Binance runs phishing simulations on staff, can fire repeat failures
Crypto exchange Binance runs monthly simulated phishing attacks on its staff to combat social engineering, a threat behind major hacks and 65% of crypto security incidents in 2025. Conducted by an internal 'red team,' the tests can lead to negative performance reviews or even dismissal for employees who repeatedly fail, according to Chief Security Officer Jimmy Su. The program has been active for three to four years.
Binance phishing simulations
▪Binance has been running these simulated attacks for three to four years and reports its security hygiene has improved significantly.
▪Cryptocurrency exchange Binance runs simulated phishing attacks against its own employees on a monthly basis.
▪The fake attacks are conducted by Binance’s "red team," an internal ethical hacking unit that identifies system vulnerabilities.
Social engineering threats
▪In April, Drift Protocol suffered a $285 million hack that resulted from a long-term social engineering campaign.
▪AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering.
▪A major Venus Protocol user lost roughly $13 million in September 2025 after a malicious Zoom client compromised their computer.
Employee performance consequences
▪Repeated, severe failures of the phishing simulations can negatively impact an employee's rating and potentially lead to dismissal.
▪Employees who fail Binance's phishing simulations are required to undergo remediation training.
▪The results of the internal phishing tests are reflected in employee performance reviews.
Red team attack scenarios
▪One simulated attack scenario involves Binance's red team posing as job recruiters.
▪Another test involves offering a fake free conference invitation to see how many employees will provide personal information.
Story comments
Loading comments…