Michael Coates walked into the Solana Foundation's security role with a blunt message: artificial intelligence is making it exponentially harder to catch crypto scams. The newly appointed chief information security officer isn't talking about blockchain vulnerabilities or code bugs. He's warning about social engineering, deepfakes, and AI-generated phishing so convincing that even paranoid users will slip up eventually.

Coates came to Solana after running security at Twitter and leading defense operations at Mozilla during some of the internet's rougher years. His read on the current threat landscape is straightforward. Most recent crypto hacks didn't happen because someone found a flaw in smart contracts. They happened because attackers compromised credentials, impersonated trusted people, or got their hands on seed phrases through carefully crafted cons. "In many cases, it is an operational security issue or a Web2 issue that led to a key compromise," he told CoinDesk.

Why Crypto Makes Mistakes Permanent

The problem gets darker when you remember how crypto works. If you wire money through your bank and realize you've been scammed, you call your bank. You might get your money back. In crypto, once you sign a bad transaction or hand over your recovery phrase, the transaction settles. The coins vanish. There is no undo button, no customer service number to call, no insurance policy kicking in.

That finality is exactly what makes social engineering so effective in this space. Attackers know that if they can trick someone once, the damage is irreversible. Coates expects this pattern to accelerate as AI tools improve. Attackers can now generate realistic emails at scale, craft convincing voice deepfakes of someone's boss or family member, and build fake identities that pass basic verification checks. "The social engineering piece is going to get a lot worse because of the power of AI and deepfakes," Coates said. He specifically flagged fully spoofed phone calls using voices of people victims know as something that will become routine.

Building Systems That Work When People Fail

Coates doesn't believe scams can be eliminated. His position is almost defeatist: "Eventually, you will be fooled because the cons are that good." Rather than betting on users staying vigilant forever, he argues that crypto systems need to be secure by default. The architecture itself should assume people will make mistakes and build in guardrails that make recovery possible even after a compromise. His work at Solana spans beyond just protecting the foundation itself. He also advises projects across the Solana ecosystem and sits in on conversations with regulators about cybersecurity standards.

Looking further out, Coates flagged quantum computing as a longer-term security concern for crypto networks. That threat sits somewhere between theoretical and approaching, but it's already on the radar of anyone managing cryptographic systems that might need to survive the next decade.

This article is for informational purposes only and does not constitute financial or security advice. Readers should consult qualified security professionals for crypto-related safety concerns.