
Binance's internal red team simulates social engineering attacks on staff for over three years. Employees who fail repeatedly face dismissal. The program targets the 65% of crypto security incidents caused by social engineering.
Binance simulates phishing attacks on its own employees every month, and those who keep failing the tests face dismissal. The world's largest crypto exchange has been running the internal red team program for more than three years, Chief Security Officer Jimmy Su said.
The simulated attacks mirror real social engineering tactics, including fake job recruiter messages and conference invitations designed to trick employees into revealing sensitive information or clicking malicious links. Staff who take the bait go through remedial training. Repeated failures affect performance ratings. Chronic offenders are terminated, Su said.
Social engineering accounts for roughly 65% of all crypto security incidents in 2025, according to a report from AMLBot. The figure dwarfs the share attributable to zero-day exploits or on-chain attacks. The Binance program directly targets that vulnerability, Su said.
Su discussed the initiative publicly to signal to regulators and institutional partners that the exchange treats security at a granular level. Binance holds about $137.7 billion in assets under management and serves 323 million registered users, according to the company.
The program's escalation from training to dismissal is what gives it force, Su said. Training without accountability is just education, he added. Training with the possibility of termination changes behavior.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.