Binance Runs Monthly Red-Team Phishing Tests on Employees, Security Chief Says
Key Takeaways
- •Binance’s internal red team runs monthly phishing simulations to assess and improve employee security awareness.
- •Jimmy Su said the program has operated for three to four years and has significantly improved Binance’s security practices.
- •Failed phishing tests lead to remediation training, and repeated failures can negatively affect performance reviews or employment outcomes.
- •The simulations use varied social engineering scenarios, including fake recruiters, free conference invitations and malicious meeting-update tactics.
- •Binance’s focus on employee behavior comes as social engineering remains a major factor in crypto security incidents.

Binance Chief Security Officer Jimmy Su says the crypto exchange is regularly testing its workforce with simulated phishing attacks and linking repeated failures to employee performance outcomes.
Su told Cointelegraph that Binance’s internal red team conducts phishing exercises every month to measure whether employees’ security awareness is improving. The red team is responsible for ethical hacking and vulnerability discovery, including attempts to simulate the kinds of intrusions and interactions that attackers use in real-world campaigns.
Employees who fail the exercises receive remediation training, Su said. Those who repeatedly fail can face consequences in performance reviews and, in severe cases, potential employment outcomes. The approach reflects Binance’s view that social engineering is not only a technical risk, but also an operational and personnel risk.
Binance says the program is designed to measure security hygiene
Su said Binance runs the phishing simulations “just so we understand if our security hygiene is improving,” describing the effort as a practical measurement program rather than a one-time awareness initiative. The red team tests staff using realistic scenarios, then feeds the results back into additional training and internal review processes.
The program has been running for three to four years, according to Su. He said Binance has seen a major improvement in security practices since the exercises began.
“In the beginning, the security hygiene left a lot to be desired. But after this amount of time, the company has improved significantly,” Su said.
Binance is a large target in the crypto sector because of its scale. The company reports 323 million registered users, while DefiLlama estimates the exchange holds $137.7 billion in assets. Su did not provide further internal metrics in the interview, but the figures illustrate why major exchanges treat employee behavior as part of their threat model.
The risk is not limited to software vulnerabilities or infrastructure weaknesses. Large exchanges depend on internal workflows involving customer support, account access, identity verification, compliance processes and internal tooling. Those operational processes can give attackers opportunities to use manipulation, impersonation or information-gathering tactics that purely technical defenses may not fully prevent.
For crypto platforms, a successful social engineering attack can be especially sensitive because employees may interact with systems connected to custody operations, customer accounts, compliance data or internal approvals. That makes workforce security practices part of the broader control environment around both user protection and exchange operations.
Social engineering remains a recurring breach pathway
Su’s comments come amid broader industry attention on social engineering as a factor in crypto security incidents. In February, AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering. In April, according to earlier coverage referenced by Cointelegraph, a long-term social engineering campaign preceded Drift Protocol’s $285 million hack.
The examples show why Binance has made recurring tests part of its internal security program. Rather than treating security training as a single compliance exercise, the company is using a process that repeatedly tests employees, measures outcomes and requires additional training when staff fall short.
Su’s description indicates that Binance is applying a feedback-loop model: employees are exposed to controlled attack simulations, the company measures who is vulnerable to those tactics, and the results are used to reinforce training and accountability. The underlying premise is that awareness must be tested regularly because attacker methods continue to evolve.
Simulations include fake recruiters and conference invitations
One scenario used by Binance involves impersonating job recruiters. Su said the red team poses as recruiters, a tactic that mirrors a common pattern in phishing campaigns across industries. In such cases, communication that appears to be legitimate professional outreach can become the first step in a broader attempt to manipulate the target.
Su also described fake “free conference invites” used as another lure. Those scenarios are designed to collect personal information and determine how many employees engage with the attempted data-harvesting tactic. He stressed that simulated job interviews are only one of several scenarios Binance’s red team uses.
The details are significant because social engineering attacks in crypto do not always arrive as obvious phishing emails asking recipients to click a suspicious link. They may be presented as normal professional communication, including recruitment messages, scheduling requests, conference outreach, partnership discussions or project-related follow-ups.
Another technique referenced in the interview is the “Zoom meeting attack,” in which attackers persuade victims to install malware disguised as a video conferencing update. Many of those campaigns begin with a fake job opportunity, though similar approaches can also use hooks such as project funding or partnership proposals.
By using multiple lures, Binance’s red team attempts to test whether employees can identify suspicious behavior across different communication channels and contexts. The company’s exercises therefore focus not only on whether staff recognize traditional phishing emails, but also on whether they can resist more subtle attempts to gather information or establish trust.
Failed tests lead to training and can affect reviews
Binance’s program does not stop at testing. Su said employees who fail phishing simulations are required to complete remediation training. He also said test outcomes are tied to incentives because performance reviews reflect the results.
“If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That’s the incentive to be vigilant,” Su said.
Su added that repeated severe failures could “bottom out” performance ratings and potentially lead to dismissal. He did not specify exact thresholds, timelines or internal procedures for dismissal in the interview. However, his comments indicate that Binance treats recurring susceptibility to social engineering as more than a training issue.
The exchange’s approach places repeated phishing-test failures within a broader employee accountability framework. In practice, that means staff who miss simulations are retrained, while repeated failures can affect how the company evaluates their performance and standing.
Similar social engineering dynamics have also contributed to losses outside centralized exchanges. Cointelegraph referenced a September 2025 incident involving a Venus Protocol user who reportedly lost around $13 million after a malicious Zoom client compromised a computer and allowed an attacker to gain control of the victim’s account. Venus paused the protocol and used an emergency governance vote to recover assets, later returning positions worth $11.4 million to the victim, according to earlier coverage cited in the article.
Those incidents underline the risk that attacks aimed at individuals can produce large-scale consequences. Binance’s monthly red-team phishing exercises, remediation training and performance-linked consequences show how one major crypto exchange is incorporating human behavior into its operational security program alongside technical defenses.