Michael Coates, Twitter’s former chief information security officer, joined the Solana Foundation as its first CISO in July 2026, citing AI-driven cybercrime as the network’s top emerging security threat.
Coates, who previously served as Twitter’s first CISO and held senior security roles at Mozilla, joined the Solana Foundation in July 2026 as the blockchain network expands its role in stablecoins, tokenized assets and institutional financial infrastructure.
In announcing the appointment, he warned that criminals have a powerful incentive to separate users from their digital assets and highlighted the rising malicious use of AI as a major security challenge.
The warning arrives as regulators and law-enforcement agencies document a broader escalation in AI-assisted fraud.
The FBI said Americans reported more than $11 billion in cryptocurrency-related losses in 2025, while AI-related complaints accounted for nearly $893 million in reported losses.
The agency said scammers were using fake social profiles, cloned voices, identification documents and convincing videos to make fraudulent schemes appear legitimate.
AI is changing the economics of crypto fraud
Crypto scams have long depended on social engineering: a fraudulent investment opportunity, a fake exchange representative, a compromised social-media account or an impersonation of a prominent industry figure.
Generative AI makes those tactics easier to execute and harder to recognize.
Scammers can use AI tools to produce polished messages, replicate communication styles, generate synthetic images and create increasingly realistic voice or video impersonations.
In an industry where transactions can be irreversible and users frequently interact with anonymous accounts, the combination creates a particularly difficult security environment.
The FBI’s 2025 Internet Crime Report illustrates the scale of the problem.
The agency recorded more than 1 million complaints overall and said cryptocurrency-related complaints generated the highest reported losses among the categories tracked, exceeding $11 billion. Investment fraud remained the largest source of scam-related losses.
The problem is not confined to crypto-native platforms. The Federal Trade Commission reported that consumers lost $3.5 billion to impersonation scams in 2025, nearly triple the reported losses recorded in 2020.
Impersonators reached victims through text messages, phone calls, email, social media and search results.
Solana is treating human trust as a security problem
The appointment of Coates reflects a broader shift in how the Solana ecosystem is approaching security.
In April, the Solana Foundation launched additional security initiatives following a $270 million exploit involving Drift Protocol.
The foundation introduced STRIDE, a security evaluation program for Solana DeFi protocols, alongside the Solana Incident Response Network, a group designed to improve coordination among security firms and researchers during incidents.
The Drift incident was particularly instructive because the underlying smart contracts were not simply defeated by a conventional coding vulnerability.
Attackers reportedly used a prolonged social-engineering campaign to compromise contributor devices and obtain legitimate approvals.
Blockchain security can verify whether a transaction is valid according to protocol rules. It cannot automatically determine whether the person approving that transaction has been manipulated by an attacker.
Coates’ mandate therefore arrives at a moment when the industry is confronting a broader definition of security, one that includes applications, users, developers, social platforms and the communications surrounding financial transactions.
His priorities include strengthening operational and application security, addressing crypto-specific threats and working with policymakers and standards bodies on cybersecurity rules.
“Security is hard,” Coates said, arguing that the industry needs to build stronger security practices as crypto infrastructure becomes more deeply integrated with traditional finance.
The deepfake threat is already familiar To crypto
Crypto has already experienced waves of deepfake-driven impersonation campaigns involving prominent founders and industry personalities.
In one widely reported case, a fake video appeared to show Solana co-founder Anatoly Yakovenko promoting a cryptocurrency giveaway. The campaign used synthetic video and directed users toward a fraudulent website.
Solana Foundation executive Austin Federa previously warned of a “substantial increase in deepfakes and other AI-generated content.”
A familiar face is no longer proof that a video is genuine. A recognizable voice is no longer proof that a caller is authentic. Even professionally written investment communications can be generated automatically.
The FBI has specifically warned that criminals are using AI-generated material to make fraudulent identities and investment opportunities more believable.
Its latest report also urged people to slow down rather than respond immediately to pressure from suspected scammers.
“Limited-time” token sales, urgent wallet warnings, airdrops and investment opportunities can all be designed to prevent victims from independently verifying what they are being told.
Security is becoming a core crypto investment issue
The rise of AI-enabled scams could ultimately force investors and institutions to reconsider what they mean by security.
For years, crypto security discussions have focused heavily on private keys, smart-contract audits, exchange custody and blockchain infrastructure. Those remain essential. But the attack surface is increasingly extending into the human layer surrounding the technology.
That shift is especially significant for Solana as the network pursues institutional adoption and expands into tokenized assets and stablecoin payments.
The foundation itself has emphasized the network’s growing financial activity. Coates cited Solana’s large stablecoin volumes, transaction activity and expanding tokenization ecosystem as reasons for taking the security role.
The greater the value moving through an ecosystem, the greater the incentive for sophisticated attackers to target its users.
For investors, the practical lesson is straightforward: blockchain verification cannot replace human verification. Users should independently confirm wallet addresses, domain names, transaction requests and claims made through social media or private messages before moving funds.
AI may help security teams identify malicious activity faster, but the same technology is lowering the cost of producing convincing deception.
The next generation of crypto scams may not look like obvious fraud. They may arrive with polished language, convincing identities, synthetic voices and apparently authentic video—all engineered to make a fraudulent transaction feel routine.
As crypto becomes financial infrastructure, the battle over trust is moving beyond the blockchain itself.