Binance phishs its own staff monthly amid Asia crypto news
Binance phishs its own staff every month through simulated attacks run by its red team, CSO Jimmy Su said. Failures trigger remediation training, and repeat failures can mean dismissal. The four-year program aims to blunt social engineering risks that AMLBot linked to 65% of 2025 crypto security incidents.
Key Takeaways
- Binance's red team runs monthly phishing drills on employees and can fire staff who keep failing.
- India ordered GitHub to disable three BitChat repos within three hours; the Internet Freedom Foundation called it unconstitutional.
- South Korea's five major exchanges saw combined volumes drop about 89% year over year, to roughly $305 million daily.
- Coinbase plans to grow Singapore headcount from about 150 to 200 by end-2026.
The Asia Express roundup from Cointelegraph Magazine also flags India cracking down on BitChat code and a steep Korean trading slump. For more market-structure and exchange alerts, see our Fintech & Crypto Alerts hub.
Why Binance phishs its own employees every month?
According to chief security officer Jimmy Su, Binance has run simulated phishing attacks against staff for four years. The internal red team—an ethical hacking unit tasked with finding vulnerabilities—launches the tests monthly to track whether security hygiene is improving.
"We do phishing attacks on our own employees on a monthly basis just so we understand if our security hygiene is improving," Su told Cointelegraph. Staff who fail get remediation training. Those who repeatedly fail can be fired.
The timing matters. In February, AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering—exactly the risk these drills target.
Why did India order BitChat code removed from GitHub?
India's cybercrime agency directed GitHub to disable access to three repositories for Jack Dorsey's decentralized messaging app BitChat within three hours. Officials said the app could help users bypass internet shutdowns, evade lawful surveillance, and facilitate unlawful activities.
BitChat routes encrypted messages between nearby devices over Bluetooth without internet or centralized servers. Since its July 2025 release, it has drawn users during unrest and outages in places including Madagascar, Nepal, Uganda, Jamaica, and Iran.
India's Internet Freedom Foundation condemned the order as unconstitutional and warned it threatens free speech and open-source software. Separately, India's Central Board of Direct Taxes told crypto exchanges to report all platform transactions to the Income Tax department.
How bad is South Korea's crypto volume collapse?
Cointelegraph compared CoinGecko seven-day averages for Upbit, Bithumb, Coinone, Korbit, and Gopax in July 2025 versus July 2026. Combined average daily volume fell about 89%, from $2.82 billion to $305 million, as the KOSPI more than doubled and retail money shifted toward stocks.
Elsewhere in the region: Korbit is reportedly set to rebrand as Digital X under Mirae Asset; regulators removed 29 unlicensed exchange apps from Google Play, including OKX, Bybit, MEXC, KuCoin, Gemini, Backpack, and BitMEX; and Coinbase aims to expand Singapore staffing by about 25% by the end of 2026.
Thailand's SEC also filed a criminal complaint against Bitkub and two former directors over alleged false disclosures tied to a 2021 cyberattack involving $50 million in assets—another reminder that exchange security and disclosure remain under hard scrutiny across Asia.