
Binance fires employees who repeatedly fail phishing simulations testing for social engineering attacks. 65% of crypto breaches in 2025 came from such tactics.
Binance is terminating employees who repeatedly fail internal phishing simulations, Chief Security Officer Jimmy Su said in an interview. The world's largest crypto exchange has run monthly red-team exercises for three to four years, testing whether staff can spot social engineering attacks before real hackers exploit them.
The program covers $137.7 billion in assets and 323 million registered users. Su said the human layer of the security stack is the most exposed. The simulations are not generic click tests. They mirror current attack playbooks.
One scenario impersonates job recruiters. Attackers in the wild contact employees with fake offers, build rapport, then push malware or credential-harvesting links. Binance's red team runs the same play and watches who takes the bait, Su said.
Another simulation involves fake conference invitations. Employees receive invites to a fictitious event. The test measures whether they hand over personal information to claim a spot. Su called it a basic lure that still works in real-world attacks.
The most sophisticated test mimics a Zoom meeting attack. An attacker tricks someone into downloading what looks like a routine software update. It is malware. The victim installs it themselves. Binance checks whether employees pause before clicking on an unsolicited prompt, Su said.
Poor results on these tests feed directly into performance evaluations. A pattern of failures pushes an employee's rating down. A low enough rating means termination. Su said that is not a vague threat. It is policy.
The logic is not punitive. Social engineering accounted for 65% of crypto security breaches in 2025, according to AMLBot. The incidents back up the number. Drift Protocol lost $285 million through a social engineering campaign. A Venus Protocol user lost roughly $13 million after attackers compromised a Zoom client. Venus paused operations and recovered most of the assets. Most is not all, Su said.
No firewall stops a social engineering attack, he said. An employee clicks one bad link on a Tuesday afternoon, and the best technical infrastructure in the business can still get cleaned out. That is why Binance built security awareness into how people are evaluated, compensated, and retained. Employees who consistently pass are recognized. Those who fall short face real career consequences. The simulations rotate to reflect how threats evolve, so employees cannot memorize one set of warning signs and coast, Su said.
Whether other exchanges adopt similar programs is unclear. Most have not said publicly. With $137.7 billion on the line and 323 million users trusting the platform, Binance's answer to the social engineering problem is direct: make it someone's job to care, then make sure they know their job depends on it.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.