Solana CISO Warns AI Is Raising Crypto Scam Risk
Solana Foundation CISO Brian Coates is warning that crypto security failures are increasingly starting outside smart contracts, as AI makes fake identities and social-engineering attacks more believable.
In an interview with CoinDesk, Coates said recent ecosystem incidents show how attackers can reach keys through operational security failures, Web2 account compromise, and convincing impersonation rather than exploiting on-chain code. The distinction matters because audits and protocol-level testing may not catch a compromised employee account, vendor workflow, or private key before funds move.
Beyond contracts
The Solana Foundation describes its role as supporting decentralization, adoption, and security across the Solana ecosystem. Coates' comments put more weight on the off-chain side of that work: identity checks, access controls, incident response, and education for teams that may be targeted by AI-assisted phishing or fabricated counterparties.
The warning lands as crypto teams also revisit longer-term cryptography risks. Solana's own quantum-readiness post says quantum threats remain years away, but that client developers have studied post-quantum migration paths and are evaluating Falcon-style signature schemes if a credible threat emerges.
Why it matters
For users and protocols, the immediate risk is less exotic than quantum computing. AI can lower the cost of personalized scams, fake hiring or partnership approaches, and support-channel impersonation. That makes key management and operational controls part of core crypto infrastructure, not just back-office hygiene.
The conservative takeaway is that stronger smart contracts do not remove the need for stronger human and organizational security. Attackers may simply move to the weaker path.