Need help? Support
BITCOIN
Tether Dominance USDT.D

SOL foundation CISO warns AI scams

Published 539 words 3 min read

TLDR

Solana (SOL) Foundations new chief information security officer is warning that AI is making crypto scams far more convincing and shifting the biggest risk toward social engineering.

  1. Michael Coates says attackers are using AI, deepfakes and fake identities to steal keys and credentials, not just exploit smart contracts.
  2. Recent large hacks already show most losses coming from compromised keys and infrastructure, a trend security firms expect AI to accelerate.
  3. Users should expect more realistic voice and video scams and rely on layered protections and out?of?band verification rather than trusting appearances.

Deep Dive

1. What The CISO Is Warning About

In an interview, Solana Foundation CISO Michael Coates argued that cryptos biggest security threats are increasingly AI?powered social engineering and credential theft rather than protocol bugs. He highlighted how AI makes deepfake voices and identities cheap and scalable, warning that users should expect fully spoofed phone calls that sound like people they know, and that eventually, you will be fooled because the scams are that good, pushing the industry to design systems that protect users by default rather than expecting them to be experts. You can see this outlined in the CoinDesk piece on the foundations new CISO and AI risks.

What this means

The attack surface is shifting from smart contract exploit to convince a human to sign or share the wrong thing.

2. Why This Matters For Crypto Users

Coates noted that many recent high profile thefts started with operational or Web2 security failures that led to key compromises, not on?chain logic errors. A mid?2026 report from security firm Ack3 found that hackers stole about $939.86 million in the first half of the year, with over 60 percent of losses originating from compromised keys and signing infrastructure rather than audited protocol code, and warned that AI tools make it easier to probe integrations for weak points. That aligns with Coates view that you must do everything a Web2 company does for security, then add Web3?specific protections on top.

What this means

Even audited DeFi or a fast chain like Solana does not help if the attacker gets your keys or an admins keys.

3. How To Respond And What To Watch

Coates advocates multiple layers of controls so that when someone is fooled, other protections take over. For everyday users this means treating urgent calls or messages, even with familiar voices or video, as untrusted until verified through a separate channel, keeping signing devices and passwords on dedicated hardware, and using least?privilege setups for wallets and APIs. On the ecosystem side, Solana and other chains are exploring post?quantum cryptography and stronger default security patterns that limit damage from a single compromised key and reduce reliance on human judgment at the moment of signing.

What this means

Practical defense is less about spotting every AI fake and more about assuming some will get through and building systems that still keep funds safe.

Conclusion

AI is making scams more persuasive and scalable, so the main crypto risk is increasingly human and credential focused rather than purely technical. For Solana and the wider market, the edge will belong to projects and users who design around inevitable social engineering failures, with layered controls and hardened key management rather than trusting that they can always spot the scam.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top