
The Solana Foundation's new chief information security officer, Michael Coates, has a blunt warning for the crypto industry: artificial intelligence is making scams significantly more convincing. In a detailed assessment of the security landscape, Coates said that AI vulnerabilities and fake identities will drive the next wave of blockchain security concerns. His message is a shift from the industry's traditional focus on protocol-level bugs to the humans who use those protocols.
Key facts at a glance
- Michael Coates is the new CISO of the Solana Foundation.
- He warns that AI is making crypto scams more convincing.
- AI vulnerabilities and fake identities will drive the next wave of blockchain security concerns.
- The biggest threats are AI-powered social engineering and compromised credentials, not just smart contract exploits.
- Attackers are increasingly targeting people rather than protocols.
- Solana is evaluating post-quantum cryptography.
- Coates advocates for security systems that protect users by default.
A changing threat landscape
For much of crypto's history, the most feared security event was an attacker draining millions from a smart contract. Exploits such as reentrancy attacks, oracle manipulation, and flash-loan abuses have caused billions of dollars in losses across the industry. But according to Coates, the next major threats will not necessarily come from code. Instead, they will be enabled by AI that can make phishing, identity theft, and social engineering far more effective and harder to detect.
Coates, who recently joined the Solana Foundation as its CISO, emphasized that compromised credentials are becoming one of the most dangerous vulnerabilities in Web3. A user who loses their private key or grants a malicious signature through a fake wallet interface can be drained instantly. No amount of smart contract auditing can prevent that if the attacker controls the human decision-making process.
How AI is making scams more convincing
AI has lowered the cost of creating believable scams. Gone are the days when a phishing email could be spotted by poor grammar or a generic greeting. Modern large language models can craft personalized messages that mimic a victim's colleagues, friends, or favorite crypto influencers. These messages can reference real transactions, know the exact wallet address a user interacted with, and produce urgent calls to action that trigger an emotional response.
Fake identities are another area of concern. AI-generated profile pictures, video calls, and voice clones can make a fraudster appear legitimate. Coates specifically pointed to fake identities as a key driver of future security issues. A social media account with thousands of followers, a website that looks identical to a legitimate project, and a video of a known founder endorsing something can be manufactured with frightening accuracy. This level of realism can easily deceive even experienced crypto users.
The rise of deepfakes has already caused problems in broader finance, but crypto's pseudonymous nature makes it even more vulnerable. In blockchain systems, transactions are irreversible, and there is no central authority to reverse a payment made to a scammer. That means a convincing fake identity can lead to permanent financial loss.
Attackers are targeting people, not just protocols
Coates's warning signals an important change in how the industry should think about security. For years, security teams focused on code audits, bug bounties, and verification of smart contract logic. Those efforts remain important, but they do not address the full scope of modern attacks. Social engineering is now one of the most common ways attackers compromise crypto wallets. A user may be tricked into importing a malicious seed phrase, signing a permit, or connecting their wallet to a phishing site that steals all approvals.
Even institutional players are not immune. Compromised credentials have been a factor in many major exchange and treasury incidents. Employees with access to private keys or custody systems may be targeted with spear phishing attacks. In a world where AI can clone a CEO's voice, even a
Source:Coindesk News
