@stake
@stake was a United States information-security professional-services company known for security consulting, penetration testing, vulnerability research, and security tools before its acquisition by Symantec.
Last updated August 31, 2026
Overview
@stake, formally Atstake, Inc. and styled as @stake, was a United States computer-security professional-services company headquartered in Cambridge, Massachusetts. Founded in 1999, it operated during a formative period in the commercial security industry, when organizations were increasingly commissioning independent assessments of networks, applications, operating systems, and enterprise infrastructure. Its principal business was consulting rather than mass-market software: consultants performed security assessments, penetration tests, application reviews, training, and related advisory work for corporate and institutional clients. The company was established by Battery Ventures, represented by Tom Crotty, Sunil Dhaliwal, and Scott Tobin, together with Ted Julian. Its early technical and executive group combined venture-backed business leadership with researchers drawn from the security community. Dan Geer served as chief technology officer, while Christopher Darby was chief executive officer, James T. Mobley chief operating officer, and Christina Luconi chief people officer. The firm also recruited or employed a number of prominent practitioners associated with vulnerability research, hacker culture, digital forensics, application security, and security engineering. This mixture of consulting expertise and research visibility helped distinguish @stake from conventional information-technology consultancies. A major early turning point came in January 2000, when @stake acquired L0pht Heavy Industries, a Boston-area security research collective known for its hacker researchers and tools. The transaction brought L0pht figures and technology into the company and made Mudge, a prominent L0pht member, vice president of research and development. The acquisition strengthened @stake's research identity and connected its commercial services to tools such as L0phtCrack, a password-auditing and recovery product. @stake expanded internationally in July 2000 by acquiring Cerberus Information Security Limited of London. Cerberus became a platform for serving Europe, the Middle East, and Africa. Alongside its advisory work, @stake operated the @stake Academy for information-security training and developed or commercialized several tools, including successive versions of LC, the later L0phtCrack product line; WebProxy for web-application testing; SmartRisk Analyzer for application-security analysis; and The @stake Sleuth Kit, an open-source digital-forensics toolkit later known as The Sleuth Kit. The company attracted attention beyond its products and client work because of the broader debate over the place of people with hacker backgrounds in professional security. In 2000, a recruiting episode involving Mark Abene, also known as Phiber Optik, prompted discussion after the company declined to hire him because of a prior felony conviction and its policy concerning convicted hackers. The episode illustrated the tension between the security industry's interest in unconventional technical talent and employers' background-screening practices. Symantec announced its acquisition of @stake on September 16, 2004, and completed the transaction on October 9, 2004. The deal brought @stake's consulting capabilities, personnel, contracts, and technologies into Symantec's enterprise security services activities. The independent @stake brand subsequently disappeared as a standalone operating company, although the remaining consulting organization continued within Symantec's Security Advisory Services team and retained some existing service relationships. Several former employees later founded or joined other security firms, including iSEC Partners. Symantec eventually discontinued new sales and support for LC5, citing United States government export regulations and ending support in December 2006; the original L0phtCrack authors reacquired that product line in 2009. @stake is therefore best understood as a defunct but influential security-consulting b…
History
@stake was founded in the United States in 1999 as a research-oriented information-security professional-services company. Its founders included Battery Ventures and its representatives Tom Crotty, Sunil Dhaliwal, and Scott Tobin, together with Ted Julian. The initial organization combined venture-backed management with security specialists from the Cambridge Technology Partners security team. Dan Geer became chief technology officer, while Christopher Darby, James T. Mobley, and Christina Luconi held senior executive roles. The company focused primarily on consulting and testing for enterprise customers. Its services included information-security assessments, penetration testing, application-security reviews, vulnerability analysis, and professional training through the @stake Academy. Rather than relying solely on packaged software, @stake used the expertise of security researchers and practitioners to assess real-world systems and advise clients on reducing risk. In January 2000, @stake acquired L0pht Heavy Industries, a security-research collective known for its hacker personnel and technical tools. The acquisition added important research capabilities and brought Mudge into the company as vice president of research and development. In July of the same year, @stake acquired Cerberus Information Security Limited in London, establishing a base for work across Europe, the Middle East, and Africa. @stake also developed or offered several security tools. LC3, LC4, and LC5 were successive versions of a password-auditing and recovery product associated with L0phtCrack. WebProxy supported web-application security testing, while SmartRisk Analyzer addressed application-security analysis. The @stake Sleuth Kit, or TASK, was an open-source digital-forensics project that later became known as The Sleuth Kit. The company's staff included many recognized security researchers, strengthening its reputation as a bridge between independent security research and commercial consulting. The company received additional attention in 2000 after a recruiter contacted Mark Abene about a security-consulting position but the company later declined to hire him because of his criminal conviction and its policy regarding convicted hackers. The episode contributed to public discussion about whether professional security companies should employ people with hacking histories. Symantec announced its acquisition of @stake on September 16, 2004, and completed it on October 9. The consulting operation and associated capabilities were integrated into Symantec's enterprise security-services organization. Some former employees later established or joined other security companies, while the remaining consulting group continued as part of Symantec's Security Advisory Services team. Symantec later stopped selling LC5 to new customers in connection with export regulations and ended support in December 2006. In 2009, the original L0phtCrack authors reacquired that product line. @stake consequently ceased to exist as an independent brand, but its personnel, methods, and technologies continued to influence the security industry.
- 2009L0phtCrack returns to its original authors
The original authors reacquire L0phtCrack from Symantec and announce L0phtCrack 6.
- 2006LC5 support discontinued
Symantec ends support for LC5 after halting new sales in connection with United States government export regulations.
- 2004Symantec acquisition announced
Symantec announces its agreement to acquire @stake on September 16.
- 2004Symantec acquisition completed
Symantec completes the transaction on October 9, ending @stake's independent corporate operation.
- 2000L0pht Heavy Industries acquisition
@stake acquires L0pht Heavy Industries, adding security researchers, technical expertise, and the foundation of the L0phtCrack product line.
- 2000Cerberus Information Security acquisition
The acquisition of the London-based firm supports @stake's expansion into Europe, the Middle East, and Africa.
- 1999@stake is founded
Battery Ventures, its representatives, and Ted Julian establish @stake as a computer-security professional-services company in Cambridge, Massachusetts.
Products and positioning
Research-led enterprise information-security consulting, testing, training, and security tooling
Security assessment and penetration testingsecurity consulting1999
Core professional services for examining enterprise networks, systems, applications, and configurations. Consultants used assessment and simulated-attack techniques to identify weaknesses and help clients improve their security controls. These services, rather than a consumer software subscription, formed the center of @stake's business.
L0phtCrack / LC3, LC4, and LC5password auditing and recovery
A password-auditing and recovery tool originating from L0pht Heavy Industries and offered in successive LC versions. It was used to evaluate password strength and recover or audit credentials in authorized environments. After Symantec acquired @stake, LC5 remained associated with the acquired technology until sales and support were later discontinued; the original authors reacquired the product line in 2009.
WebProxyweb-application security
A security-testing tool for examining web applications. It complemented @stake's application-security consulting by helping practitioners inspect and test application behavior for weaknesses.
SmartRisk Analyzerapplication-security analysis
An application-security analysis product developed by @stake. Its underlying technology was later extended and ultimately brought to market through Veracode, a Symantec spinoff.
The @stake Sleuth Kitdigital forensics
An open-source digital-forensics toolkit created by @stake. The project later became known as The Sleuth Kit and continued beyond the life of the @stake brand.
@stake Academysecurity training
A training program offering information-security education for practitioners and organizational customers. It extended @stake's role beyond testing engagements into workforce development and security skills training.
Flagship businesses
- Enterprise security assessments
- L0phtCrack / LC password-auditing tools
- WebProxy
- SmartRisk Analyzer
- The @stake Sleuth Kit
Brand decisions
- 2006Discontinue LC5 supportOther
After acquiring the L0phtCrack-related technology, Symantec faced United States government export-regulation considerations affecting the product.
What changed. Symantec stopped selling LC5 to new customers and discontinued support in December 2006.
Aftermath. The product line later returned to its original authors, who announced L0phtCrack 6 in 2009.
- 2004Sell the company to SymantecM&A
Symantec sought to broaden its enterprise security consulting and professional-services capabilities. @stake offered an established consulting team, research reputation, technologies, and customer relationships.
What changed. Symantec announced the acquisition on September 16, 2004, and completed the transaction on October 9.
Aftermath. @stake's capabilities were integrated into Symantec's security-services organization. The independent brand ceased operating as a standalone company, while portions of its consulting work continued within Symantec.
- 2000Acquire L0pht Heavy IndustriesM&A
The young consulting company sought to deepen its technical and research capabilities by incorporating a prominent security-research collective.
What changed. @stake acquired L0pht Heavy Industries and appointed Mudge as vice president of research and development.
Aftermath. The deal strengthened @stake's research-led identity and connected the company to L0phtCrack and other security technologies.
- 2000Acquire Cerberus Information SecurityM&A
To build an international presence, @stake needed a base from which to serve clients in European, Middle Eastern, and African markets.
What changed. @stake acquired Cerberus Information Security Limited in London.
Aftermath. Cerberus served as @stake's launchpad for expansion across Europe, the Middle East, and Africa.
Leadership
| Name | Title | Tenure |
|---|---|---|
| Mudge | Vice President of Research and Developmentformer | 2000–2004 |
| Christina Luconi | Chief People Officerformer | –2004 |
| Christopher Darby | Chief Executive Officerformer | –2004 |
| Dan Geer | Chief Technology Officerformer | –2004 |
| James T. Mobley | Chief Operating Officerformer | –2004 |
Recent events
- 2009Original authors reacquire L0phtCrack
The original authors acquired L0phtCrack from Symantec, and L0phtCrack 6 was announced at the SOURCE Boston Conference.
M&AProduct generation - 2006Symantec ends support for LC5
Symantec discontinued support for LC5 in December 2006 after stopping new sales in connection with United States government export regulations.
RegulationProduct generation - 2004Symantec announces acquisition of @stake
Symantec announced that it would acquire @stake to expand its enterprise security consulting and professional-services capabilities.
M&A - 2004Symantec completes acquisition of @stake
The transaction was completed on October 9, after which @stake's consulting capabilities were integrated into Symantec's security-services organization.
M&ALeadership change - 2000@stake acquires L0pht Heavy Industries
The acquisition brought the L0pht security-research team and related expertise into @stake, including Mudge as vice president of research and development.
M&A - 2000@stake acquires Cerberus Information Security
The London-based acquisition provided @stake with a base for expansion into Europe, the Middle East, and Africa.
M&A - 2000Recruiting dispute involving Mark Abene prompts debate over hiring convicted hackers
A recruiting approach to Mark Abene followed by a refusal to hire him because of his prior felony conviction drew attention to background-check policies and the role of former hackers in the security profession.
Other
Sources
Cite this profile: Cite the canonical profile. /brand-wiki/stake · Editorial policy · How profiles are compiled