TechSolana Foundation's new CISO highlights AI's role in crypto scams

Michael Coates, the foundation’s CISO, warns that AI vulnerabilities and fake identities will fuel the next wave of blockchain security challenges.

By Margaux Nijkerk|Edited by Nikhilesh De Aug 1, 2026, 1:00 p.m. 2 min readMake preferred on

  • Michael Coates, the CISO of the Solana Foundation, warns that the most significant security threats in crypto are increasingly stemming from AI-driven social engineering and compromised credentials, shifting the focus from smart contract exploits to human vulnerabilities.
  • As the industry braces for the eventual rise of quantum computing, Coates indicates that Solana is assessing post-quantum cryptography and is advocating for security frameworks that inherently protect users, asserting that crypto needs to "meet users where they are" rather than expecting them to be security-savvy.

Recent months have seen significant security breaches in crypto ecosystems that were not linked to smart contract flaws, but rather to sophisticated compromises such as fake identities and AI-generated scams.

According to Michael Coates, the chief information security officer at the Solana Foundation, these kinds of vulnerabilities are set to drive the next wave of blockchain security issues.

In an interview with CoinDesk, Coates stated, "You have to do everything that a Web2 company has to do for security, and the incremental uniqueness to Web3." He added, "When adversaries are highly motivated and can irreversibly take funds, they will look for any mistake."

Coates, who previously served as CISO at Twitter and led security at Mozilla during the browser wars, joined the Solana Foundation earlier this year. His role encompasses not just securing the foundation but also collaborating with Solana ecosystem projects to implement robust security practices and engaging with regulators to establish appropriate cybersecurity standards.

While crypto hacks often make headlines due to the substantial amounts stolen, Coates highlighted that many of these incidents originate from issues outside of blockchain vulnerabilities. "In many cases, it is an operational security issue or a Web2 problem that led to a key compromise," he noted.

This situation is likely to worsen as advancements in artificial intelligence provide attackers with enhanced tools to exploit security weaknesses.

Coates remarked, "The social engineering aspect is going to get significantly worse due to the capabilities of AI and deepfakes. We should anticipate fully spoofed phone calls with voices of individuals we know... there's really no reason this won't hyperscale."

To mitigate these risks, he believes the crypto industry must develop more effective systems that remain secure even when individuals fall victim to scams. "You cannot completely prevent anyone from being deceived," he explained. "Eventually, you will be tricked because the cons are that good." He suggested that organizations should implement multiple layers of security controls, so "when someone gets fooled, other measures can take over to protect them."

Looking ahead, the looming question of quantum computing poses a significant challenge for various crypto ecosystems, including Solana's. "The challenge with quantum readiness is we don't know when the Q-day will hit," Coates said. "The way to prepare for this is known. It involves adopting post-quantum algorithms." The Solana Foundation has released its own strategy to prepare for this eventuality.

Whether the security threats arise from AI scams or quantum computing, Coates emphasized that the industry's future success will depend on building systems that automatically protect users instead of relying on them to act as security experts. "We need to meet users where they are, and we need to make the default secure decision for the user," he stated.

Read more: Solana's quantum-threat readiness reveals harsh tradeoff: security vs speed

Solana Newsquantum computingHackLatest Crypto News