While crypto security conversations still center on smart contract bugs and bridge exploits, a far more personal threat is accelerating. Michael Coates, the newly appointed Chief Information
While crypto security conversations still center on smart contract bugs and bridge exploits, a far more personal threat is accelerating. Michael Coates, the newly appointed Chief Information Security Officer of the Solana Foundation, has publicly warned that artificial intelligence is enabling scams that are vastly harder to detect than traditional phishing. The original report details Coates’ view that AI vulnerabilities and synthetic identities will drive the next major wave of blockchain security failures.
Coates’ warning lands at a moment when Solana’s ecosystem is again attracting heavyweight developer interest. Recent developer activity data places Solana among the most active blockchain networks, a standing that naturally expands the target surface for attackers. High network usage combined with a growing retail audience creates exactly the conditions where AI-enhanced social engineering can extract the most value.
How AI Is Reshaping the Scam Landscape
Generative models have fundamentally changed the economics of fraud. Deepfake video calls, voice clones of known contacts, and personalised messages scraped from social platforms now cost almost nothing to produce. A scammer no longer needs broken English and a suspicious link; they can impersonate a support agent from a legitimate project with startling accuracy. Coates’ concern is that static security checks—passwords, seed phrases, even two-factor authentication—cannot protect a user who is convinced they are speaking with a real representative.
For the everyday holder, this means the old advice of “check the URL” is losing its power. Phishing campaigns already use AI to generate clean, context-aware messages that bypass spam filters. Synthetic ID images bypass exchange KYC checks. When a fake profile passes a visual inspection and a video call feels real, the social layer of crypto security collapses. The Solana Foundation’s new CISO is essentially arguing that user-facing identity breaches will outpace protocol-level hacks in frequency and damage.
Implications for Solana and the Wider Ecosystem
The Solana network, with its emphasis on consumer-grade speed and low fees, attracts a broad demographic of users who may not have deep technical knowledge. That demographic is precisely the one most vulnerable to AI-generated confidence tricks. A protocol with 400-millisecond block times and near-zero fees is not a shield against a fake support call that extracts a private key. The foundation’s decision to bring in an experienced security voice like Coates signals an internal recognition that infrastructure security is no longer enough.
Moreover, AI-driven features are being woven directly into Web3 applications at an accelerating pace. Partnerships that fuse decentralized computing with AI are unlocking new utility, but they also expand the attack surface. Every integration becomes a potential vector for a scammer who understands how users interact with AI-assisted interfaces. The same tools that personalize a DeFi dashboard can be repurposed to mimic it identically.
Regulatory and Defensive Gaps
The warning arrives against a backdrop of slow-moving policy. While lawmakers debate landmark crypto bills in the US, banks are lobbying to reshape market-structure legislation that largely ignores the AI scam problem. Regulatory drafts focus on custody, token classification, and exchange rules—not on synthetic identity verification or the liability of platforms that fail to detect AI-generated fraud. The timeline for any legislative fix is years behind the speed at which open-source generative models evolve.
For Solana specifically, the foundation is now forced into a proactive defense posture without a regulatory playbook. Education campaigns and tighter identity verification layers become the immediate, imperfect tools. What remains uncertain is whether user-focused defenses can scale across a permissionless ecosystem without eroding the very openness that made it valuable. Coates’ appointment acknowledges the threat; it does not resolve the tension between security and accessibility. If AI scams continue to improve at their current pace, the entire sector will face a reckoning over how to vet who—or what—is really on the other side of the screen.