Solana Foundation CISO Warns AI Is Making Crypto Scams More Convincing
Solana Foundation’s Chief Information Security Officer, Michael Coates, has warned that artificial intelligence is making crypto scams more convincing, particularly through social engineering, phishing, and voice-based impersonation. The warning does not point to a flaw in Solana’s blockchain or smart contracts, but rather to how attackers target individuals.
Crypto security discussions have traditionally focused on code—smart contracts, bridges, wallets, private keys, and validators. While these remain important, attackers are increasingly targeting users, employees, founders, moderators, and support channels. AI enables this shift by generating more realistic messages, voices, identities, and pressure tactics.
AI-powered scams are becoming more personal. The old scam emails with spelling mistakes are no longer the main threat. AI can now write polished messages, imitate support staff, generate fake identities, create convincing voice calls, and adapt scripts to specific victims. In crypto, the stakes are high because mistakes can be irreversible. A signed malicious transaction, shared seed phrase, or fake wallet approval can lead to instant fund loss with no chargeback or password reset.
Coates emphasizes that systems should be secure by default. Crypto has often placed too much responsibility on users. Telling users not to click bad links is insufficient when bad links look real, voices sound authentic, and fake support accounts respond faster than real ones. Wallets can make risky approvals clearer, apps can reduce blind signing, protocols can limit permissions, exchanges can improve withdrawal controls, and teams can use internal verification steps. Security should not depend on every user being perfect every time.
Social engineering also targets crypto teams. A convincing fake vendor, investor, journalist, or colleague can compromise credentials or trick employees into approving transactions. Voice deepfakes make this worse—a team member might receive a call that sounds like an executive asking for urgent action. In a fast-moving environment, urgency can bypass normal checks. Teams need procedures such as out-of-band verification, multisig discipline, hardware keys, and strict treasury controls.
Solana’s ecosystem, with its consumer apps, DeFi activity, meme coin trading, NFT history, and mobile-friendly tools, makes user-facing security especially important. As an ecosystem becomes more mainstream, attackers target ordinary users more. A chain can be fast and technically sound, but users can still lose funds through fake mints, fake airdrops, malicious token approvals, or wallet-draining sites. The warning applies to all crypto ecosystems, not just Solana.
AI does not create fraud from nothing; it makes existing fraud more efficient. Scammers can test messages faster, personalize attacks, generate realistic content, and operate at larger scale. Users and teams must assume scams will look increasingly professional. Crypto security must move beyond telling users to ‘be careful’ and instead focus on safer defaults, better warnings, permission limits, stronger internal controls, and trusted communication channels. The next wave of crypto scams may not look obviously fake.
Source: https://bitcoinist.com/solana-foundation-ciso-warns-ai-is-making-crypto-scams-more-convincing/