Binance Uses Monthly Phishing Tests on Staff to Counter Social Engineering
Key Takeaways
- •Binance’s red team conducts monthly phishing simulations against the company’s own employees.
- •Employees who fail the tests receive remediation training, while repeated failures can affect performance reviews.
- •Jimmy Su said severe and repeated failures could cause an employee’s rating to fall low enough to result in dismissal.
- •Binance has run simulated phishing exercises for three to four years and says its internal security practices have improved.
- •Social engineering remains a major crypto-sector threat, with AMLBot estimating it represented 65% of crypto security incidents in 2025.

Binance conducts simulated phishing attacks against its own employees every month and may dismiss staff who repeatedly fail the tests, according to Jimmy Su, the cryptocurrency exchange’s chief security officer.
Su told Cointelegraph that the exercises are run by Binance’s red team, an internal ethical hacking unit tasked with attempting to breach systems so the company can identify weaknesses before real attackers exploit them. Red-team testing is a common security practice in which authorized personnel emulate attacker behavior to test whether staff, processes and technical controls can detect and withstand intrusion attempts.
“We do phishing attacks on our own employees on a monthly basis just so we understand if our security hygiene is improving,” Su said. “The ones that have failed it, we will do remediation training.”
The program illustrates how far cryptocurrency companies are going to prepare for social engineering threats, a persistent attack method in the digital asset sector. Unlike purely technical exploits, social engineering targets people and operational workflows, making employee training and repeat testing part of the defensive surface for exchanges and protocols that handle customer assets. Binance is the world’s largest cryptocurrency exchange and reports 323 million registered users. DefiLlama estimates that Binance holds $137.7 billion in assets.
In February, AMLBot estimated that social engineering accounted for 65% of crypto security incidents in 2025. In April, Drift Protocol was hit by a $285 million hack following what was described as a long-term social engineering campaign.
Su said Binance has been conducting its simulated phishing operations for three to four years. He said the company’s internal security practices have improved over that period.
“In the beginning, the security hygiene left a lot to be desired. But after this amount of time, the company has improved significantly,” Su said.
One scenario used in Binance’s internal tests involves the red team posing as job recruiters, Su said.
A commonly cited technique in recent years has been the “Zoom meeting attack,” in which hackers persuade targets to install malware disguised as an update to the video conferencing application. Many such attacks begin with a fake employment opportunity, while others use supposed project funding or partnership proposals as the lure.
In September 2025, a major Venus Protocol user lost roughly $13 million after a malicious Zoom client compromised his computer and led him to grant an attacker control over his account. Venus paused the protocol and used an emergency governance vote to recover the assets, later returning positions worth $11.4 million to the victim. Venus Protocol also posted about the incident on X: https://x.com/VenusProtocol/status/1963251755543839227
“The interview process is just one scenario. There are other ones. For example, it could be that we are offering some kind of free conference invite just to try to collect personal information and see how many of them will actually fall for it,” Su said.
According to Su, Binance employees have a direct incentive to perform well in the exercises because their results are included in performance reviews. Tying results to remediation and performance reviews makes the tests more than a training formality, but it also places the emphasis on repeat behavior rather than a single failed simulation.
“If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That’s the incentive to be vigilant,” he said.
Repeated and severe failures could cause an employee’s rating to “bottom out,” which could result in dismissal, Su said.