Mcap -- BTC -- ETH -- SOL -- BNB -- XRP -- F&G -- View Market
Loading prices…

Binance Fires Staff Who Repeatedly Fail Monthly Phishing Tests

Binance security team running simulated phishing attacks on employees with red warning indicators

Binance runs fake phishing attacks against its own employees every month and will fire staff who repeatedly fall for them, according to chief security officer Jimmy Su. The practice has been running for three to four years, with test results now factored directly into performance reviews.

The disclosure comes as social engineering, not technical exploits, has emerged as the dominant attack vector across the crypto industry. AMLBot estimated in February that 65% of crypto security incidents in 2025 stemmed from social engineering. The $285 million Drift Protocol hack in April traced back to a long-term social engineering campaign rather than a smart-contract vulnerability. For an exchange holding $137.7 billion in assets across 323 million registered accounts, according to DefiLlama, the human layer has become the critical perimeter.

Fake Job Offers and Free Conference Tickets

Binance’s internal red team, an ethical hacking unit tasked with probing the company’s own defenses, orchestrates the monthly tests. One recurring scenario involves red team members posing as job recruiters reaching out to employees. The tactic mirrors real-world attack patterns that have plagued crypto firms for years.

“The interview process is just one scenario. There are other ones. For example, it could be that we are offering some kind of free conference invite just to try to collect personal information and see how many of them will actually fall for it,” Su told Cointelegraph.

The so-called “Zoom meeting attack” has become a particularly effective vector. Attackers lure victims into installing malware disguised as a video conferencing update. The attack chain typically begins with a fake job opportunity, though some variants dangle project funding or partnership proposals as bait. In September 2025, a major Venus Protocol user lost roughly $13 million after a malicious Zoom client compromised his machine, granting an attacker control over his account. Venus paused its protocol and used an emergency governance vote to recover positions worth $11.4 million for the victim.

The consistency of these social engineering patterns explains why Binance treats internal testing as a continuous process rather than an annual compliance checkbox. Su noted that when the program launched, “the security hygiene left a lot to be desired. But after this amount of time, the company has improved significantly.”

Performance Reviews Now Carry Security Weight

What distinguishes Binance’s approach from standard corporate phishing awareness training is the direct tie to career consequences. Employees who fail simulated attacks face mandatory remediation training. Repeated failures drag down their performance ratings.

“If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That’s the incentive to be vigilant,” Su said. He added that repeated, severe failures could cause ratings to “bottom out,” which could lead to dismissal.

“We do phishing attacks on our own employees on a monthly basis just so we understand if our security hygiene is improving. The ones that have failed it, we will do remediation training.” β€” Jimmy Su, Binance CSO

The policy creates a stark internal calculus. An employee who clicks a suspicious link in a test email isn’t just facing an awkward training session. They’re watching their annual review take a hit, with compounding consequences for bonuses, promotions, and ultimately job security. It’s a model that treats human error as a measurable, improvable metric rather than an inevitable cost of doing business.

This approach reflects a broader shift in how sophisticated organizations think about security. Traditional perimeter defenses, firewalls, intrusion detection systems, multi-signature wallets, remain necessary but insufficient. When 65% of incidents trace to someone clicking the wrong link or trusting the wrong recruiter, the human element becomes the weakest point in the chain. Binance’s solution is to stress-test that weakness relentlessly.

Why Social Engineering Dominates Crypto Attacks

The prevalence of social engineering in crypto exploits isn’t accidental. The industry combines several factors that make human manipulation particularly effective.

First, crypto culture prizes accessibility. Founders, developers, and even security leads often maintain public profiles, respond to DMs, and engage with strangers who might be investors, partners, or contributors. That openness creates attack surface. A developer who wouldn’t dream of running an unaudited smart contract might still take a Zoom call with someone claiming to represent a VC firm.

Second, the stakes are immediate. Unlike traditional finance, where compromised credentials might enable wire fraud that banks can claw back, crypto transactions are final. An attacker who tricks someone into signing a malicious transaction can drain millions before the victim realizes what happened. The September Venus Protocol incident illustrates this perfectly: one compromised machine led to $13 million in losses within hours.

Third, remote-first work culture expanded during the pandemic and never contracted in crypto. Teams span time zones, communicate primarily through Discord and Telegram, and often bring on contributors they’ve never met in person. That environment makes impersonation easier. When you’ve never heard your colleague’s voice, how do you know that “urgent” Zoom link came from them?

As we reported in May when covering Ripple’s intelligence-sharing initiative after the Drift and Kelp exploits, state-sponsored groups like Lazarus have refined social engineering into a precise science. The Drift Protocol hack that drained $285 million followed months of relationship-building by attackers who embedded themselves in the project’s orbit before striking. These aren’t spray-and-pray phishing campaigns; they’re targeted operations that exploit the trust networks crypto communities depend on.

Diagram showing Binance’s monthly phishing simulation workflow from red team attack to employee outcome

The asymmetry favors attackers. A red team at Binance might run hundreds of simulated phishing attempts per month; an attacker only needs one employee to click. That math explains why Su’s team treats continuous testing as essential rather than optional.

The Broader Industry Response

Binance’s red team program represents one node in an evolving industry-wide response to social engineering threats. Crypto ISAC, the information-sharing consortium that Ripple contributed threat intelligence to earlier this year, exists precisely to help firms learn from each other’s incidents without waiting for public post-mortems.

Exchanges face unique pressure because they’re custodial honeypots. Unlike DeFi protocols where user funds sit in smart contracts, centralized exchanges hold assets in hot and cold wallets that employees can access. A compromised employee at a major exchange could theoretically enable withdrawals that dwarf any smart-contract exploit. That’s why Binance’s security investments, including the red team program, function as existential risk management rather than nice-to-have compliance theater.

For context on what custodial risk looks like in practice, our coverage of GhostSwap’s non-custodial pitch noted that centralized platforms have hemorrhaged $670 million to hacks in 2026 alone. Binance hasn’t appeared on that list, which may reflect the cumulative effect of programs like monthly phishing simulations.

The performance-review mechanism Su described also suggests a maturation in how crypto companies think about security culture. Early in the industry’s history, security was often an afterthought, something handled by a small technical team while the rest of the organization focused on growth. Tying security behavior to compensation and career advancement signals that Binance treats every employee as part of the defensive perimeter.

Calculating the Exposure

Consider the numbers involved. Binance reports 323 million registered users and DefiLlama pegs its held assets at $137.7 billion. Even a minor breach, something that drained 0.1% of those holdings, would represent $137 million in losses. The Venus Protocol incident showed how a single compromised individual can enable eight-figure losses; scale that to an exchange with thousands of employees and the potential exposure multiplies.

Binance’s approach essentially prices human error into its risk model. By measuring failure rates on simulated attacks, the security team gains visibility into organizational vulnerability. If failure rates spike, whether because of new employees, novel attack patterns, or simple complacency, the data surfaces the problem before a real attacker exploits it.

The remediation training for failed tests serves a dual purpose. It educates employees on the specific technique that tricked them, making repeat failures less likely. It also creates a documented trail that protects the company if an employee later causes a real incident. Having proof that someone received security training and still failed to apply it changes the liability calculation.

What This Means for Competitors

Binance’s disclosure puts implicit pressure on other major exchanges to demonstrate comparable programs. If Binance can claim that its security hygiene has “improved significantly” over three to four years of continuous testing, exchanges that lack similar programs face uncomfortable questions from institutional clients conducting due diligence.

Institutional crypto adoption has expanded steadily, with firms like BlackRock, Fidelity, and traditional banks now touching digital assets directly or through ETF products. Those institutions bring compliance and risk-management expectations shaped by decades of traditional finance. Learning that a major counterparty runs monthly phishing simulations and fires staff who fail them reads as reassuring. Learning that a competitor does nothing of the sort reads as a red flag.

For individual users, the disclosure offers mixed comfort. On one hand, it suggests Binance takes operational security seriously. On the other hand, it implicitly acknowledges that employees at the world’s largest exchange were, at least initially, susceptible to basic phishing attacks. The security hygiene that “left a lot to be desired” when the program launched presumably reflected real vulnerabilities that attackers could have exploited.

The industry’s challenge is that social engineering targets people, not code. Audits can verify smart-contract security. Bug bounties can surface software vulnerabilities. But there’s no equivalent external check on whether an exchange’s employees will recognize a fake Zoom link. Programs like Binance’s red team offer one answer, but they require sustained internal investment that not every firm will make.

Looking Ahead to Q4 Security Posture

Binance’s disclosure arrives as the industry enters what has historically been a high-activity period for both legitimate volume and attacks. Q4 2025 saw elevated social engineering attempts as attackers targeted year-end activity spikes. If that pattern repeats in 2026, programs like monthly phishing simulations become particularly relevant.

Su didn’t disclose specific failure-rate metrics or how many employees have been dismissed under the policy. Those details would offer a clearer picture of program effectiveness. But the existence of the program, with real consequences attached to test results, signals a security posture that treats human error as manageable rather than inevitable.

For firms watching Binance’s example, the takeaway is straightforward. Technical security is necessary but not sufficient. Social engineering will continue dominating incident statistics until organizations invest as heavily in their human perimeter as they do in their software perimeter. Monthly phishing tests tied to performance reviews represent one model for that investment. Whether competitors adopt similar programs, or continue accepting the 65% of incidents that trace to human manipulation, will shape the industry’s security landscape heading into 2027.

References

Share:
Twitter Facebook LinkedIn Reddit WhatsApp Telegram Email