Solana CISO: AI-driven scams replace smart contract bugs as top crypto threat
Cryptocurrency security risks are shifting from protocol-level code exploits to AI-powered social engineering and credential theft, demanding new operational defenses across the industry.
Michael Coates, the newly appointed chief information security officer at the Solana Foundation, warned that artificial intelligence is fundamentally altering the blockchain threat landscape. Attackers are increasingly targeting people rather than protocols, relying on AI-generated deepfakes and fake identities to bypass technical safeguards. Coates, who previously served as CISO at Twitter and led security at Mozilla, joined the foundation earlier this year to secure its operations and advise ecosystem projects.
Over the past few months, high-profile crypto security incidents have stemmed not from smart contract vulnerabilities, but from traditional operational failures. "In many cases, it is an operational security issue or a Web2 issue that led to a key compromise," Coates said.
For market participants, this means code audits are no longer a sufficient shield against capital loss. Crypto organizations must now master standard corporate security while managing the unique risks of decentralized networks. "When you have adversaries that are definitely motivated and can take funds irrevocably, they are going to look for any mistake," he said.
The advancement of AI tools is set to accelerate this human-centric attack vector. "The social engineering piece is going to get a lot worse because of the power of AI and deepfakes," Coates warned. "We should expect full spoofed phone calls with voices of people that we know... there's really no reason this won't hyperscale."
Because technical perfection cannot stop human error, Coates argued that crypto platforms must build systemic resilience. "You cannot fully prevent anyone from falling victim," he said. "Eventually, you will be fooled because the cons are that good." The solution requires layered security controls so that when an individual is tricked, secondary systems intervene to prevent the theft.
Beyond immediate AI risks, Coates pointed to the longer-term threat of quantum computing. While the exact timeline for "Q-day" remains unknown, he stressed that the mitigation strategy is already clear. "The way to prepare for this is known. It is adopting the post-quantum algorithms," he said, noting the Solana Foundation is actively evaluating these cryptographic standards.
Ultimately, Coates believes the sector's institutional maturation depends on changing how it approaches user safety. Rather than expecting users to become security experts, blockchain networks must prioritize secure-by-design architecture. "We need to meet the users where they are, and we need to make the default secure decision for the user," he said.