The cryptocurrency industry's most pressing security threats are shifting from smart contract vulnerabilities to AI-powered social engineering, according to Michael Coates, the newly appointed Chief Information Security Officer at the Solana Foundation.
In an interview with CoinDesk, Coates — who previously served as CISO at Twitter and led security at Mozilla — said that recent major crypto security incidents have originated not from protocol-level exploits but from increasingly sophisticated compromises of human trust.
AI as a Force Multiplier for Attackers
"In many cases, it is an operational security issue or a Web2 issue that led to a key compromise," Coates said. He emphasized that attackers are no longer primarily targeting code — they are targeting people.
The integration of AI tools into social engineering campaigns is accelerating this trend. Coates warned that AI-generated deepfakes, including voice synthesis capable of impersonating known individuals, will "hyperscale" the effectiveness of social engineering attacks against crypto users and organizations.
"We should expect full spoofed phone calls with voices of people that we know," he said. The implication for an industry where multi-signature approvals and verbal verification remain common security practices is significant.
Coates's assessment aligns with a broader pattern observed across the crypto sector. Recent high-profile incidents — including the $293 million Kelp DAO exploit — have been traced to operational security failures rather than fundamental smart contract flaws. Attackers are increasingly exploiting the human layer: compromised credentials, fake identities, and AI-generated content designed to deceive.
Redefining the Security Model
Coates argues that the industry must abandon the assumption that users can reliably protect themselves. "You cannot fully prevent anyone from falling victim," he said. "Eventually, you will be fooled because the cons are that good."
The solution, in his view, is layered security that maintains protection even when individual controls fail. Organizations should implement multiple independent security measures so that when one barrier is breached — whether through a deepfake call or a compromised credential — other controls take over.
The Solana Foundation is also advocating for security-by-default architectures that "meet users where they are" rather than expecting them to become security experts. This represents a philosophical shift for an industry that has historically placed the burden of operational security on end users.
Quantum Readiness
Beyond the immediate AI threat, Coates addressed the longer-term challenge of quantum computing. The Solana Foundation has published a quantum readiness strategy, acknowledging that while the timeline for cryptographically relevant quantum computers remains uncertain, the preparation path is clear.
"The challenge with quantum readiness is we don't know when the Q-day will hit," Coates said. "The way to prepare for this is known. It is adopting the post-quantum algorithms."
The foundation's approach mirrors a growing consensus across the blockchain industry: while quantum threats may be years or decades away, the transition to post-quantum cryptographic standards is sufficiently complex that preparation must begin now.
A Broader Mandate
Coates's role at the Solana Foundation extends beyond securing the organization itself. He is working with ecosystem projects to strengthen their security practices and engaging with regulators on cybersecurity standards for the industry.
That dual mandate — internal security and ecosystem-wide standards — reflects the interconnected nature of blockchain security. A vulnerability at a single application built on Solana can undermine confidence in the entire network, making coordinated security practices across projects essential.
The appointment of a CISO with Coates's credentials also signals institutional maturation. As blockchain networks grow in scale and value, the security frameworks protecting them increasingly resemble those of traditional financial infrastructure — with the added complexity of managing an open, permissionless environment where anyone can deploy code and anyone can be targeted.