the vast majority of its prompt-injection and jailbreak tests while keeping response times low.

“The Lakera team has accelerated our GenAI journey, allowing us to create secure GenAI experiences at scale.”Adrian Wood, security engineer at Dropbox

Nubank describes another constraint: a regulated banking environment, large-scale operations and support for Portuguese and Spanish. An unnamed Fortune 500 education company used Lakera to protect AI products for children; its published case study describes two major applications covered, with more planned. These examples make the sales pitch less abstract. The buyer is usually a security or engineering team trying to give many product groups one defensible policy without turning every AI feature into a separate security project.

$30mSeed and Series A funding disclosed before acquisition
$201.8mApproximate total acquisition consideration in Check Point’s filing
80m+Adversarial Gandalf prompts reported by Check Point

Lakera raised $10 million in a seed round led by Redalpine and $20 million in a 2024 Series A led by Atomico. Check Point completed its purchase of Lakera AI AG on October 22, 2025. In its securities filing, Check Point put total consideration at about $201.8 million. That is the clearest public answer to what the acquisition cost; it should not be confused with the value of every product in Check Point’s wider AI security portfolio.

The chatbot grew hands

The risk changed as AI systems became agents. A chatbot that produces an odd answer may inconvenience someone. An agent with access to files, payment systems or developer tools can take an odd action. A malicious instruction in a tool result can redirect it just as surely as a message from the user can. Check Point’s current documentation therefore recommends screening each step of an agent loop - user input, model output, tool call and tool response - against a configured policy. The control can monitor first, then enforce blocking once the team understands its normal traffic.

This is where the original Lakera product meets its new owner’s reach. Check Point AI Security now sells controls for three recurring scenes: employees using AI tools, developers building AI applications, and autonomous agents calling other systems. Workforce AI Security discovers use and applies data-loss policies. AI Guardrails screens conversations and actions. Red Teaming probes weaknesses, with automated and expert-led options. Check Point also offers AI Cloud Protect for infrastructure and, in 2026, introduced an AI Network Firewall in its R82.20 release. The firewall aims to inspect AI interactions from the network equipment organizations already run. The products have different insertion points; buyers still have to decide which ones cover their own traffic.

The company’s distinction is the path it took to those controls: public adversarial play, a developer-facing runtime layer, then distribution through a large security vendor. Other choices exist. Teams may use a model provider’s safety features, a cloud platform’s guardrails, a specialist AI security product, or controls already in their network stack. Check Point’s case is strongest when an enterprise wants shared governance across many teams and can place inspection at the relevant point in each workflow. A single small app with limited data and no agent permissions may need a much simpler setup.

What the wizard teaches

Lakera’s most transferable lesson is methodological. Put a harmless secret in a test system. Invite people to break the instruction. Observe which attacks work. Then put policy checks where untrusted words can become trusted actions. In production, start by watching what the guardrail flags, measure false positives and latency, and enforce the rules that protect the assets that matter. The company’s own docs distinguish detection mode from enforcement for precisely this reason: a control that surprises a product team is likely to be bypassed.

Gandalf’s secret was fictional. The systems that came after it handle customer data, financial workflows and software tools. That is the peculiar charm of this business story. The silly password game did not make prompt injection disappear. It made the weakness easy to see, and it gave Lakera a way to study how people keep finding it. Check Point paid for a company built around that observation. The wizard, in other words, got a security budget.