Need help? Support
BITCOIN
Tether Dominance USDT.D

SOL CISO warns AI scams target crypto

Published Updated 551 words 3 min read

TLDR

Solana Foundations CISO Michael Coates says AI-powered scams are rapidly becoming one of the biggest security threats in crypto, particularly through social engineering.

  1. Coates warns that deepfake audio, video, and fake identities are now more dangerous to crypto users than many smart contract exploits.
  2. AI-assisted scams focus on stealing credentials and seed phrases, exploiting the irreversibility of crypto transactions and a surge in user-targeted fraud.
  3. The main defense is stronger operational security and systems that default to safety, rather than expecting every user to behave like a security expert.

Deep Dive

1. Nature Of The AI Scam Threat

In a recent Solana Foundation CISO interview, Michael Coates highlights that attackers are shifting from protocol exploits to people-focused attacks. He specifically points to AI-generated deepfakes and synthetic identities that can convincingly impersonate founders, support staff, or regulators.

Coates expects full spoofed phone calls with voices of people that we know, and warns that even careful users may eventually be fooled because the scams will look and sound legitimate. His role covers both securing the Solana Foundation and helping ecosystem projects adopt stronger security practices, including engagement with regulators on standards.

What this means

The headline is not about a new Solana bug, but about human-facing attacks becoming the primary risk vector across crypto.

2. Why AI Scams Hit Crypto So Hard

Crypto is uniquely exposed because control of funds is concentrated in private keys and seed phrases, and transactions are irreversible once signed. Coates notes that many recent hacks actually start with operational security failures or Web2-style compromises, not on-chain code flaws.

Broader data supports this trend. Blockaid reports a record 1.1 billion dollars in hacks in the first half of 2026, with privileged key misuse driving most losses. At the same time, government and exchange impersonation scams are rising, such as counterfeit IRS letters pushing crypto holders toward fake compliance portals to steal wallet access and identities, as detailed in an IRS fraud alert.

AI tools make these phishing and impersonation campaigns more convincing, faster to scale, and harder for a typical user to detect.

What this means

The biggest risk may be trusting the wrong person or website, not a bug in the chain or protocol you use.

3. How Users And Ecosystems Can Respond

Coates argues that crypto systems must meet users where they are by building security that works even when people make mistakes. That includes default-safe wallet and app design, clearer verification of official communications, and multi-layer defenses around key storage and access.

For individual users, the practical angle is to treat unsolicited messages, calls, QR codes, and urgent security alerts with skepticism, especially when they reference seed phrases, recovery codes, or login credentials. On the ecosystem side, improved governance, multi-source oracles, better key management, and timely patching of known vulnerabilities can reduce the damage when attackers do gain access.

What this means

The most useful alpha here is behavioral and architectural; projects that invest early in user-friendly security and scam-resistant UX are better positioned to retain trust as AI scams get more sophisticated.

Conclusion

Coates warning reinforces a shift in crypto security from purely technical exploits to AI-enhanced social engineering aimed at users themselves. As deepfakes and impersonation scams spread, the critical edge is not just stronger code, but systems and habits that make it hard for attackers to turn a single mistake into permanent financial loss.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top