Solana Foundation CISO Warns AI Is Making Crypto Scams More Convincing
Key Takeaways
- •Michael Coates, previously CISO at Twitter and a security leader at Mozilla, joined the Solana Foundation earlier this year as its new chief information security officer.
- •Coates reports that most recent cryptocurrency hacks result from social engineering and compromised credentials rather than smart contract vulnerabilities.
- •AI tools are enabling attackers to create realistic messages, synthetic voices, and convincing false identities at scale, which Coates expects will make social engineering scams significantly worse.
- •Coates advocates for layered defense-in-depth security frameworks and argues that crypto systems should make secure decisions the default option so users do not need specialized expertise to stay safe.
- •The Solana Foundation has identified quantum computing as a future risk and has already published its own post-quantum readiness strategy following NIST's finalized standards in 2024.

Michael Coates, the newly appointed chief information security officer at the Solana Foundation, is warning that artificial intelligence is making cryptocurrency scams significantly harder to detect. The threat, he emphasizes, stems from social engineering rather than vulnerabilities in blockchain code. His arrival at a major blockchain foundation reflects a broader pattern of crypto organizations recruiting seasoned security leaders from traditional technology companies as the industry seeks to professionalize its defenses amid growing institutional adoption.
Coates previously served as CISO at Twitter and led security efforts at Mozilla during the browser wars. He joined the Solana Foundation earlier this year. His responsibilities extend beyond protecting the foundation itself — he also collaborates with projects across the Solana ecosystem and engages with regulators on cybersecurity standards.
AI Is Changing How Scams Work
In an interview with CoinDesk, Coates noted that many recent crypto hacks did not originate from smart contract bugs. Instead, they resulted from compromised credentials and fabricated identities. This pattern is consistent with industry-wide reporting: blockchain analytics firms have repeatedly identified phishing and social engineering as leading causes of funds lost across the cryptocurrency sector.
"In many cases, it is an operational security issue or a Web2 issue that led to a key compromise," he said.
He expects this trend to worsen as AI tools become more sophisticated. Attackers can now produce realistic messages, synthetic voices, and convincing false identities at scale.
"The social engineering piece is going to get a lot worse because of the power of AI and deepfakes," Coates said. He warned that fully spoofed phone calls replicating the voices of people known to potential victims could become commonplace.
In the cryptocurrency space, mistakes are often irreversible. If someone signs a malicious transaction or discloses a seed phrase, there is no bank to contact and no mechanism to reverse the transfer. This makes convincing scams especially costly. Coates said attackers will continue probing for any user error because stolen funds typically cannot be recovered.
Building Systems That Expect Failure
Coates does not believe scams can be eliminated entirely. Even vigilant users, he said, will eventually succumb to a well-crafted deception.
"You cannot fully prevent anyone from falling victim," he said. "Eventually, you will be fooled because the cons are that good."
For this reason, he argues that organizations need layered security frameworks — a defense-in-depth approach long standard in traditional cybersecurity but still maturing in many crypto applications. If one defensive layer fails, another should still safeguard the user or their funds. This principle applies equally to individuals and to crypto project teams. A fabricated vendor, investor, or colleague using AI-generated audio or messages could deceive an employee into approving a fraudulent transaction or surrendering system access.
Coates said the industry's long-term success depends on making security the default option. Users should not be required to possess specialized expertise to protect themselves.
"We need to meet the users where they are, and we need to make the default secure decision for the user," he said.
Quantum Computing on the Horizon
Coates also identified quantum computing as a future risk for cryptocurrency networks, including Solana. The exact timeline for when quantum computers could break current encryption standards remains uncertain, though the U.S. National Institute of Standards and Technology released its first finalized post-quantum encryption standards in 2024, giving the broader technology industry a reference framework for migration.
"The challenge with quantum readiness is we don't know when the Q-day will hit," Coates said. He noted that the solution is already understood: adopting post-quantum algorithms proactively.
The Solana Foundation has already published its own strategy for quantum readiness. Coates said that whether the threat is AI-driven scams or quantum computing, the same core principle applies — systems should protect users automatically rather than demanding flawless behavior at all times.