The crypto industry's next major security threat won't necessarily come from a smart contract vulnerability. According to the Solana Foundation's newly appointed Chief Information Security Officer, it will come from AI-powered scams targeting the humans behind the wallets.

Michael Coates, who previously served as CISO at Twitter and led security at Mozilla, told CoinDesk in an interview that artificial intelligence is fundamentally changing the threat landscape for crypto users — and the industry is not prepared.

Shifting Attack Surface

Recent crypto security incidents have increasingly originated outside of blockchain infrastructure itself. Rather than exploiting protocol-level flaws, attackers are compromising credentials, manufacturing fake identities, and using AI to create increasingly persuasive social engineering campaigns.

"In many cases, it is an operational security issue or a Web2 issue that led to a key compromise," Coates said. "You have to do everything that a Web2 company has to do for security, and the incremental uniqueness to Web3."

That convergence of traditional cybersecurity failures with crypto's irreversible transactions creates a uniquely dangerous environment. An employee who falls for a deepfake voice call or a sophisticated phishing attempt can expose private keys that cannot be recovered once drained.

AI as Force Multiplier

Coates was particularly blunt about the trajectory of AI-enhanced attacks. "The social engineering piece is going to get a lot worse because of the power of AI and deepfakes," he said. "We should expect full spoofed phone calls with voices of people that we know. There's really no reason this won't hyperscale."

The implication is sobering: as generative AI tools become cheaper and more accessible, the cost of mounting convincing impersonation attacks approaches zero. Crypto users, who manage high-value assets through self-custodial wallets, represent attractive targets.

Coates argues that the industry cannot rely on training users to recognize scams. "You cannot fully prevent anyone from falling victim," he said. "Eventually, you will be fooled because the cons are that good." Instead, he advocates for layered security systems — multiple independent controls that can catch a compromise even when one layer fails.

Quantum Readiness

Beyond immediate AI threats, Coates also addressed the longer-term question of quantum computing. Solana has published its own quantum readiness strategy, and the foundation is evaluating post-quantum cryptography algorithms.

"The challenge with quantum readiness is we don't know when the Q-day will hit," Coates said. "The way to prepare for this is known. It is adopting the post-quantum algorithms."

The tension, as Solana has acknowledged previously, is that post-quantum cryptographic schemes carry performance tradeoffs that could impact blockchain throughput — a particularly sensitive issue for high-performance networks like Solana.

Designing for Real Users

Ultimately, Coates's message centers on a design philosophy that the crypto industry has historically resisted: security must be invisible to the user.

"We need to meet the users where they are, and we need to make the default secure decision for the user," he said. For an industry built on the premise of individual sovereignty and personal key management, that represents a philosophical shift — one that may prove necessary as the threat environment grows more sophisticated.

The alternative — expecting every wallet user to function as their own security operations center — is becoming untenable. The question is whether crypto protocols can build protective layers without sacrificing the self-custody principles that define them.