TLDR
Solana Foundation's new CISO says AI-powered deepfakes and social engineering are now among the biggest threats to crypto users, making scams far more convincing than older phishing attempts.
- Michael Coates warns that attackers are shifting from smart contract exploits to AI-driven scams that trick users into giving up keys and credentials.
- Recent data show billions in losses from hacks and sophisticated impersonation schemes, with AI tools making it easier to scale and personalize attacks.
- Crypto users can reduce risk by focusing on operational security: strong authentication, channel verification, and treating any request for seed phrases or urgent action as highly suspect.
Deep Dive
1. Coates Core Warning
Michael Coates, Solana Foundations Chief Information Security Officer, says the biggest security threats are increasingly AI-powered social engineering and fake identities, not just protocol bugs. In an interview, he warns that deepfake audio and video will enable full spoofed phone calls with voices of people that we know, making it much easier to trick users into revealing keys or signing malicious transactions. He argues crypto needs systems that protect users by default, rather than assuming everyone is a security expert, and notes Solana is also exploring post-quantum cryptography to prepare for longer term risks Coates comments.
2. How AI-Driven Crypto Scams Are Evolving
The warning comes amid a clear trend: most of the largest recent crypto losses began with compromised keys or identities. One report found hackers stole about $939.86 million in the first half of 2026, with 61 percent of losses coming from incidents like the KelpDAO and Drift exploits that relied on key compromise and advanced social engineering, not code bugs hack loss analysis.
AI is already embedded in these scams. OpenAI recently shut down ChatGPT accounts used by a Cambodian pig-butchering operation that generated fake personas, passports and trading dashboards for fraudulent crypto schemes ChatGPT fraud crackdown. In the US, the IRS has warned of convincing fake tax letters and QR-code portals designed to steal exchange credentials and wallet access IRS fraud alert. Together, these show AI is lowering the cost of running highly customized scams at scale.
3. Practical Protections For Crypto Users
Coates and other security teams now stress operational security: protecting people and credentials as much as smart contracts. Common measures include strong two factor authentication on exchanges and wallets, verifying any support, tax, or regulator contact through official websites, and refusing to share seed phrases, private keys or one-time codes in chats or calls. Treat unsolicited QR codes, urgent payment demands, or too good to be true investment offers as red flags, especially when they arrive in polished videos, deepfake voice calls or AI-written emails.
The biggest risk for many Solana and other crypto users is no longer a protocol exploit, but being socially engineered into handing attackers the keys themselves.
Conclusion
AI is rapidly shifting crypto security from purely technical defenses to a battle over identity, trust and user behavior. Solanas CISO is effectively saying that if the ecosystem does not build protections that assume convincing AI scams are normal, losses from key theft and impersonation will keep rising. For everyday users, the best response is to raise the bar on verification and access control now, so that even highly realistic deepfakes cannot easily turn a moment of confusion into a permanent loss of funds.
