Binance’s chief security officer, Jimmy Su, says the exchange is actively testing its own workforce against simulated phishing attempts—and tying repeated failures to employment outcomes. Su
Binance’s chief security officer, Jimmy Su, says the exchange is actively testing its own workforce against simulated phishing attempts—and tying repeated failures to employment outcomes. Su told Cointelegraph that the internal “red team” runs phishing exercises on a monthly basis to gauge whether security awareness among staff is improving.
According to Su, employees who fail the exercises aren’t just retrained once. Instead, Binance uses remediation training for those who miss the mark, and persistent, repeat failures can ultimately affect their standing at the company, reflecting the role that social engineering plays in real-world cyber incidents.
Key takeaways
- Binance conducts monthly simulated phishing attacks against employees as part of an ongoing internal security program.
- The simulations are carried out by Binance’s red team, a unit focused on ethical hacking and vulnerability discovery.
- Failed employees receive remediation training, while repeated failures can negatively affect performance reviews and potentially job outcomes.
- Binance says the program has been running for three to four years, with Su describing significant improvements in security hygiene over time.
- The company uses multiple real-world lures—such as fake recruiter outreach and other “information collection” tactics—to test staff resilience.
Why Binance is testing its own staff
Su said Binance runs phishing simulations “just so we understand if our security hygiene is improving,” framing the effort as a practical measurement exercise rather than a theoretical awareness campaign. The red team’s role, as described by Su, is to attempt intrusions and interactions that mirror real attack paths, then feed results back into training.
Binance is often described as a large-scale target in crypto due to its user base and market footprint. Su did not provide additional internal metrics in the interview, but the context underscores the stakes: Binance reports 323 million registered users, while DefiLlama estimates the exchange holds $137.7 billion in assets.
For investors and traders, the takeaway is that big exchanges treat human behavior as part of their threat model. The more a firm relies on operational processes—such as customer support, account access, identity verification, and internal tooling—the more social engineering becomes a risk factor that technical defenses alone can’t fully eliminate.
Social engineering remains a recurring breach pathway
Su’s comments land in the context of broader industry reporting on social engineering as a driver of crypto security incidents. In February, AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering. Later, in April, a long-term social engineering campaign preceded Drift Protocol’s $285 million hack, according to earlier coverage referenced by Cointelegraph.
Su also said the simulated attacks have been in place for three to four years. He suggested that security hygiene has improved substantially since the program began: “In the beginning, the security hygiene left a lot to be desired. But after this amount of time, the company has improved significantly,” he said.
This matters because it highlights a specific operational change: Binance is not treating awareness training as a one-time checkbox, but as an ongoing feedback loop. The key shift for organizations is moving from “teach and forget” to “test, measure, and enforce.”
What the simulations look like: recruiting lures and data-harvesting scenarios
One scenario Binance uses is impersonation of job recruiters. Su said the red team poses as recruiters—an approach that mirrors a common pattern seen in phishing incidents across industries, where “legitimate-sounding” contact becomes the entry point for further manipulation.
Su also described another lure: fake “free conference invites” aimed at collecting personal information and determining how many employees fall for it. He emphasized that the job interview process is only one of multiple scenarios used by Binance’s red team.
These details are important because social engineering attacks in crypto don’t always arrive as obvious “click this link” attempts. They can be structured like legitimate professional outreach, scheduling requests, or follow-ups—channels that can appear normal to staff who might otherwise be trained to recognize traditional phishing emails.
Another well-known technique referenced in the interview is the “Zoom meeting attack,” where attackers trick victims into installing malware disguised as a video conferencing update. Many such campaigns begin with a fake job opportunity, but they can also use other professional hooks like project funding or partnership proposals.
Binance’s approach doesn’t end with simulated testing. Su said employees who fail the phishing simulations undergo remediation training. He also described incentives tied to the results, stating that performance reviews reflect test outcomes.
Su’s framing is direct: “If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That’s the incentive to be vigilant.”
He further said repeated severe failures could “bottom out” performance ratings, potentially leading to dismissal. While Su did not outline exact thresholds or timelines for dismissal in the interview, the principle is clear: Binance is treating repeated susceptibility to social engineering as a personnel risk, not just a training gap.
Outside centralized exchanges, similar social engineering dynamics have produced major losses in DeFi ecosystems as well. For example, Cointelegraph referenced a September 2025 incident in which a Venus Protocol user reportedly lost around $13 million after a malicious Zoom client compromised a computer and led the attacker to gain control over the victim’s account. Venus paused the protocol and used an emergency governance vote to recover assets, later returning positions worth $11.4 million to the victim, according to earlier coverage cited in the article.
Those examples reinforce the broader point behind Binance’s internal testing: even when attackers target individuals rather than systems, the outcome can still be catastrophic at scale.
What readers should watch next is whether Binance’s approach—monthly red-team phishing tests, remediation, and performance-linked consequences—becomes a more standard pattern across large crypto firms as regulators and stakeholders increasingly focus on operational security beyond code and infrastructure.
This article was originally published as Binance Runs Monthly “Red Team” Tests on Staff to Thwart Hackers on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.