Binance Runs Monthly Phishing Tests to Strengthen Employee Security Awareness
Key Takeaways
- •Binance’s red team conducts monthly phishing simulations to test and improve employee security behavior.
- •The exercises use scenarios based on real crypto-sector threats, including fake job outreach and offers designed to collect personal information.
- •Employees who fail the tests must complete remedial training, and repeated failures can negatively affect performance reviews.
- •Jimmy Su said Binance has operated the program for three to four years and has seen improved security habits among staff.
- •Social engineering remains a significant crypto security threat, with AMLBot estimating it caused 65% of 2025 security incidents.

Binance conducts simulated phishing attacks every month across its global workforce as part of an internal security awareness program, according to chief security officer Jimmy Su.
The exercises are designed by the exchange’s red team, an internal ethical hacking unit tasked with identifying weaknesses before external attackers can exploit them. The team creates fake attack scenarios that resemble real threats faced by crypto companies, including recruiter outreach and free conference invitations intended to gather personal information.
Employees who fail the tests must complete remedial training. Su said repeated serious failures can also affect performance ratings, with persistent issues potentially leading to more severe consequences. He said Binance has operated the phishing simulation program for three to four years and that employee security habits have improved over that period.
How Binance’s phishing simulations are structured
The phishing tests are run by Binance’s red team, whose broader role includes attempting to break into systems and uncover vulnerabilities before malicious actors do. Su told Cointelegraph that the company runs the tests monthly to measure whether employee behavior and security practices are improving over time.
“We do phishing attacks on our own employees on a monthly basis just so we understand if our security hygiene is improving,” Su said.
The scenarios vary and are updated to reflect tactics currently used by attackers. In one simulation, red team members pose as job recruiters contacting Binance employees. In another, employees may receive an offer for a free conference invitation designed to persuade them to disclose personal details.
“It could be that we are offering some kind of free conference invite just to try to collect personal information,” Su explained.
Those scenarios mirror methods that have been used in attacks across the crypto industry in recent years. One widely known technique is the fake Zoom update, in which hackers disguise malware as a patch for the video conferencing application. Many campaigns also begin with a fraudulent job offer or a fake partnership proposal used as bait.
For crypto exchanges and protocols, these lures can be especially damaging because attackers often seek employee credentials, device access, internal permissions, or information that helps them move deeper into company systems. Simulated phishing programs are intended to test that human layer of defense before similar tactics appear in a real incident.
Su said the program produced mixed results when it began. “In the beginning, the security hygiene left a lot to be desired,” he said. After three to four years of recurring tests, staff security habits have improved across the company, he added.
Training requirements and performance consequences
Employees who fail Binance’s phishing tests are required to complete follow-up training sessions. Su said test results are connected to performance reviews, creating a direct incentive for employees to remain alert to suspicious messages and requests.
“If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating,” Su said. “That’s the incentive to be vigilant.”
According to Su, repeated and serious failures can cause an employee’s rating to decline sharply over time. Such declines could eventually lead to dismissal. Binance treats consistent failure in phishing simulations as a real security risk rather than a minor mistake.
The exchange reports 323 million registered users and holds an estimated $137.7 billion in assets, according to DefiLlama data. At that scale, staff-level security failures can become a possible entry point for major breaches. Regular employee testing is one measure Binance uses to reduce that risk alongside technical security controls and internal vulnerability testing.
Social engineering has become a major source of crypto security losses across the industry. AMLBot estimated in February that 65% of 2025 security incidents stemmed from social engineering tactics. In April, Drift Protocol lost $285 million following a long-term social engineering campaign targeting its systems.
In a separate case, a Venus Protocol user lost roughly $13 million in September 2025 after a fake Zoom client compromised his device. Venus later recovered $11.4 million of the stolen funds through an emergency governance vote.