NewsCryptoSolana Foundation's New CISO Warns AI Is Making Crypto Scams More Convincing

Solana Foundation's New CISO Warns AI Is Making Crypto Scams More Convincing

Author: Coindesk·

Key Takeaways

  • Michael Coates, CISO at the Solana Foundation, identifies AI-powered social engineering and compromised credentials as the foremost emerging security threats to cryptocurrency, surpassing smart contract exploits.
  • Many major crypto security incidents originate from operational security weaknesses or Web2 vulnerabilities that lead to key compromises rather than flaws within blockchain protocols themselves.
  • The growing accessibility of AI-driven deepfake and voice cloning tools is lowering the cost and technical barrier for attackers to conduct convincing impersonation campaigns at scale.
  • The Solana Foundation has published a quantum readiness strategy that aligns with NIST's first finalized post-quantum cryptography standards released in 2024.
  • Coates emphasizes that organizations must implement layered security controls and make secure choices the default for users, acknowledging that individuals will inevitably be deceived by sophisticated scams.
Solana Foundation's New CISO Warns AI Is Making Crypto Scams More Convincing

AI vulnerabilities and fake identities will drive the next wave of blockchain security concerns, says Michael Coates.

The most significant security threats facing the cryptocurrency industry increasingly stem from AI-powered social engineering and compromised credentials rather than smart contract exploits, as attackers redirect their focus toward people instead of protocols, according to Solana Foundation Chief Information Security Officer Michael Coates.

Speaking to CoinDesk, Coates said that several major security incidents across crypto ecosystems in recent months were not triggered by smart contract vulnerabilities but by more sophisticated attack vectors, including fabricated identities and AI-generated scams. The trend mirrors broader shifts across the cybersecurity landscape: industry tracking has consistently shown that phishing, credential theft, and social engineering rank among the most costly attack categories, and blockchain's irreversible transactions mean that successful deception can result in immediate, unrecoverable losses.

"You have to do everything that a Web2 company has to do for security, and the incremental uniqueness to Web3," Coates said. "When you have adversaries that are definitely motivated and can take funds irrevocably, they are going to look for any mistake."

Coates joined the Solana Foundation earlier this year after previously serving as CISO at Twitter and leading security at Mozilla during the browser wars. His current responsibilities extend beyond securing the foundation itself — he also collaborates with Solana ecosystem projects to strengthen their security practices and engages with regulators to establish appropriate cybersecurity standards.

While crypto exploits frequently make headlines due to the scale of funds stolen, Coates stressed that many of these incidents originate outside of blockchain itself. "In many cases, it is an operational security issue or a Web2 issue that led to a key compromise," he said.

The rapid advancement of artificial intelligence is providing attackers with increasingly powerful tools to circumvent security measures. "The social engineering piece is going to get a lot worse because of the power of AI and deepfakes," Coates warned. "We should expect full spoofed phone calls with voices of people that we know... there's really no reason this won't hyperscale." AI-driven voice cloning and deepfake video tools have become widely accessible, lowering the cost and technical barrier for conducting convincing impersonation attacks at scale.

To counter this trend, Coates believes the crypto industry must develop security systems that remain effective even when individuals are deceived. "You cannot fully prevent anyone from falling victim," he said. "Eventually, you will be fooled because the cons are that good." Organizations should therefore implement multiple layers of security controls so that "when someone gets fooled, the other things take over to protect you."

On the longer-term horizon, the prospect of quantum computing looms over the future of various crypto ecosystems, including Solana. "The challenge with quantum readiness is we don't know when the Q-day will hit," Coates said. "The way to prepare for this is known. It is adopting the post-quantum algorithms." As part of this effort, the Solana Foundation has released its own quantum readiness strategy. The push aligns with broader industry momentum following NIST's publication of its first finalized post-quantum cryptography standards in 2024, which gave organizations a reference framework for migrating away from cryptosystems vulnerable to quantum attacks.

Whether the threat originates from AI-driven scams or quantum computing, Coates said the industry's success will depend on building systems that protect users by default rather than expecting them to become security experts.

"We need to meet the users where they are, and we need to make the default secure decision for the user," he said.

Read more: Solana's quantum-threat readiness reveals harsh tradeoff: security vs speed