LockurBlock Digital News & Media Platform

collapse
Home / Daily News Analysis / Solana Foundation's new CISO warns AI is making crypto scams more convincing

Solana Foundation's new CISO warns AI is making crypto scams more convincing

Aug 08, 2026  Twila Rosenbaum 6 views
Solana Foundation's new CISO warns AI is making crypto scams more convincing

When Michael Coates stepped into the role of chief information security officer at the Solana Foundation, he brought with him a stark warning: the next major wave of crypto security threats will not come from clever code exploits but from AI-powered scams that deceive humans. In a recent interview, Coates said that AI vulnerabilities and fake identities are poised to drive blockchain security concerns in the coming years, marking a fundamental shift in how the industry must think about protection.

Coates, who officially joined the Solana Foundation in recent months, is a veteran of the cybersecurity industry. His career has been defined by a focus on protecting organizations from evolving digital threats, with leadership positions at several major technology companies. His appointment signals that Solana is recognizing the importance of robust security leadership as the ecosystem grows and faces new challenges. The foundation, which supports the development of the Solana blockchain, has long been a target for malicious actors, and Coates's expertise is expected to strengthen the network's overall security posture.

Attackers Shift From Code to People

The traditional image of a crypto hack involves a hacker finding a bug in a smart contract and draining millions from a protocol. While those exploits still happen, Coates argues that the most dangerous threats today are far more human-centric. "The attacker is not going after the protocol; they're going after the person," he said, noting that credentials and fake identities are becoming the primary attack surface. This observation aligns with a broader trend in cybersecurity, where attackers have realized that people are often the weakest link in any security system. Even the most technically secure blockchain can be compromised if a user unwittingly hands over their private keys or signs a malicious transaction.

The shift from exploiting code to exploiting human psychology is not entirely new, but AI has dramatically accelerated it. In the past, phishing campaigns were often generic and easy to spot, but now they can be highly personalized and incredibly convincing. Coates pointed out that the rise of generative AI has given criminals the tools to create realistic fake identities, fake websites, and even deepfake videos and audio that can fool even vigilant users. This makes crypto scams more convincing than ever before, and it requires a new approach to security.

AI-Powered Social Engineering

AI has dramatically increased the sophistication of social engineering. Phishing emails that once contained obvious typos are now polished and personalized, often referencing recent transactions or specific wallet activity. Attackers can scrape social media and public blockchain records to build detailed profiles of their targets, then craft messages that appear to come from trusted friends, family members, or well-known industry figures. Coates emphasized that this is not just a theoretical risk; it is already happening in the wild.

One particularly worrying development is the use of AI to generate deepfakes. In the crypto world, deepfakes have been used to impersonate executives on video calls, to create fake endorsements from celebrities, and to fabricate entire news broadcasts about fictitious partnerships or giveaways. These convincing forgeries are difficult to distinguish from reality, and they have already led to significant financial losses. Coates noted that as AI technology continues to improve, the barrier to creating these scams will fall, allowing even low-skilled criminals to launch highly sophisticated attacks.

The Solana Foundation has already taken steps to educate its community about these risks, but Coates believes that education alone is not enough. He argues that the industry must build systems that are resilient to social engineering by default. This means implementing stronger identity verification, multi-factor authentication, and transaction monitoring that can flag suspicious activity before it results in a loss. The goal is to make security features so seamless that users are protected even when they make mistakes.

The Danger of Fake Identities

Coates specifically called out fake identities as a growing concern. With AI-generated video and audio, a scammer can impersonate a company executive or a trusted community member in real time. There have already been cases where attackers used deepfake technology to impersonate crypto exchange officials during video calls, convincing victims to transfer funds or reveal sensitive information. The human voice and face are no longer reliable proof of identity, which creates enormous challenges for a trustless ecosystem built on cryptographic verification.

Fake identities are not just used in direct scams; they are also deployed to create fake news sites, fake customer support channels, and fake social media accounts that spread misinformation. In the crypto space, where news can move markets, a single well-crafted fake announcement can cause panic or euphoria. Coates warned that the Solana ecosystem is not immune to these tactics and that the foundation is working on ways to help users verify the authenticity of accounts and communications. This includes collaboration with wallet providers, exchanges, and social media platforms to establish trusted channels.

Compromised Credentials

Beyond fake identities, compromised credentials are a major vector. Many crypto users reuse passwords across multiple sites, making them vulnerable to credential stuffing attacks. Once a hacker obtains a password from a data breach, they can try it on exchanges, wallets, and other services. Two-factor authentication helps, but even that can be bypassed through phishing attacks that trick users into sharing one-time codes. Coates stressed that the industry needs to move away from passwords entirely, adopting hardware wallets, passkeys, and other more secure authentication methods.

The problem of compromised credentials is exacerbated by the growing number of third-party services in the crypto ecosystem. From portfolio trackers to tax software, users often grant these services access to their exchange accounts and wallets. If one of those third-party services is breached, the attacker can gain access to all the user's funds. Coates noted that the Solana Foundation is exploring ways to help users manage these permissions more safely, potentially through wallet-level alerts and permissions audits that make it easier to see and revoke unused access.

Solana's Security Posture

Coates said that Solana is focusing on "security by default" systems that protect users without requiring them to be security experts. "We need to meet users where they are," he said, arguing that crypto must not expect the average person to act as their own security guard. This philosophy is consistent with his broader vision for the industry: security should be an invisible layer that works silently in the background, rather than a set of rigorous protocols that users must actively follow.

In practice, this means integrating security features directly into wallets and applications. For example, Solana wallets could soon include warnings about transactions that interact with known malicious addresses, or simulate transactions before execution to show the likely outcome. These features already exist in some advanced wallets, but Coates wants to make them standard across the ecosystem. He also emphasized the importance of incident response, noting that the Solana Foundation has a dedicated team that works quickly to mitigate threats and support users who have been affected by hacks.

Another area of focus is the security of the Solana protocol itself. While Coates believes that human-focused attacks are the most immediate threat, he acknowledged that smart contract exploits remain a concern. The foundation actively supports audits and bug bounty programs, but he argued that the industry should also research new ways to make smart contracts more resilient. Formal verification, which uses mathematical proofs to verify that code behaves as intended, is one promising avenue. Solana has already invested in this area, and Coates expects it to become more mainstream in the coming years.

Preparing for Quantum Computing

Another looming threat is quantum computing. While large-scale, error-corrected quantum computers are still years away, the crypto industry must prepare for a future where they exist. Quantum computers could theoretically break the elliptic curve cryptography that underpins most blockchain networks, including Solana. This would allow an attacker to derive private keys from public keys, effectively stealing funds. Coates said Solana is evaluating post-quantum cryptography to ensure the network remains secure against this future threat.

Post-quantum cryptography involves new cryptographic algorithms that are believed to be secure against both classical and quantum computers. The transition will not be easy, as it requires changes to the underlying protocol, wallets, and other infrastructure. Coates noted that Solana is working with academic researchers and industry partners to stay ahead of the curve. He emphasized that this is a long-term project, but one that must start now. "If we wait until quantum computers are a reality, it will be too late," he said.

Quantum readiness is not just a technical challenge; it is also a coordination challenge. The entire ecosystem—validators, wallet providers, exchanges, and users—must update their systems simultaneously to avoid vulnerabilities. Coates drew a parallel to the Y2K bug, where years of preparation prevented a digital catastrophe. The crypto industry needs a similar level of coordinated effort for the quantum transition, and Solana is positioning itself as a leader in this space.

The focus on quantum security may seem premature, but Coates believes that proactive measures are essential. The same logic applies to AI threats; by the time a new exploit is widespread, the damage has already been done. He hopes that other blockchain projects will follow Solana's lead and invest in post-quantum research, raising the security bar for the entire industry. "We have a responsibility to build for the future, not just for today," he said.

As AI continues to make scams more convincing, and as the specter of quantum computing looms, Coates's message is clear: the crypto industry must evolve past the old playbook of relying on user caution. The next generation of security will be embedded in the tools people use every day, designed to protect them from threats they cannot see or understand. For Solana, that vision is now under the leadership of a CISO who understands that in the world of blockchain, the human is the new frontier.


Source:Coindesk News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy