Key facts
- Binance conducts monthly simulated phishing attacks on its employees.
- The company's internal red team performs these ethical hacking exercises.
- Employees who repeatedly fail the tests undergo remediation training.
- Poor performance on these simulations can affect performance reviews and lead to dismissal.
- These security tests have been in place for three to four years.
Binance, the world's largest cryptocurrency exchange, regularly conducts simulated phishing attacks against its own employees to enhance security against social engineering threats. According to Chief Security Officer Jimmy Su, the company's internal red team performs these tests monthly. Employees who repeatedly fail these simulated attacks face mandatory remediation training, and persistent failures can negatively impact their performance reviews, potentially leading to dismissal.
Su stated that these security hygiene tests have been ongoing for three to four years, noting significant improvement in the company's defenses over time. Scenarios include the red team posing as job recruiters or offering fake conference invitations to gauge employee vigilance and information-sharing habits. This proactive approach highlights the lengths crypto companies are taking to prepare for sophisticated social engineering attacks, which have been a major source of industry breaches.
In February, AMLBot estimated that 65% of crypto security incidents in 2025 would be driven by social engineering. Notable incidents include a $285 million hack on Drift Protocol in April, which followed a long-term social engineering campaign, and a $13 million loss by a Venus Protocol user in September 2025 due to a compromised Zoom client. Binance, with 323 million registered users and an estimated $137.7 billion in assets, aims to mitigate such risks through its rigorous internal testing.