Key Insights
- Binance runs its internal Red Team to periodically test for phishing, repeating the process of failure could result in dismissal.
- Phishing test results for employees shape their performance evaluations, in addition to providing technical defenses, to reinforce security awareness.
- The programme tackles the increasing human threats within the cyber landscape with social engineering now making up 65% of crypto security incidents in 2025.
Binance phishing tests have become a permanent part of the exchange’s internal security strategy, with employees facing training, lower performance ratings, or even dismissal after repeated failures. The monthly exercises reflect the growing pressure on cryptocurrency firms to defend against social engineering attacks that continue to drive most security incidents across the industry.
Jimmy Su, Binance’s chief security officer, said the company has operated the program for three to four years through its internal Red Team. The ethical hacking unit launches realistic phishing campaigns against employees to measure whether security awareness improves over time while exposing weaknesses before criminals can exploit them.
Binance Runs Fake Hacks on Its Own Staff Every Month: Here's What They Keep Finding — https://t.co/2SzRtjvjRW
— morosaki (@Morosaki) July 26, 2026
Security drills now influence employee performance
Binance introduced the simulations after identifying gaps in staff security awareness. Initially, workers were not able to identify phishing emails, says Su. But frequent testing and required training has helped increase security practices throughout the company.
The Red Team is constantly adapting its strategies to match new ways of running a cybercrime. It could be an online recruitment campaign with fake recruiters promising jobs or a campaign providing free conference invites to request personal details. Other scenarios mirror fraudulent software updates from video conference software, a common method used by attackers against cryptocurrency professionals.
Workers not passing the simulations are required to take extra security training. In the meantime, the lack of success regularly impacts annual assessments. Those who fall for these phishing schemes again could face the company’s poorest performance rating, and that may result in their termination.
Key security measures include
- Monthly phishing simulations conducted by the internal Red Team
- Mandatory remediation training for employees who fail
- Performance reviews linked to phishing awareness results
Su said the company treats employee awareness as an essential layer of defense rather than relying only on technical safeguards.
Social engineering remains the industry’s weakest link
The Binance phishing tests come as social engineering continues to account for most cryptocurrency security breaches. According to AMLBot data, 65% of the crypto security incidents analyzed in 2025 were not software vulnerabilities, but due to social engineering.
As opposed to directly attacking the blockchain infrastructure, attackers are focusing more on human behavior. The criminals will build rapport with the victim over weeks before convincing them to add malicious software, accept a fraudulent wallet request or give out sensitive information.
Such attacks have been effective in recent years. An attacker breached the account of one of the administrators after a prolonged social engineering campaign, causing the loss of about $285 million for Drift Protocol. The downtime was the result of an attacker exploiting one of the administrators in a long-term social engineering attack, losing approximately $285 million for Drift Protocol. In other cases, a user of the Venus Protocol lost about $13 million when installing a fake video conferencing update.
Fake job postings and fake online meetings for employment are also associated with campaigns carried out by North Korea-backed hacking groups seeking to recruit cryptocurrency executives and developers.
Security metric Details
Binance registered users 323 million
Assets under custody Approximately $137.7 billion
Phishing simulation frequency Monthly
Program duration Three to four years
Crypto incidents tied to social engineering in 2025 65%
Broader implications for the cryptocurrency industry
The Binance phishing tests illustrate the current trend in cybersecurity strategies from software to employees. As trusted employees become the seemingly obvious target for gaining access to critical infrastructure, large exchanges are increasingly realizing they are vulnerable to this attack.
Binance’s measurable career repercussions for non-conformance with security measures are more stringent than a standard annual compliance program. The strategy could make other exchanges and financial technology companies more likely to use more regular simulations as attackers further evolve their social engineering techniques.
The strategy also has a message for the regulators and institutional investors. Workforce readiness is as important to operational resilience as are technical defenses. Although no phishing drill will stop every type of attack, it will help make an organization more resilient to detecting suspicious requests before they cause significant security issues.
important takeaways
- Recurring simulations enable employees to become aware of new phishing tactics before attackers are able to exploit them.
- Performance-based accountability helps to keep security awareness active beyond regular compliance training.
- The risk of human-centric attacks is more of a concern for crypto companies than software vulnerabilities.
The Binance phishing tests show how cybersecurity is no longer a one-off exercise, but an active part of day-to-day business. With more sophisticated social engineering attacks, exchanges are being pushed to beef up their technology and their staff. The program’s longevity suggests that ongoing testing, practical experience and responsible oversight are now needed to safeguard digital assets and build user trust.









