
Binance tests employees with fake phishing attacks monthly, targeting social engineering risks that caused 65% of crypto losses in 2025, according to AMLBot.
Binance runs simulated phishing attacks against its employees every month to reduce the risk of social engineering, the exchange's chief security officer said.
Jimmy Su, Binance's chief security officer, said the company's red team creates fake attacks to test whether staff recognise suspicious links and requests. Employees who fail must complete follow-up training. Repeated failures can affect performance ratings and may lead to dismissal, Su said.
The programme targets human errors that attackers use to enter crypto companies. Binance has operated the drills for three to four years, Su said. He said the company's security habits had improved during that period. Binance reports 323 million registered users, while DefiLlama tracks about $137.5 billion in assets linked to the exchange.
The red team uses methods that resemble real attacks. One test may present a fake recruiter offering a job. Another may promise free access to a conference and request personal details. The team records whether employees open the message or follow a link. Sharing information that could expose company systems is also tracked.
Su said workers who fail receive remedial training. Repeated failure "will negatively impact their rating," he said. Severe cases may push a worker's rating to the lowest level and result in dismissal. The policy gives employees a direct work-related reason to verify unexpected messages before responding.
Binance has described its red team as an internal group of ethical hackers that tests systems from an attacker's point of view. The exchange also works with external researchers through bug bounty programmes, Su said. Its security model covers technical weaknesses and employee behaviour because attackers may enter through trusted accounts or devices.
The drills come as social engineering causes a large share of reported crypto losses. AMLBot reviewed more than 2,500 investigations and found that 65% of the cases it handled in 2025 began with social engineering rather than direct software exploits. Phishing represented 18% of its cases, while device compromise accounted for 13%.
Attackers often spend days or months building trust before asking a target to open a file or approve a wallet request. This method can defeat technical controls when a worker has access to private keys or administrator accounts. Stolen credentials can lead directly to liquid assets that move across blockchains within minutes.
The April 2026 attack on Drift Protocol drained about $285 million after attackers compromised an administrator key, researchers said. They linked the breach to social engineering and operational security failures rather than faulty smart contracts. The attacker changed market settings and withdrawal limits before removing assets across dozens of transactions.
A Venus Protocol user lost about $13.5 million in September 2025 after approving a malicious transaction. Venus paused its lending platform and recovered the assets through an emergency governance process. The case showed how a user-level compromise can place assets at risk even when a protocol's contracts remain intact.
Su identified fake job interviews as one scenario used in Binance's tests. Real attackers use the same approach against developers and executives. They may move a conversation from LinkedIn or Telegram into a video meeting, then claim that the victim's camera or microphone needs an update.
North Korea-linked hackers have used compromised Telegram accounts and deepfake Zoom calls to contact crypto professionals, according to reports. The attackers impersonated known contacts and asked victims to install files that claimed to fix audio problems. Those files instead delivered malware capable of accessing devices, browser data and crypto wallets.
Monthly simulations let Binance compare failure rates and update training when attackers change their methods. A single annual course may not prepare staff for new lures built around current events or trusted contacts. Frequent tests also show whether workers report suspicious messages instead of only deleting them.
That approach cannot remove every risk. Attackers can hijack genuine accounts or copy earlier conversations. They use artificial intelligence to create convincing audio and video messages. Firms still need access controls, transaction limits, device monitoring and fast incident response alongside employee training.
Su said Binance's early security habits "left a lot to be desired," but repeated testing brought improvement. The exchange treats staff awareness as part of its wider defence system rather than a one-time compliance task. Employees still need to verify unusual requests through a separate channel before opening files or approving transactions.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.