AI-Powered Crypto Scams Are Getting Dangerously Convincing, and Bitcoin Isn't Immune
The biggest security threat to cryptocurrency right now isn't a hacked smart contract or a broken bridge; it's a phone call that sounds exactly like your boss. That's the warning from Michael Coates, the Chief Information Security Officer at the Solana Foundation, who says artificial intelligence is making crypto scams so convincing that even careful users can fall victim. The danger has little to do with any flaw in blockchain technology itself, but rather how attackers are exploiting human psychology and trust.
Why Are AI-Powered Crypto Scams So Effective?
Crypto scams aren't new, but AI is making them dramatically more effective. Traditional phishing emails full of typos and awkward phrasing are being replaced by polished, personalized messages generated in seconds. Scammers can now create realistic fake identities, adapt scripts in real time to match specific targets, and even clone voices to impersonate trusted colleagues or executives.
The stakes in cryptocurrency are unusually high because transactions are instant and irreversible. If a user signs a malicious transaction, hands over a seed phrase, or approves the wrong wallet connection, funds disappear permanently. There's no chargeback, no password reset, and no central authority capable of reversing anything. This finality makes social engineering attacks far more dangerous in crypto than in traditional finance.
"The social engineering piece is going to get a lot worse because of the power of AI and deepfakes. We should expect full spoofed phone calls with voices of people that we know," warned Michael Coates, Chief Information Security Officer at the Solana Foundation.
Michael Coates, Chief Information Security Officer at the Solana Foundation
Coates, who previously served as Chief Information Security Officer at Twitter and led security efforts at Mozilla, joined the Solana Foundation earlier this year. His role spans securing the foundation itself, working with ecosystem projects on security practices, and meeting with regulators on cybersecurity standards.
How Are Attackers Targeting Crypto Teams and Users?
The threat doesn't stop at individual users. Crypto teams and organizations face equally convincing attacks designed to compromise credentials and trick employees into approving harmful transactions. Attackers impersonate fake vendors, investors, journalists, job applicants, or internal colleagues to gain access to sensitive systems or treasury controls.
Coates emphasized that the vulnerability isn't in Solana's blockchain or smart contracts, but in the human layer surrounding them. "In many cases, it is an operational security issue or a Web2 issue that led to a key compromise," he explained. In other words, attackers aren't breaking the chain; they're breaking the people who manage it.
Coates
The problem is amplified by how mainstream crypto networks have become. Solana has attracted consumer applications, decentralized finance (DeFi) operations, meme coin markets, NFT platforms, payment initiatives, and user-friendly mobile solutions, all of which widen the pool of everyday users who could be targeted through fake mints, fake airdrops, malicious token approvals, impersonation accounts, or wallet-draining websites.
How to Protect Against AI-Enhanced Crypto Scams
Telling people to "be careful" is no longer a viable security strategy when fake links look identical to real ones, cloned voices sound authentic, and fraudulent support accounts respond faster than genuine ones. Instead, Coates advocates for systems designed to be secure by default, rather than systems that depend on flawless human judgment every single time.
- Wallet Design: Implement wallets that make risky approvals clearer to users and reduce the need for blind signing, where users approve transactions without understanding what they're authorizing.
- Protocol Permissions: Design protocols that limit permissions and reduce the damage a single compromised account can cause.
- Exchange Controls: Tighten withdrawal controls and verification procedures to catch suspicious activity before funds leave the platform.
- Organizational Procedures: Use out-of-band verification for sensitive requests, multisig discipline for treasury actions, hardware security keys, strict access controls, and rigorous internal checks before any significant transaction.
- Layered Defenses: Build multiple layers of security so that when someone falls for a scam, other protections can still activate to limit the damage.
Coates was blunt about the limits of relying on individual caution alone. "You cannot fully prevent anyone from falling victim. Eventually, you will be fooled because the cons are that good," he stated. His answer isn't to demand perfect vigilance from every user, but to build systems where mistakes don't automatically result in permanent losses.
The warning applies broadly across all crypto ecosystems, not just Solana. "You have to do everything that a Web2 company has to do for security, and the incremental uniqueness to Web3," Coates noted, emphasizing that "when you have adversaries that are definitely motivated and can take funds irrevocably, they are going to look for any mistake".
As AI continues to narrow the gap between real messages and fake ones, procedural guardrails and secure-by-default design become the difference between a close call and a permanent loss. For Bitcoin, Ethereum, Solana, and every other blockchain network, the real security battle isn't happening at the protocol level; it's happening in the spaces where humans interact with technology.