
Binance runs monthly phishing simulations on its staff and fires repeat failures. Social engineering drives 65% of crypto hacks, making red-team tests a key defense for the exchange.
Binance runs simulated phishing attacks against its own employees and can fire staff who repeatedly fail the tests, according to chief security officer Jimmy Su.
The fake attacks are conducted by Binance's red team, an internal ethical hacking unit whose job is to break into systems to identify vulnerabilities. Su told Cointelegraph the exchange does phishing tests on a monthly basis to check whether security hygiene is improving. Employees who fail get remediation training. Repeated, severe failures could lead to dismissal, he said.
The measure shows the lengths crypto companies go to prepare for social engineering attacks. In February, AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering. In April, Drift Protocol suffered a $285 million hack after a long-term social engineering campaign.
Su said Binance has been running these simulated attacks for three to four years. One of them involves the red team posing as job recruiters. Another involves offering a free conference invite to collect personal information. The results are reflected in performance reviews, giving employees a financial incentive to stay alert.
One of the more well-known attack methods in recent years has been the “Zoom meeting attack,” where hackers trick victims into installing malware disguised as an update to the video conferencing app. Many of these attacks start with a fake job opportunity, though some use project funding or a partnership proposal as the lure. In September 2025, a major Venus Protocol user lost roughly $13 million after a malicious Zoom client compromised his computer, leading him to grant an attacker control over his account. Venus paused the protocol and used an emergency governance vote to recover the assets, later returning positions worth $11.4 million to the victim.
Social engineering attacks are not limited to external actors. The Binance program targets internal weaknesses, a strategy that other exchanges have adopted. The risk is that even sophisticated security systems can be bypassed if an employee opens the wrong link or shares credentials with a convincing impersonator.
Su said the interview scenario is just one of several. The red team also tests staff with fake conference invitations, attempts to collect personal information, and measures how many employees fall for each ruse. The broader industry context is that crypto platforms hold billions in assets but remain vulnerable to the oldest trick in the book: trusting the wrong person.
(Note: This article includes reporting from Cointelegraph.)
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.