Newsroom
26 July, 2026 / News / AI / Tags: employees, simulations, jimmy, binance, phishing

The exchange’s red team tests employees with realistic social engineering scenarios, linking repeated failures to training and performance reviews as crypto firms face rising human-targeted risks
Binance conducts simulated phishing attacks against its own employees every month through an internal red team. The program, in place for three to four years, aims to assess and improve staff awareness of social engineering tactics that threaten cryptocurrency platforms.
Chief security officer Jimmy Su described the effort as a practical way to determine whether security habits are getting better across the organization. The red team designs exercises that closely resemble actual attack methods used against crypto firms.
The internal group of ethical hackers creates fake messages and requests designed to test whether employees recognize suspicious communications, links or information demands. One common scenario involves impersonating job recruiters. Another offers free access to a conference and seeks personal details in return.
These approaches mirror tactics that have produced significant losses elsewhere in the industry. Attackers frequently build trust over days or months before asking targets to open files, approve transactions or install software. The tests record whether staff open messages, follow links or disclose information that could expose systems.
Binance also maintains external bug bounty programs and broader technical testing. The company treats employee behavior as a core part of its security model because attackers often seek entry through trusted accounts or devices rather than pure software flaws.
Employees who fail a simulation receive follow-up training. The company links results to performance evaluations. Su stated that repeated failures will negatively impact ratings. In severe cases, ratings can reach the lowest level and result in dismissal.
This structure creates a direct workplace incentive for staff to verify unexpected messages before responding. Su noted that security habits left much room for improvement when the program began. Continued monthly testing has produced clear gains over time.
The drills address a persistent industry problem. A review of more than 2,500 investigations found that 65 percent of cases handled in 2025 began with social engineering rather than direct software exploits. Phishing accounted for 18 percent of those cases, while device compromise made up 13 percent.
In April 2026, attackers drained about $285 million from Drift Protocol after compromising an administrator key through social engineering and operational security failures. The attacker altered market settings and withdrawal limits before moving assets across multiple transactions.
In September 2025, a Venus Protocol user lost roughly $13 million after approving a malicious transaction following a compromised Zoom client. The protocol paused operations and recovered most of the assets through an emergency governance process.
North Korea-linked groups have used compromised messaging accounts and deepfake video calls to target crypto professionals, often posing as known contacts and requesting software updates that deliver malware.
Binance reports 323 million registered users. External data track approximately $137.5 billion to $137.7 billion in assets associated with the exchange. At that size, human decision points remain a high-value target for attackers.
Monthly simulations allow the company to track failure rates and adjust training as tactics evolve. A single annual session may not prepare staff for new lures built around current events, trusted contacts or professional opportunities. Frequent testing also checks whether employees report suspicious messages rather than simply discarding them.
Simulations alone cannot eliminate every risk. Attackers can take over genuine accounts, replicate prior conversations or use advanced tools to generate convincing messages, audio and video. Access controls, transaction limits, device monitoring and rapid response remain necessary alongside staff training.
Binance presents the program as an ongoing operational practice rather than a one-time compliance exercise. Employees are expected to confirm unusual requests through a separate channel before opening files, sharing data or approving transactions.









