Loading article…
Malcolm Portelli, Coinflow’s CISO, discusses rising APT targeting, AI‑generated vulnerabilities and evolving fraud defenses for crypto payments.
Crypto payment firms are now prime targets for advanced persistent threat groups, and the pressure on security leaders is intensifying as AI tools accelerate vulnerability discovery [1]. Malcolm Portelli, CISO of Coinflow, explained how his threat model is shaped more by the industry’s financial‑services and Web3 nature than by geography, and outlined the company’s shifting defenses against AI‑enabled attacks.
Key takeaways
Portelli says the crypto and Web3 landscape dictates the security posture more than the fact that Coinflow’s security team operates from Malta. “Crypto is a big target, especially for the big APTs,” he noted, emphasizing that threat actors focus on firms handling digital money [1]. To keep pace, Coinflow has revamped its awareness program: monthly video snippets were deemed a compliance checkbox and discontinued in favor of quarterly, concise training sessions capped at 30 minutes, supplemented by more engaging formats [1].
The rise of AI tools is reshaping both attack and defense. Portelli highlighted Mythos, an AI‑driven vulnerability discovery system that uncovered numerous issues in Firefox, and TrendAI research that identified roughly 300 vulnerabilities in popular WordPress plugins at a cost of about $20 per zero‑day [1]. While defensive AI helps flag these flaws, automated patching that preserves functionality remains a challenge, leaving many CISOs with growing backlog of unaddressed findings [1].
On the fraud front, attackers have shifted toward social‑engineering scams that persuade customers and staff to approve payments themselves. Coinflow counters this by deploying AI‑based anomaly detection to flag suspicious transactions and maintaining continuous education for employees and end users, while also leveraging multi‑factor authentication for API keys to secure the primary integration point [1].
Portelli’s insights illustrate a broader trend: crypto‑payment providers must adapt to an environment where AI accelerates both vulnerability discovery and sophisticated fraud schemes. By aligning board communication with financial impact data and modernizing awareness training, Coinflow aims to stay ahead of attackers. However, the gap between AI‑generated findings and effective remediation tools suggests that many firms will continue to face mounting pressure over the next few years, underscoring the need for faster patching solutions and robust API security practices.
Coverage is mostly measured — 122 of 128 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 4 outlets · May 31, 2026 · How we report
It allows Bitget Wallet users to connect directly to Mesh’s network, facilitating fund transfers and purchases without copying addresses or switching apps.
The law permits crypto only for international trade, bans domestic crypto payments, imposes a licensing regime, and excludes privacy coins such as Monero, Zcash, and Dash.
The inquiry aims to determine whether banking barriers that limit crypto firms’ access to accounts and payments could undermine the UK’s goal of becoming a global leader in digital assets.