{"id":258870,"date":"2026-05-29T12:00:00","date_gmt":"2026-05-29T16:00:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/05\/29\/coinbase-head-of-security-the-ai-arms-race-has-started-and-most-companies-arent-ready\/"},"modified":"2026-05-29T12:45:14","modified_gmt":"2026-05-29T16:45:14","slug":"coinbase-head-of-security-the-ai-arms-race-has-started-and-most-companies-arent-ready","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/05\/29\/coinbase-head-of-security-the-ai-arms-race-has-started-and-most-companies-arent-ready\/","title":{"rendered":"Coinbase head of security: The AI arms race has started and most companies aren&#8217;t ready"},"content":{"rendered":"<p><a href=\"https:\/\/fortune.com\/2026\/05\/29\/the-ai-arms-race-in-cybersecurity-has-already-started-most-companies-arent-ready\/\">Coinbase head of security: The AI arms race has started and most companies aren&#8217;t ready<\/a><\/p>\n<p><a href=\"https:\/\/fortune.com\/2026\/05\/29\/the-ai-arms-race-in-cybersecurity-has-already-started-most-companies-arent-ready\/\">https:\/\/fortune.com\/2026\/05\/29\/the-ai-arms-race-in-cybersecurity-has-already-started-most-companies-arent-ready\/<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-05-29 12:00:00<\/a><\/p>\n<p>Source Domain: <a href=\"fortune.com\">fortune.com<\/a><\/p>\n<p>In 2019, sophisticated hackers spent weeks targeting Coinbase employees with emails from compromised Cambridge University accounts. The attackers patiently built trust before deploying a pair of chained zero-day exploits\u2014a term that describes undiscovered software vulnerabilities\u2014that took aim at the Firefox browser. One exploit sought to break into the browser, and the other sought\u00a0to execute malicious code on the host machine. At the time, it was among the most advanced attacks ever directed at the corporate sector.\u00a0<\/p>\n<p>The Coinbase security team caught it within hours after an employee report and automated alerts fired simultaneously. This allowed us to identify the malicious behavior. Response times measured in minutes, no customer funds lost. But I think about that incident differently now. The attacker needed weeks of social engineering and rare zero-days to get one shot at us. An AI-driven adversary wouldn\u2019t need weeks. It might not even need hours. And that\u2019s the world I\u2019m preparing for today.<\/p>\n<p>The last few months have made something clear that security teams across industries have been quietly preparing for: AI is and will continue to change how cyberattacks occur. Since the form of this change is still taking shape, the hardest part of my job right now is planning for threat models that don\u2019t fully exist yet.<\/p>\n<p>Frontier AI models, such as those being built by Anthropic, OpenAI, and others, have crossed a capability threshold in cybersecurity that would have seemed speculative eighteen months ago. These systems can read a codebase the way an experienced auditor reads a codebase, but with the speed, memory and focus of a machine. One recent model found a 27-year-old bug in OpenBSD, one of the most audited codebases on the planet. That\u2019s a structural shift in what\u2019s possible.<\/p>\n<p>Today, that shift favors the defender.\u00a0<\/p>\n<p>Security is, in large part, a context problem. Defenders usually know more about their own systems than attackers:&#8230;<\/p>\n<p><a href=\"https:\/\/fortune.com\/2026\/05\/29\/the-ai-arms-race-in-cybersecurity-has-already-started-most-companies-arent-ready\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Coinbase head of security: The AI arms race has started and most companies aren&#8217;t ready&#8230;<\/p>\n","protected":false},"author":1,"featured_media":258871,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/fortune.com\/img-assets\/wp-content\/uploads\/2026\/05\/Philip-Martin.jpg?resize=1200,600","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[20,57],"class_list":["post-258870","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-artificial-intelligence","tag-security"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/258870"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=258870"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/258870\/revisions"}],"predecessor-version":[{"id":258872,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/258870\/revisions\/258872"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/258871"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=258870"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=258870"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=258870"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}