Crypto’s biggest security threat right now might not be a hacked smart contract or a broken bridge. It might be a phone call that sounds exactly like your boss. That’s the warning coming from Michael Coates, the new Chief Information Security Officer at the Solana Foundation, who says AI crypto scams are becoming convincing enough to fool even careful users, and that the danger has little to do with any flaw in Solana’s blockchain itself.
Key takeaways
- Solana Foundation CISO Michael Coates warns that AI is making crypto scams more convincing, especially through phishing, impersonation and voice-based deception, according to CoinDesk.
- The threat targets people, not code: Coates says the risk sits in social engineering aimed at users and crypto teams, not in Solana’s blockchain or smart contracts.
- AI lets scammers write polished messages, fake identities, and even clone voices, making voice deepfake attacks a growing concern across the industry.
- Because blockchain transactions are instant and irreversible, a single successful scam can wipe out funds with no chargeback and no reset button.
- Coates argues security has to be built into defaults and team procedures, not left to user vigilance alone, and the warning applies to every crypto ecosystem, not just Solana.
Solana Foundation’s Warning on AI-Enhanced Crypto Scams
Coates, who joined the Solana Foundation earlier this year after previously serving as CISO at Twitter and leading security at Mozilla, told CoinDesk that the biggest security threats in crypto are increasingly coming from AI-powered social engineering and compromised credentials, not from smart contract exploits. His job now spans securing the foundation itself, working with Solana ecosystem projects on security practices, and meeting with regulators on cybersecurity standards.
Focus on Social Engineering, Not Blockchain Flaws
This isn’t a claim that Solana’s code has a vulnerability. “In many cases, it is an operational security issue or a Web2 issue that led to a key compromise,” Coates said, according to CoinDesk. In other words, attackers aren’t breaking the chain, they’re breaking the human layer around it, going after employees, founders, moderators, and support channels instead of protocols. That distinction matters because it shifts the conversation away from code audits and toward how people communicate, verify, and trust one another online.
“You have to do everything that a Web2 company has to do for security, and the incremental uniqueness to Web3,” Coates told CoinDesk, adding that “when you have adversaries that are definitely motivated and can take funds irrevocably, they are going to look for any mistake.” Notably, Coates framed this as relevant far beyond one chain: the warning applies broadly across crypto ecosystems, wherever value moves fast and mistakes are hard to undo.
How AI Amplifies Cryptocurrency Scam Techniques
AI doesn’t invent new categories of fraud, but it makes old ones far more efficient and far more believable. The clumsy scam email full of typos is no longer the main threat. Modern crypto social engineering now relies on polished, personalized messages generated in seconds.
Realistic Phishing, Impersonation, and Voice Deepfakes
“The social engineering piece is going to get a lot worse because of the power of AI and deepfakes,” Coates said, warning that “we should expect full spoofed phone calls with voices of people that we know” and that “there’s really no reason this won’t hyperscale.” That’s a direct nod to voice deepfake attacks, where a team member might pick up what sounds like an urgent call from an executive demanding immediate action, a scenario built to bypass normal checks by exploiting urgency.
AI Enables Polished Messages and Adaptive Scripts
AI tools can now imitate support staff, generate convincing fake identities, and adapt a script in real time to fit a specific target. Scammers can test messages faster, personalize attacks at scale, and generate content that no longer reads like a scam. As one analysis put it, AI does not create fraud from nothing; it makes existing fraud more efficient, more scalable, and more convincing than the generic attempts of just a few years ago.
Risks of AI-Driven Scams in the Crypto Ecosystem
The stakes in crypto are unusually high because there’s no undo button. If a user signs a malicious transaction, hands over a seed phrase, installs fake software, or approves the wrong wallet connection, funds move instantly and permanently. There’s no chargeback, no simple password reset, and often no central authority capable of reversing anything.
Irreversible Losses Due to Instant Blockchain Transactions
That irreversibility is exactly why social engineering has become such a high-impact attack vector in this industry. Coates was blunt about the limits of relying on individual caution: “you cannot fully prevent anyone from falling victim,” he told CoinDesk, adding that “eventually, you will be fooled because the cons are that good.” His answer isn’t to demand perfect vigilance from every user, but to build layered defenses so that when someone does get fooled, other safeguards can still catch the mistake before funds disappear.
Increasing User Attack Surface in Solana’s Ecosystem
These Solana security risks are amplified by how mainstream the network has become. Solana has drawn in consumer applications, decentralized finance operations, meme coin markets, NFT records, payment initiatives, and user-friendly mobile solutions, all of which widen the pool of everyday users who could be targeted through fake mints, fake airdrops, malicious token approvals, impersonation accounts, or wallet-draining sites. The more accessible and popular an ecosystem becomes, the more attractive its users are to scammers, and that dynamic isn’t unique to Solana. It applies wherever mainstream adoption meets irreversible transactions.
Recommended Security Measures Beyond User Vigilance
Telling people to “be careful” isn’t a strategy anymore, not when fake links look real, cloned voices sound authentic, and fraudulent support accounts respond faster than genuine ones. Coates has pushed for systems designed to be secure by default rather than systems that depend on flawless human judgment every single time.
Necessity of Safer Defaults and Controls
“We need to meet the users where they are, and we need to make the default secure decision for the user,” Coates said. In practice, that means wallets that make risky approvals clearer, apps that reduce blind signing, protocols that limit permissions, and exchanges that tighten withdrawal controls. Organizations, he argued, need multiple layers of security so that when someone falls for a scam, other protections still activate to limit the damage.
Procedures for Crypto Teams to Mitigate AI Scams
Individual users aren’t the only targets. Crypto teams face convincing fake vendors, investors, journalists, job applicants, or internal colleagues designed to compromise credentials or trick employees into approving harmful transactions. That’s why Coates and industry practice point toward concrete procedures rather than awareness campaigns alone: out-of-band verification for sensitive requests, multisig discipline for treasury actions, hardware keys, strict access controls, and rigorous internal checks before anything moves. As AI narrows the gap between a real message and a fake one, those procedural guardrails become the difference between a close call and a permanent loss.
FAQ
Is the Solana blockchain itself vulnerable to these AI-enhanced scams?
No. The threat targets users and teams through social engineering, not the blockchain or smart contracts.
How does AI improve the effectiveness of crypto scams?
AI enables scammers to create more realistic messages, fake identities, voice deepfakes, and adapt scripts dynamically to victims.
What risks do AI-driven crypto scams pose to users?
Because blockchain transactions are instant and irreversible, users can suffer permanent losses if they fall victim to scams.
What security measures are recommended to combat AI-driven scams?
Security should include safer defaults, better warnings in wallets, permission limits, and team procedures like out-of-band verification and multisig discipline.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.
en.cryptonomist.ch