Binance Runs Monthly Phishing Simulations on Staff to Combat Hackers

DRIFT2.18%
XVS-1.90%
Key Takeaways
  • Binance's internal red team conducts monthly simulated phishing attacks against employees, a practice in place for three to four years.
  • Social engineering attacks account for sixty-five percent of crypto security incidents in 2025, according to AMLBot estimates.
  • Employees who fail phishing simulation tests receive remediation training, with repeated failures negatively impacting performance ratings.

Cryptocurrency exchange Binance runs monthly simulated phishing attacks against its own employees through an internal red team, according to chief security officer Jimmy Su. The practice, which has been in place for three to four years, aims to improve security hygiene as social engineering attacks account for 65% of crypto security incidents in 2025 per AMLBot estimates from February. Binance, which reports 323 million registered users and holds $137.7 billion in assets per DefiLlama estimates, conducts the tests to prepare for social engineering threats that have led to major losses across the industry, including a $285 million Drift Protocol hack in April and a $13 million Venus Protocol loss in September 2025.

Binance Red Team Conducts Monthly Phishing Simulations

Binance's red team, an internal ethical hacking unit, conducts phishing attacks on employees monthly to assess security hygiene improvements, Su told Cointelegraph. Employees who fail the tests receive remediation training. "We do phishing attacks on our own employees on a monthly basis just so we understand if our security hygiene is improving," Su said. "The ones that have failed it, we will do remediation training."

Su stated that security hygiene "left a lot to be desired" when the program began three to four years ago, but the company has improved significantly since then. The simulated attacks are part of Binance's preparation for social engineering threats targeting the exchange, which holds $137.7 billion in assets according to DefiLlama estimates.

Simulated Attack Methods Include Fake Job Recruiters

One simulated attack scenario involves the red team posing as job recruiters, according to Su. This method mirrors real-world "Zoom meeting attacks," where hackers trick victims into installing malware disguised as video conferencing app updates. Many of these attacks begin with fake job opportunities, though some use project funding or partnership proposals as lures.

In September 2025, a Venus Protocol user lost $13 million after a malicious Zoom client compromised his computer, granting an attacker control over his account. Venus paused the protocol and used an emergency governance vote to recover the assets, later returning positions worth $11.4 million to the victim.

"The interview process is just one scenario. There are other ones. For example, it could be that we are offering some kind of free conference invite just to try to collect personal information and see how many of them will actually fall for it," Su said.

Performance Reviews Tied to Test Results

Employees are incentivized to perform well on the phishing simulation tests because results are reflected in their performance reviews, Su stated. "If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That's the incentive to be vigilant," he said.

Repeated, severe failures could cause an employee's rating to "bottom out," which could result in dismissal, according to Su. The performance review system ties security awareness directly to employment outcomes at the exchange.

FAQ

How often does Binance conduct phishing simulations on employees? Binance conducts simulated phishing attacks on its employees on a monthly basis through its internal red team, according to chief security officer Jimmy Su. The practice has been in place for three to four years.

What happens to Binance employees who fail phishing simulation tests? Employees who fail the phishing simulation tests receive remediation training. If someone repeatedly fails the tests, it negatively impacts their performance rating and could lead to dismissal if their rating "bottoms out," according to Su.

What types of phishing scenarios does Binance's red team simulate? Binance's red team simulates various scenarios including posing as job recruiters and offering free conference invites to collect personal information. These scenarios mirror real-world social engineering attacks that have targeted the crypto industry.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments