CISO @SolanaFndn | Cyber Investing Seven Hill Ventures - Former: CISO @Twitter, @Mozilla, @Coinlist, Chairman @OWASP, Startup Founder (Acquired)

San Francisco, CA
Pinned Tweet
Honored to testify to Homeland Security and joint session on AI, Quantum and Cybersecurity. Full info below
10
33
3,330
Michael Coates retweeted
Everyone is coming to Solana. 𝕏 integrated Solana. XRP expanded to Solana. Visa is settling on Solana. Mastercard supports Solana. Chiliz expanded to Solana. Bitget integrated Solana Pay. Stripe supports payments on Solana. PayPal launched PYUSD on Solana. Cash App supports USDC on Solana. Coinbase integrated Solana DEX trading. BlackRock brought BUIDL to Solana. J.P. Morgan has used Solana for tokenized commercial paper. Franklin Templeton brought BENJI to Solana. Ondo brought 200+ tokenized stocks & ETFs to Solana. Western Union launched USDPT on Solana. MoneyGram integrated Solana. VanEck brought VBILL to Solana. What's next?👀
117
254
1,204
28,602
Michael Coates retweeted
I really don't think people are understanding the @HacktronAI HEIF Heist moment properly. Before AI, what class of attacker do you think would be capable of discovering a silently fixed upstream image parser vulnerability w/o a CVE assigned nor patched in distro packages, exploiting against modern Linux w/ ASLR, and then using it to pop top-tier tech companies w/o them noticing? I have *never* seen bug bounty researchers land something like that. Have you?
23
24
240
52,141
Michael Coates retweeted
Lily Hansen-Gillis of @tetradigitalgrp on why they brought Canada's first regulated stablecoin to Solana. "We didn't pick Solana for speed. It's not just a network for retail. It's a network we can take to a large institution considering onchain rails for how they manage their finances. If they want to settle in CADD, Solana is a very viable option."
Superteam Canada
107
102
724
121,873
Michael Coates retweeted
Rachel Conlan, Chief Strategy Officer at the Solana Foundation, on the token supercycle. "As I look at Solana, not just the developers but the broad range of projects, and the centerpiece it occupies in the ecosystem, it's at that juncture of being part of the next stage: the total reimagination and rebuilding of financial infrastructure. We're now in the stage of becoming part of the technology layer of the future of finance." @RachelConlan @FINTECHTVglobal @RemyBlaireNews
111
117
817
126,523
Michael Coates retweeted
Private researcher reported a security vulnerability to Chromium on August 4. The fix went into the public source code but Chrome users never got it due to patching timelines. Two Chinese groups, apparently read that public fix, built an exploit chain from it and started phishing NGOs on September 1 using identical code. Technically an N-day but for anyone actually running Chrome, a zero-day. Here the public patch knowledge worked as an instruction manual. Open source means everyone can read the fix. With AI, some people just operationalise the knowledge faster. volexity.com/blog/2026/09/09…
16
61
297
27,858
Michael Coates retweeted
Frontier Traders Season 1 is live. $1M+ in rewards. 8 weeks of trading. Eight finalists. One World Champion, crowned live in London this November. frontiertraders.com/seasons/…
125
77
655
277,441
While hands in front of face may catch some deepfakes, there’s a more important lesson here. Don’t clone and run untrusted code on your machine. Ever. Use ephemeral dev boxes/VMs.
Had an "interview" for a blockchain project last week. Camera was on, we're chatting, and the guy tells me to clone a GitHub repo and run it locally before we go further into the technical round. I said sure, but first can you do me a favor hold up 3 fingers in front of your face for me real quick. He froze. Didn't move. Just sat there for a few seconds before the call cut off and he blocked me. That's when I knew. A real interviewer doesn't glitch out over a random ask like that. A deepfake/AI overlay does. These "run this repo" scams are getting scary common in crypto and dev hiring right now. The setup is always the same: - flattering DM - real-sounding project - rushed timeline - a "quick step" before the call that's really just remote access or a credential stealer in disguise. If someone wants you to run code or install something before you've even had a real conversation, that's the whole scam. Trust the instinct. Stay safe out there.
419
Michael Coates retweeted
I’ve joined @SolanaFndn as Chief Strategy Officer. What excites me is Solana’s position to bring Internet Capital Markets to life: connecting assets, trading and payments on one global network, open to anyone, around the clock. You can already see it happening: $200M in tokenised equities traded in a single day, with roughly 63% outside US market hours. My focus is helping drive the next phase of growth, bringing more institutions, enterprises, builders and users into that opportunity. Thank you to @calilyliu and the team for the warm welcome. Excited to get going. 💜 coindesk.com/business/2026/0…
366
66
1,144
233,288
Michael Coates retweeted
The @SolanaFndn just open-sourced Microscope, a free monitoring & alerting tool for Solana programs. We've tested it out. Its skills map alerts to our STRIDE security framework so the responding team has context to start from during an incident. github.com/solana-foundation…
11
44
221
33,957
Michael Coates retweeted
Letters of marque and reprisal might be our best chance against cybercrime. I spoke with security and legal experts, plus former DOJ and military for this @LawofCodeFM episode on cyber letters of marque. Featuring @ARedbord of TRM, @perkinscr97 of Franklin Crypto, @_mwc of Solana Foundation, @NelsonMRosario of Rosario Tech Law, and Camelia Lopez Shoemaker of Holland & Knight. This covers the role of these letters in the American Revolution, privateers, prize courts and a White House memo that trends toward implementing a modern version for cyberspace. Timestamps: 0:00 The $200 billion problem 2:16 The Model T and the FBI 4:18 Pig butchering 7:03 History 7:50 The high seas and the internet 8:30 Marque vs. reprisal 11:35 American Revolution 14:08 Building a (private) navy 17:25 The Constitution 18:40 The Paris Declaration 20:34 Pirates or privateers? 22:12 The five-part system 22:40 Why government can't scale 23:30 The Fourth Amendment 25:26 Suspicious Activity Reports 28:23 Recent memorandum 30:40 The bond 32:34 The blockchain 33:49 Latest from U.S. gov't 34:56 The attribution problem 36:30 Who's involved today? 37:49 The Beacon Network 39:16 Pre-clearance and due process 41:10 Reporting cybercrime 44:26 International law Thank you to the presenting sponsor of this episode, @altitude. Nothing in this podcast is legal or investment advice.
2
5
12
3,338
Mempool scanners: now front-running hackers too
A hacker found a way to drain $7.8M from an Ethereum wallet. Then another bot hacked the hacker before the hacker could even take out the funds. The attacker found a bad permission setup in a Safe wallet holding around 2,900 rsETH. The exploit worked. But he made one mistake: He sent the transaction through Ethereum's public mempool. A bot called Yoink saw the pending transaction, copied the exploit and paid about $47,000 to get its transaction processed first. The hacker's transaction came afterwards and failed because the money was already gone. Yoink walked away with roughly 2,882 rsETH worth $7.8M. The original hacker got basically nothing from the main exploit. But there's another funny part. Yoink sold 17.63 rsETH for 18.95 ETH during the transaction. Then immediately sent 18.93 ETH to the block builder to win the race. So the bot basically spent almost the entire first chunk of stolen money just to make sure it could steal the remaining millions before the actual hacker.
1
1
12
1,344
Crypto peeps - a reminder that the oath to compromise crypto projects isn’t always onchain. Path of least resistance is often targeted. Be sure you have solid procedures whenever someone internal requests a password reset. The “I’m locked out of my account” + deepfake or spoofed callerID / email is a common and often successful attack vector
1
5
381
Best practices is out of band confirmation of password reset with consideration to deepfake attacks. Immediate flags - can’t go on video - video is oddly choppy - extreme urgency for the request
89
Michael Coates retweeted
Scammers found a way to make people drain their own wallets without sending them a phishing link. They uploaded YouTube tutorials showing people how to build an AI crypto trading bot with Claude. People followed the tutorial themselves. Copied the code. Deployed the smart contract themselves. Funded it from their own wallets. And approved every transaction themselves. Except the “trading bot” had no trading logic. It was built to send their ETH straight to the scammers. 224 wallets lost 274.6 ETH, worth about $517,000 when it was stolen. The median victim lost 1 ETH. Some victims even got an error after getting drained telling them to deposit another 50% to fix the bot. They literally got people to build, fund and approve their own wallet drainer. You've got to be very careful this days
576
1,253
7,972
711,965
This is the messy middle. A moment in the transition from old to new. The free market will play out here with many impacts. If this works for the company bottom line, they’ll keep leaning in. Talented developers may leave but if it works, it works. This will butt up with inevitable friction on quality, compliance, security. But those things too are largely solvable in most generic software. This will commoditize software creation for the general use case into something that looks far different than 12 months ago. Then there’s a reckoning on where the “developers” go. The “just press enter” work will go to the lowest cost because the skill set needs drops. The high value engineering work shifts to orchestrating the automation. An “AI software architect” or such And none of this applies to high risk critical systems Those systems will have the most interesting transition with a huge push and pull between wanting to adopt AI coding for efficiency and the critical need for precision. We’ll see an adoption of ai coding to be sure, but more likely increasing use of ai for all of the safety checks around every step (ai security reviews per PR, formal verification, continuously maintained end to end threat models etc). But again, we’re in the messy middle. Embrace, learn, and leverage capabilities vs just being mindless cog in the machine.
I am done with this shit. It is over. The state of engineering right now is horrible. It has been half a month since I started a new role at a big company. Nobody knows anything here. The specs, code, tests, PRDs, tickets, resolution of those tickets, reports, etc., everything is made by Claude Code. Nobody on my team likes this. They are being forced to ship as much as they can. I have heard multiple times from higher management that pushing code is not a bottleneck, so why are we slow? People are working 12 to 13 hours a day just to press enter. Nobody is reading anything. Humans in corporate are doing nothing on their own. Everyone, literally everyone, from an L1 to an L7 engineer here is doing the same thing. Talk to Claude. There is no sense of victory. Nobody is resolving bugs. In reality, nobody is thinking anymore. Everything is done by LLMs. It is so soul-sucking. I would not mind it, to be honest, if we were at least given the time to check out the code and see what is going where. But no, the goal is to just ship. No matter what happens.
1
3
613
1/ The @SECGov just issued an innovation exemption for onchain securities trading. This framework has the potential to move trillions of dollars in existing financial assets onto “public, permissionless” blockchains like @solana, positioning the US as the home of internet capital markets.
1/4 📢 @solanainstitute, @superstatefunds and @orca_so, with support from @LowensteinLLP, have submitted a proposal to the SEC – dubbed Project Open – for a pilot project to enable the issuance and trading of equity securities on public blockchain networks like @solana.
8
11
55
17,349
Michael Coates retweeted
The "whiteboard defense:" I should be able to pull you aside at any moment and ask you to explain any customer-facing system you've shipped. You should be able to clearly explain how it works and defend the decisions you made. This is my benchmark for responsible AI usage. I don't expect line-level familiarity with the code. I don't care if you remember the exact function name or implementation detail. You may not even know it. I don't care. But if I ask "why did you do X instead of Y?", "what happens if this actor behaves maliciously?", "what data structure did you use here and why?", or "where does this fail?" you should be able to answer confidently. For PoCs, demos, experiments, whatever: I don't care. Generate 100% of it and understand none of it. Speed over quality every time in those specific scenarios. But if you're shipping customer-facing work, you can't be shipping things you don't understand at a high level.
232
977
9,329
477,385
RT @toly: Yes, this is disappointing. Yes, the USA remains one of the last g20 economies without a crypto bill. The tiny sliver of silver…
38
16
Yes. This ⤵️
😳 Brad Gerstner on the ex-Anthropic researcher who told America AI could end humanity in three years: "To go on national television in a highly coordinated way and sit in the living room on NBC, on ABC, on CBS, on Fox, and have a single researcher who spent six weeks at Anthropic tell the moms and dads of America that this can kill all of humanity in the next three years without any countervailing conversation is deeply irresponsible. Jensen Huang yesterday called it deeply untrue. Andrew Feldman, the founder of Cerebras, who spent decades studying this, called it utter horseshit. Elon himself said it was a coordinated psyop." - @altcap with Scott Wapner @TheJudgeCNBC on CNBC Friday, Sept 11th, 2026
2
1,056