What to Know

  • Solana Foundation CISO Michael Coates says crypto security threats are increasingly moving beyond smart contract exploits toward AI-powered social engineering, fake identities and compromised credentials.
  • Coates argues that attackers are focusing on people and operational weaknesses because crypto transactions can move funds irrevocably once a mistake is made.
  • Recent security incidents across crypto ecosystems have involved advanced compromises such as fake identities and AI-generated scams rather than only blockchain-level vulnerabilities.
  • Coates, who previously served as CISO at Twitter and led security at Mozilla during the browser wars, joined the Solana Foundation earlier this year.
  • The Solana Foundation is working on security practices across its ecosystem and engaging with regulators on cybersecurity standards.
  • Coates warns that AI and deepfakes could make spoofed phone calls and impersonation attacks far more convincing.
  • He says crypto organizations need layered security controls that can protect users even when someone is fooled by a scam.
  • Solana is also evaluating post-quantum cryptography as the industry prepares for the eventual risk posed by quantum computing.
  • Coates says the industry must make secure defaults easier for users rather than expecting them to behave like security experts.

Solana Security Focus Shifts From Code to People

Solana Foundation CISO Michael Coates is warning that the next wave of blockchain security concerns may be driven less by smart contract flaws and more by the vulnerabilities surrounding the people and systems that interact with crypto networks. In FXCOINZ market coverage, the message is clear: attackers are no longer limiting themselves to protocol bugs. They are increasingly targeting identity, access, trust and human judgment.

That shift matters because blockchain security has often been discussed through the lens of code. Smart contract audits, formal verification, bug bounties and protocol upgrades remain important, but Coates’ warning highlights a broader reality for the sector. Even a well-designed blockchain or decentralized application can be exposed if a private key is mishandled, an employee is tricked, a credential is stolen or a fake identity is accepted into a sensitive workflow.

Coates has said that crypto must handle everything a Web2 company handles for security, plus the additional complexities that come with Web3. The reason is straightforward: when motivated adversaries can take funds in a way that is difficult or impossible to reverse, they will search for any mistake. That mistake does not need to sit inside the blockchain itself. It may appear in account access, internal procedures, vendor management, user support, communications or social engineering defenses.

AI Raises the Stakes for Social Engineering

The concern is becoming more urgent as artificial intelligence gives attackers more convincing tools. Coates has warned that social engineering is likely to become much worse because of AI and deepfakes. The risk is not merely a poorly written phishing email or an obvious scam message. The emerging threat is a more persuasive form of impersonation, potentially including spoofed phone calls using voices of people a target already knows and trusts.

That kind of attack changes the security equation for crypto firms, foundations, decentralized projects and users. Traditional security education often tells people to look for suspicious wording, unusual requests or unfamiliar senders. AI-generated messages and synthetic identities can weaken those clues. If a scam can imitate a colleague, a founder, a support agent, an investor, a community moderator or another trusted figure, then the burden on individual judgment becomes far heavier.

Coates’ warning that there is no reason this threat will not hyperscale captures the speed at which automated fraud can spread. Crypto is particularly exposed because it combines global access, valuable digital assets, online communities and transaction finality. Attackers do not need to compromise a protocol if they can convince someone with access to sign the wrong transaction, reveal a seed phrase, approve a malicious request or transfer control of an important account.

Compromised Credentials Remain a Critical Weak Point

Many crypto exploits that appear at first to be blockchain failures can begin with operational security problems. Coates has emphasized that in many cases, a Web2 issue or operational security issue leads to key compromise. This is an important distinction for investors and builders because it suggests that preventing losses requires more than reviewing on-chain code.

Compromised credentials can affect teams in many ways. They can expose private keys, administrator accounts, communication channels, cloud services, deployment systems, domain controls or internal tools. Once attackers gain access to a trusted account, they can move laterally through an organization or create a false sense of legitimacy when contacting others. In crypto, that access can become especially dangerous if it touches wallets, signing processes or governance controls.

For the Solana ecosystem and the broader crypto market, this means security planning has to include strong identity management, access controls, employee training, incident response and layered approval systems. The challenge is not unique to blockchain, but blockchain raises the consequences. When funds can move quickly and settlement is final, recovery can be far more difficult than in traditional financial systems where intermediaries may freeze or reverse certain transactions.

Layered Defenses Are Becoming Essential

Coates has argued that crypto organizations should not assume users or employees will never fall for scams. His view is that people will eventually be fooled because the cons are becoming that good. That does not mean the industry should abandon education. It means education alone cannot be the final line of defense.

The stronger model is layered security. In practice, layered controls can reduce the chance that one human mistake becomes a catastrophic loss. If someone clicks a malicious link, other protections should still stand. If a voice call is spoofed, a transaction should still require independent verification. If an account is compromised, access limits and approval requirements should reduce the attacker’s ability to act immediately.

This approach fits a broader security principle often described as defense in depth. The idea is to create multiple checkpoints rather than relying on a single perfect decision. For crypto, that can mean better default wallet warnings, transaction simulation, multi-party approvals, hardware-backed authentication, limited permissions, monitoring for unusual activity and procedures that slow down high-risk actions. The exact tools vary by organization, but the philosophy is the same: systems should protect people when human judgment fails.

Solana Foundation’s Broader Security Role

Coates joined the Solana Foundation earlier this year after previously serving as CISO at Twitter and leading security at Mozilla during the browser wars. His role at the foundation includes securing the foundation itself, working with Solana ecosystem projects on stronger security practices and meeting with regulators to help shape appropriate cybersecurity standards.

That mandate reflects how major blockchain foundations often sit at the intersection of technology, ecosystem coordination and public trust. The Solana Foundation does not simply operate in isolation. It supports a network of builders, applications and infrastructure participants that all face overlapping security risks. A weakness in one part of an ecosystem can affect user confidence more broadly, even if the core protocol continues to function as designed.

For Solana, the security narrative is therefore about both technical performance and operational resilience. Fast settlement, active development and growing application activity can attract users and builders, but they can also attract attackers. As the ecosystem expands, the need for consistent security standards becomes more important across projects that may vary widely in maturity, staffing and risk controls.

Quantum Computing Adds a Longer-Term Challenge

Beyond AI-enabled scams, Coates is also focused on the longer-term challenge of quantum computing. He has said the difficulty with quantum readiness is that nobody knows when “Q-day” will arrive. In crypto discussions, that phrase generally refers to a future point when quantum computing could threaten cryptographic systems that currently secure digital infrastructure.

Coates has said the way to prepare is known: adopting post-quantum algorithms. The Solana Foundation has developed its own strategy for preparing for that future. The issue is complex because blockchain networks must balance security, performance, compatibility and decentralization. Moving to new cryptographic assumptions can introduce tradeoffs, especially for networks that place heavy emphasis on speed and throughput.

Quantum readiness is not the same kind of immediate operational threat as an AI-generated scam, but it is significant because blockchains are long-lived systems. Assets, identities and transaction histories can persist for years. Preparing early may reduce the risk of rushed migrations later if quantum capabilities become more practical. At the same time, the uncertainty around timing means networks must make careful decisions about when and how to adopt new cryptographic standards.

Secure Defaults Could Define the Next Phase of Crypto

One of Coates’ most important points is that crypto must meet users where they are. The industry has often expected users to manage complex security decisions on their own, from seed phrase storage to transaction approvals and wallet permissions. That approach can empower experienced users, but it can also expose everyday participants to mistakes they may not fully understand.

Secure defaults are designed to reduce that burden. Instead of requiring users to become security experts, wallets, applications and platforms can make the safer path the easiest path. That may include clearer risk signals, safer approval flows, limited default permissions and stronger recovery options that do not undermine user control. The goal is not to remove responsibility, but to avoid making the average user responsible for recognizing every advanced scam.

As AI makes deception more realistic and as quantum computing remains a long-term cryptographic concern, crypto security is becoming a wider discipline. It now includes code, people, processes, identity, governance, regulation and user experience. Coates’ warning places Solana in a broader industry conversation: the next security frontier may be less about whether blockchains can execute correctly and more about whether ecosystems can protect users in an adversarial digital environment.

Why This Matters for Crypto Markets

Security remains a market issue because confidence is central to adoption. When users believe they can safely interact with wallets, applications and networks, participation becomes easier. When high-profile scams or compromises spread, confidence can weaken even if the underlying protocol was not at fault. That reputational spillover is one reason operational security has become as important as technical security for major crypto ecosystems.

For market participants watching Solana and the wider digital asset sector, Coates’ comments point to a maturing risk landscape. The early crypto security conversation often centered on whether smart contracts were safe. That question remains important, but it is no longer sufficient. The industry must now address AI-amplified fraud, fake identities, compromised credentials and future cryptographic transitions. Those issues may influence how institutions, regulators and users evaluate blockchain networks over time.

The clearest takeaway is that crypto security is becoming more like full-spectrum cybersecurity, with Web3-specific stakes. Attackers will pursue the easiest path, whether that path is a flawed contract, a weak password, a fake identity, a convincing phone call or an outdated cryptographic assumption. For ecosystems such as Solana, the challenge is to build defenses that are resilient even when users, teams and partners face increasingly sophisticated deception.

Frequently Asked Questions (FAQs)

What did Solana Foundation CISO Michael Coates warn about?

Michael Coates warned that crypto’s biggest security threats are increasingly coming from AI-powered social engineering, fake identities and compromised credentials, not only from smart contract exploits.

Why are AI scams a major concern for crypto?

AI can make scams more convincing by helping attackers create realistic messages, identities and deepfake communications. Coates has warned that spoofed phone calls using familiar voices could become a serious threat.

Are smart contract exploits still a risk?

Yes. Smart contract vulnerabilities remain important, but Coates emphasized that many crypto incidents also begin outside the blockchain through operational security failures or Web2-style compromises.

What does compromised credential risk mean in crypto?

It means attackers may gain access to accounts, keys, systems or communications that allow them to move funds, impersonate trusted parties or manipulate internal processes without directly exploiting blockchain code.

How does Solana fit into this security discussion?

The Solana Foundation is working to secure itself while helping ecosystem projects improve security practices. It is also engaging with regulators on cybersecurity standards and evaluating post-quantum cryptography.

What is post-quantum cryptography?

Post-quantum cryptography refers to cryptographic methods designed to remain secure against future quantum computing threats. Coates has said adopting post-quantum algorithms is the known path for quantum readiness.

What does “Q-day” mean?

“Q-day” refers to the uncertain future moment when quantum computing could become powerful enough to threaten current cryptographic systems. Coates has said the timing is unknown.

Why are secure defaults important for crypto users?

Secure defaults help protect users without requiring them to act like security experts. Coates argues that crypto should meet users where they are and make the safer choice the default option.

What is the main market takeaway?

The main takeaway is that crypto security is expanding beyond code audits. AI-driven deception, credential theft, operational controls and quantum readiness are becoming central to how blockchain ecosystems manage risk.

Photo by https://kaboompics.com/ on Pexels