Skip to content
FORKOFF
FORKOFF RADARLaunch teardown no. 14
Andrea Michi

Andrea Michi

@andreamichi · 2.6K followers

depthfirst has raised an $80M Series B at a $580M valuation. Attackers are using AI to break into systems faster than ever before. depthfirst is on a mission to stop this. RT + Comment “depthfirst” and I’ll send you a FREE vibe coding security agent.

The launch post under analysis. Press play to watch it inline.
Reconstructed readingMedium confidenceAs monitored on 2026-06-29Methodology v1

depthfirst launchReconstructed reading

depthfirst is a real product by a real founder (@andreamichi). RADAR has tracked 1.6M views on this launch, according to the source post linked below. RADAR measures how the launch reach was built, not whether the product works or whether anyone was honest. This reading is reconstructed confidence and every input is public.

By Simba, Launch Intelligence Analyst · Reviewed by JK · Published 29 Jun 2026 · Confidence: reconstructed

1.6M
Views
527
Likes
113
Reposts
2,983
Views / like

Independent, methodology-derived signal, not a statement of fact about any person. RADAR reads how reach was built, a signature, not an accusation. See the methodology.

Direct answer, speakable

Did the depthfirst launch go viral organically, or was the reach amplified?

The depthfirst launch by @andreamichi drew 1.6M views on 527 likes, which is 2,983 views per like, well above the roughly 500 organic ceiling. RADAR reads a reconstructed reading in how that reach was built, a signature of the mechanics and not a claim about the product or the founder. This is a reconstructed reading and every input is public and reproducible.

New here? Start with the product

What is RADAR, and what does this grade mean?

RADAR is FORKOFF's launch authenticity rating system. It reads whether a product launch earned its reach through real engagement or bought it through paid distribution, using only public signals anyone can pull from the launch post. Every reading carries a letter grade, a confidence label, and the date it was last checked, and links back to a published method you can reproduce. depthfirst is a real product by a real founder (@andreamichi). RADAR measures how the reach was built, not whether the product works or whether anyone was honest.

Reconstructed reading

Medium confidenceAs monitored on 2026-06-29Methodology v1

Independent, methodology-derived signal, not a statement of fact about any person. RADAR reads how reach was built, a signature, not an accusation. See the methodology.

What this grade means

RADAR reads this launch from its views-to-likes ratio alone, without a full amplification trace, so the grade is labeled reconstructed and held at lower confidence. The read is a signature of how the reach was built, not a claim about the product or the founder.

The signals RADAR reads

Views-to-likes ratio

Organic reach tops out near 500 views per like. When views climb far past that without the likes to match, the extra reach is arriving without the engagement organic reach produces.

Amplification wave shape

Organic amplification spreads over hours and days. A coordinated launch fires a synchronized burst of quote posts in the first few hours, read from each post's own timestamp.

Posting-time fingerprint

A post that fires exactly top of the hour on a weekday is scheduled. On its own it is weak, but it corroborates a coordinated launch alongside the other two signals.

Those three public signals sit on top of RADAR's five-component forensic read. The full method, the bands, and the confidence model are on the RADAR methodology page.

This launch in the data

Where does this reach sit against the tracked corpus?

Where it sits in the corpus

Rank 27 of 30 tracked launches by views per like, lowest (most organic) first. A lower ratio is the favorable end.

2,983
Most organicMost amplified

Against the benchmark

This launch's views per like next to the organic median (354) and the amplified median (1,441) across the tracked set.

This launch2,983
Organic median354
Amplified median1,441
Verdict at a glance

A real founder, a real product, real money, and reach that engagement did not keep pace with.

RADAR's read on the depthfirst launch is distribution-amplified, confidence reconstructed. The 31 March 2026 announcement drew 1,571,817 views on 527 likes, a ratio of about 2,983 views per like. Organic reach on X tends to keep likes coupled to views up to roughly 500 views per like, so this launch sits about six times above that ceiling, inside the paid distribution band. The product, the founder, and the funding are genuine. The finding is about how the reach was built, not whether anyone did anything wrong.

Here is the tension that makes this launch worth reading. Almost every public signal says the company is legitimate: a sitting cofounder and CTO, an $80M Series B and a $40M Series A that independent outlets reported, and named enterprise customers using the product. None of that is in doubt. What RADAR measures is narrower and more specific. When a post collects 1,571,817 views but only 527 likes, 113 reposts, 121 replies, and 59 quotes, the views are arriving from a channel that does not also produce engagement. That is the fingerprint of distribution layered on top of a real post, and it is what the public numbers here show.

One nuance belongs up front, because it cuts the other way and the read accounts for it. The launch carried a giveaway hook, a "repost plus comment depthfirst and I will send you a free vibe-coding security agent" offer. A giveaway is a legitimate organic tactic that is designed to manufacture cheap reposts and one-word replies, which normally pulls the views-per-like ratio down and lifts the reply count. On this launch it did neither at the scale of the reach: the ratio stayed high at 2,983:1 and the reply layer stayed thin at 121. An incentive that should have lowered the ratio left it well above the organic ceiling. That makes the gap between the reach and the engagement more notable, not less.

The rest of this teardown walks the reading first, then steps back to the product, the founder, the funding, and the market, so a reader can audit the read and understand the launch in full. RADAR exists to separate the marketing layer (what a launch claims) from the data layer (what the public signals actually show). Both layers matter. This page documents both.

The read

Engagement coupling: the reach outran every layer under it

RADAR reads a launch distribution-amplified when reach and the costly engagement layers come apart: likes fall far behind views past the 500 views-per-like ceiling, and the labor-intensive actions (replies, quotes) stay thin instead of rising with the reach. The depthfirst launch holds all of that. The load-bearing signal is the views-to-likes gauge, sitting in the paid zone at 2,983:1, with a giveaway incentive present that should have pushed it the other way.

The thing that often hides a buy is the size of the account, and here it points the same direction. Andrea Michi's account carries a small base, around 2,600 followers, against a 1.57M-view launch. That is roughly 604 times the follower count in views. Views-per-follower is the weak signal, the one a small account inflates and a large account masks, so RADAR does not lean on it. But paired with thin coupled engagement, a tiny account producing mega-viral reach is the profile a distribution push produces, not the profile a 2,600-follower account produces on its own audience.

Signal one: the views-to-likes gauge in the paid zone

The load-bearing signal is V:L, views divided by likes. On X, the feed that surfaces a post also makes it easy to like, so under organic distribution reach and likes rise together up to roughly 500 views per like. When views climb but likes do not keep pace, the views are arriving from a channel that does not also produce engagement. The depthfirst launch shows exactly that decoupling: 1,571,817 views divided by 527 likes is 2,982.6 views per like, a like rate near 0.034 percent. That is about six times above the organic ceiling, and a giveaway hook on the same post should have lowered it, not raised it.

05002,0005,00012,000
2,983:1At 2,983 views per like, the needle sits above the 500:1 ceiling that organic engagement coupling holds, and below the 5,000:1 line where like-farms live. The reach was distributed. The engagement did not scale with it.
At 2,983 views per like, this launch sits about six times above the organic ceiling, squarely in the paid band (2,000 to 5,000). Not fraud-tier, not a like-farm. Distribution on a genuine, funded product, with an incentive hook present that the ratio still ran past.

Signal two: the costly layers stayed thin under the reach

Likes are the cheapest action to fake. Replies and quotes are not, because each one is a written post a real person had to compose. The full engagement stack on this post is 527 likes, 113 reposts, 121 replies, and 59 quotes, a total of 820 actions against 1,571,817 views, which is about 0.05 percent coupling. For a post that reached this far, that sits far below the normal engagement band. The pattern matters more because of the hook: a "repost plus comment" giveaway is built to inflate reposts and replies cheaply, so the honest expectation is a heavy reply layer and a depressed ratio. Instead the reply layer is light and the ratio is high. The reach did not bring the costly engagement with it, even when an incentive was on the table to manufacture some.

Views per like

2,983:1

About six times above the 500 organic ceiling. Likes lagged far behind a 1.57M-view reach instead of keeping pace with it.

Reply layer

121

Thin for this reach, and notable because a repost-plus-comment giveaway hook was on the post. The costly written action stayed light when an incentive should have lifted it.

Giveaway hook

Present

A free-agent offer for a repost plus comment is built to manufacture cheap reposts and replies and pull the ratio down. It did neither at the scale of the reach.

Total coupling

0.05%

Likes plus reposts plus replies plus quotes (820 actions) against 1,571,817 views. Far below the normal engagement band for a post that reached this far.

Signal three: a small account, a mega-viral number, thin coupling

The shape of the spread matters as much as its size. A 2,600-follower account does not reach 1.57M views on its own audience through one post, and when it does, organic reach would still carry proportionate likes, replies, and quotes along with it. Here the reach is roughly 604 times the follower base while the coupled engagement stays at 0.05 percent of views. RADAR does not name or characterize any account that may have amplified the post; it reads only the public metrics on the launch post itself. Those metrics show reach that arrived faster than the engagement under it could account for.

Read together, the signals tell one story. The reach is large, the account is small, the costly layers are thin, and an incentive hook that should have closed the gap did not. The distance between the 1.57M-view figure and the 820 coupled actions under it is the distribution. That distinction, how the reach was built, is the entire point of RADAR.

The product, in depth

What depthfirst actually is

depthfirst is an AI-native application and code security platform, which the company describes as an "applied AI lab." Its models reason across a company's codebase, business logic, and infrastructure to find real vulnerabilities, cut false positives, and deliver precise fixes inside developer workflows. The company has also shipped its first in-house security model, dfs-mini1, initially focused on securing cryptocurrency smart contracts. This is a real, funded product, not a concept.

Andrea Michi announced the Series B from a personal account on 31 March 2026, and the post carried both the funding news and a giveaway: a free vibe-coding security agent in exchange for a repost and a comment (x.com/andreamichi). The official BusinessWire release and the company blog frame depthfirst as an applied AI lab building security tooling that works inside the software delivery pipeline rather than as a scanner bolted on after the fact (businesswire.com, depthfirst.com).

Who it is for, and what it covers

depthfirst targets engineering and security teams shipping software at speed, where AI-assisted coding has raised both the volume of code and the rate at which vulnerabilities reach production. The pitch is precision: models that understand a codebase well enough to separate real exploitable issues from the noise that floods traditional scanners, and that propose fixes a developer can accept inline. The named customers and partners cited at announcement include ClickUp, Lovable, Supabase, incident.io, and Moveworks (techcrunch.com, securityweek.com). The dfs-mini1 model is the company's first in-house model release, scoped at launch to smart-contract security, which is a narrower beachhead than the broader AppSec positioning.

That the product is real and adopted is part of why the announcement drew genuine attention. It is also why the reach reads as amplified rather than fabricated: there is a real launch underneath the distribution, not an empty one.

The founder

Andrea Michi, cofounder and CTO of depthfirst

Andrea Michi is a cofounder and the CTO of depthfirst. His public profile states he previously worked on reinforcement-learning post-training for Gemini at Google DeepMind (x.com/andreamichi). He is the launch account for this announcement. Two points belong up front for accuracy: Michi is the CTO, not the CEO, and his account is small, around 2,600 followers, which is the base against which the 1.57M-view reach should be read.

depthfirst's CEO and cofounder is Qasim Mithani, previously at Databricks and Amazon, and the third cofounder is Daniele Perito, Executive Chairman, previously a Faire cofounder and part of the Cash App founding team at Block, formerly Square (techcrunch.com). This is a credentialed founding team with relevant security and infrastructure backgrounds, which is consistent with the company raising institutional capital twice inside a single quarter. RADAR states the team as real and verifiable; the reading above is about the reach on one post, not about the people or their track records.

The launch tweet making the $580M valuation claim came from Michi's own account. RADAR treats that figure separately from the round itself, for a reason set out in the funding section below.

Backers and funding

What is behind depthfirst, and how the round is reported

The funding is public and confirmed. depthfirst announced an $80M Series B on 31 March 2026, led by Meritech Capital, with participation from Forerunner Ventures, The House Fund, and existing investors Accel, Box Group, Liquid 2 Ventures, Alt Capital, and Mantis VC. The round came less than 90 days after the company emerged from stealth with a $40M Series A (announced 14 January 2026, led by Accel, with SV Angel, Mantis VC, and Alt Capital), bringing total capital raised to $120M (businesswire.com, techcrunch.com, securityweek.com).
One number does not have the same backing as the rest. The founder's launch tweet states the Series B was done at a $580M valuation. The BusinessWire press release and SecurityWeek report the round amount but state the valuation was not disclosed. So the $580M figure is sourced only to @andreamichi's own tweet, not to any independent outlet, and RADAR flags it as a founder-stated figure rather than a confirmed one.
Structural factReading
Series B$80M led by Meritech Capital, 31 March 2026
Series A$40M led by Accel, 14 January 2026
Total raised$120M across two rounds in one quarter
Series B valuation$580M, founder-stated only, not in BusinessWire or SecurityWeek
Named customersClickUp, Lovable, Supabase, incident.io, Moveworks

The funding is the part of this launch that is most solidly corroborated, by BusinessWire, TechCrunch, and SecurityWeek among others. That a real, twice-funded company announced a real round is exactly why RADAR is careful to separate the two layers here. The money is confirmed. The reach on the announcement post is the thing RADAR reads as distribution-amplified, and the two findings do not contradict each other.

Market and context

Where this launch sits, and how modern launches are built

depthfirst launched into AI-native cybersecurity, specifically AI-driven application and code security and software supply-chain security. The category thesis is that AI lets attackers find and exploit software faster than it can be secured, which raises demand for tooling that can keep pace on the defensive side. The launch announcement names no direct competitors. For context only, established players in this AI and code-security space include Snyk and Semgrep, named here as category peers, not as companies cited by depthfirst.

Why the category drew real attention

AI security is one of the more active funding lanes in 2026, and a team that raised $40M and then $80M inside one quarter is a genuine signal in it. A real, well-capitalized entrant in a hot category draws unpaid attention from founders, engineers, and investors on its own. The demand substrate for real interest exists, which is what makes a distribution layer on top of it possible to read cleanly: the engagement that organic interest would produce is measurable, and on this post it is thin relative to the reach.

How modern launches are amplified

A coordinated launch in 2026 is a planned distribution event, not one spontaneous tweet. The documented pattern runs on a small set of repeatable levers: a pre-built or recruited set of accounts, a giveaway or incentive that manufactures cheap early engagement, and a synchronized push that exposes the post to audiences beyond the founder's own. A giveaway hook, like the free-agent offer on this post, is one of those levers. None of this is an accusation. It is the neutral mechanics that explain how a 2,600-follower account reaches 1.57M views while the coupled engagement stays at 0.05 percent, and it is the profile this launch displays.

Comparable RADAR launches

RADAR has profiled a library of launches. Compare the depthfirst reading against these peers:

How RADAR read it

Methodology, and what we are not saying

RADAR does not output a pass or fail on a person. It outputs a signature and a confidence label, both built from public metrics anyone can pull, so the reader can check the work. For depthfirst, the distribution-amplified signature rests on the decoupling between reach and engagement:

  • The views-per-like ratio (2,983:1) sat about six times above the 500:1 organic ceiling, inside the paid band.
  • The costly engagement layers stayed thin: 121 replies and 59 quotes, alongside 527 likes and 113 reposts, a total of 820 actions on 1,571,817 views, about 0.05 percent coupling.
  • A "repost plus comment" giveaway hook was present on the post. That incentive should have lowered the ratio and lifted the reply count. Neither happened at the scale of the reach, which strengthens rather than weakens the read.
  • A roughly 2,600-follower account reached about 604 times its follower count in views, with engagement that did not scale with that reach.
What RADAR is and is not saying. RADAR is not saying that depthfirst is fake, that the product does not work, that the $80M Series B or the $40M Series A is not real, or that Andrea Michi did anything against the rules. Paying for or engineering distribution is legal and common. RADAR is also not making any claim about depthfirst's investors or any third party. Meritech Capital, Forerunner Ventures, The House Fund, Accel, Box Group, Liquid 2 Ventures, Alt Capital, Mantis VC, and SV Angel funded a real company on confirmed terms, and nothing here implies any of them backed bought reach or did anything wrong. The named customers and partners cited at announcement, ClickUp, Lovable, Supabase, incident.io, and Moveworks, are likewise outside this finding; nothing here implies any of them endorsed or amplified the post. RADAR does not name or characterize any account that may have amplified the launch; it reads only the public metrics on the launch post itself. The finding is narrow and specific: the 1.57M-view figure reflects distributed reach that the engagement under it did not keep pace with, not organic word of mouth.

Confidence and how to reproduce it

Confidence is labeled reconstructed: built from the live metric snapshot and the engagement-ratio reading, not a full forensic trace of every account that carried the post. There is no quote-tweet wave rendered here, because this read does not rest on a per-account timeline; it rests on the ratio band and the coupling. Every input is public. Pull the launch post's view, like, repost, reply, and quote counts; divide views by likes for the gauge; and check whether the costly layers (replies, quotes) are present and proportionate to the reach, accounting for the giveaway hook that should have lifted them. The decoupling falls out of the data. See the full method at the RADAR methodology.

Frequently asked

Questions readers ask about this launch

Is depthfirst real?

+
Yes. depthfirst is a real, funded AI-native application and code security platform, described by the company as an applied AI lab. Its models reason across a codebase, business logic, and infrastructure to find vulnerabilities and deliver fixes inside developer workflows, and it has shipped a first in-house model, dfs-mini1, focused at launch on securing cryptocurrency smart contracts. It announced an $80M Series B led by Meritech Capital on 31 March 2026, less than 90 days after a $40M Series A led by Accel, for $120M total. The funding is confirmed by BusinessWire, TechCrunch, and SecurityWeek.

Who is Andrea Michi?

+
Andrea Michi is a cofounder and the CTO of depthfirst, and the account that posted this launch. His public profile states he previously worked on reinforcement-learning post-training for Gemini at Google DeepMind. He is the CTO, not the CEO; depthfirst's CEO and cofounder is Qasim Mithani (previously Databricks and Amazon), and the third cofounder is Daniele Perito (Executive Chairman, previously a Faire cofounder and Cash App founding team member at Block, formerly Square). Michi's account carries roughly 2,600 followers, which is the base the 1.57M-view reach should be read against.

What is a normal views-to-likes ratio on X?

+
Organic reach on X tends to keep likes coupled to views up to roughly 500 views per like, because the same feed that surfaces a post also makes it easy to like, so reach and engagement rise together. A ratio between 2,000 and 5,000 views per like sits in the paid distribution band. Above roughly 5,000 views per like is the fraud-tier signature associated with like-farms. The depthfirst launch measured about 2,983 views per like, around six times above the organic ceiling.

How do you know the reach was distributed and not organic?

+
RADAR reads the coupling between reach and the costly engagement layers. The depthfirst launch shows 1,571,817 views on only 527 likes (a 2,983:1 ratio, about six times above the 500 ceiling), with 121 replies and 59 quotes and 113 reposts, a total of 820 actions, about 0.05 percent of views. The post also carried a repost-plus-comment giveaway hook that should have manufactured cheap reposts and replies and pulled the ratio down; it did neither at the scale of the reach. This is a reconstructed read, meaning ratio and coupling based, without a full forensic trace of every account that carried the post.

Does this mean depthfirst did something wrong?

+
No. Engineering distribution, including running a giveaway, is legal and common, and RADAR reads how the reach was built, not whether anyone was dishonest. The product, the founder, the named customers, and the $80M Series B and $40M Series A funding are all real and independently reported. One figure, the $580M Series B valuation, is sourced only to the founder's own tweet and was not disclosed by BusinessWire or SecurityWeek, so RADAR flags it as founder-stated. The distribution-amplified signature is about the 1.57M-view reach on one post, nothing more.
About this analysis

Sources

Primary citation: x.com/andreamichi/status/2039010131443437850. Every number traces to a public pull; reads re-checked over time.

  1. x.com/andreamichi/status/2039010131443437850 (launch post, 31 March 2026, 1.57M views)
  2. x.com/andreamichi (verified founder account, CTO depthfirst, ex-DeepMind)
  3. businesswire.com depthfirst $80M Series B release
  4. depthfirst.com Series B announcement
  5. techcrunch.com depthfirst $40M Series A
  6. securityweek.com depthfirst $80M Series B
  7. finsmes.com depthfirst $80M Series B
  8. fintech.global depthfirst $80M Series B
  9. theaiinsider.tech depthfirst $80M Series B
  10. thesaasnews.com depthfirst $80M Series B
  11. justainews.com depthfirst $80M raise
  12. cybertechnologyinsights.com depthfirst $80M raise
  13. raising.fi depthfirst Series B
  14. regtechanalyst.com depthfirst $80M Series B
The five components

How RADAR read this launch, component by component

Each named component carries a plain-English definition and a directional read where the public data supports one. RADAR publishes the component names, never the weights or the formula.

View-velocity signature

Not published

Whether the view curve grew the way organic spread does, or spiked like an injected burst.

Per-launch read not published in the public dataset. This component needs the forensic engine output.

Engagement coupling

Flags amplification

Whether likes, replies, and reposts grew in step with views (the organic signature), or the views ran out ahead.

At 2,983 views per like, reach runs well ahead of the likes, far above the roughly 500 organic ceiling.

Reply-network authenticity

Not published

Whether the accounts replying are real, distributed people or a coordinated cluster posting together.

Per-launch read not published in the public dataset. This component needs the forensic engine output.

Amplifier-cluster pattern

Not published

Whether the quote-tweet amplification looks like organic word of mouth or a known activation cluster.

Per-launch read not published in the public dataset. This component needs the forensic engine output.

Smart-follower activation

Not published

Whether genuinely influential reference accounts engaged, or the reach was only low-quality volume.

Per-launch read not published in the public dataset. This component needs the forensic engine output.

Are you the founder of depthfirst? You can claim or contest this read. RADAR attaches a founder response to the launch and re-examines any component you dispute.

Claim or contest this read

Authorship

Simba

Co-founder, FORKOFF

Reviewed by: Kshitij JK

Last reviewed:

Published:

Methodology

RADAR reconstructed reading of the depthfirst launch from public metrics: the views-to-likes ratio against the roughly 500 organic ceiling and the posting-time slot, framed as a signature of how reach was built, not an accusation.

Sources cited

Where to go next

Understand launch authenticity

Three ways in, depending on what brought you here: learn how the score works, get a launch read or built, or get the plain answer on this launch.

Learn the score

What a launch authenticity score is

A launch authenticity score reads whether a launch earned its reach or bought it, from public signals. Start with the definitions and the checks you can run yourself.

Verify or build

Launch authenticity verification

Want a launch read by the same method, or a launch video made and distributed on the outcome? RADAR reads any public launch, and FORKOFF builds the launch behind the reach.

The skeptic's question

Is the depthfirst launch legit?

If you are checking whether the depthfirstlaunch was real users or bots, here is the honest read: RADAR's reading is Reconstructed reading, at reconstructed confidence, computed from public metrics and reproducible from the source post. It measures how the reach was built, not whether the product works.

RADAR · launch intelligence

Want a launch read by RADAR's method?

RADAR reads whether a launch's reach was earned or bought from public data, with the confidence label and the source citation on every reading.