Binance red teams its staff monthly to keep hackers out
Binance red teams its own employees every month with simulated phishing attacks to test security hygiene, chief security officer Jimmy Su told Cointelegraph. Staff who fail get remediation training, and repeated severe failures can hurt performance ratings—and may lead to dismissal—as social engineering drives most crypto breaches.
Key Takeaways
- Binance’s internal red team runs monthly phishing simulations on staff to measure security hygiene.
- Employees who fail receive remediation training; repeated severe failures can tank ratings and risk dismissal.
- Social engineering drove an estimated 65% of crypto security incidents in 2025, per AMLBot.
- Simulations have run for three to four years and include fake recruiter and free-conference lures.
What does Binance do when it red teams its staff?
According to Cointelegraph, Binance’s red team—an internal ethical hacking unit—stages fake phishing attacks on employees each month. The goal is to see whether security habits are improving before real attackers strike.
“We do phishing attacks on our own employees on a monthly basis just so we understand if our security hygiene is improving,” Su said. Those who fail get remediation training rather than an automatic exit.
Su said the program has been in place for three to four years. Early results were weak, but he said the company has improved significantly over that period. Binance reports 323 million registered users, and DefiLlama estimates the exchange holds about $137.7 billion in assets—scale that makes insider-facing defenses a high-stakes priority for readers tracking fintech and crypto alerts.
Why does social engineering matter so much in crypto?
Industry data underscores the threat. In February, AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering. In April, Drift Protocol suffered a $285 million hack after a long-term social engineering campaign.
Common real-world tactics include “Zoom meeting” attacks, where malware is disguised as a video-app update, often after a fake job, funding, or partnership lure. In September 2025, a major Venus Protocol user lost roughly $13 million after a malicious Zoom client compromised his computer; Venus later recovered and returned positions worth $11.4 million via emergency governance.
Binance’s drills mirror those patterns. Su said one simulated attack has the red team pose as job recruiters. Another offers a free conference invite to harvest personal information and gauge how many people fall for it.
Can failing a phishing test cost a Binance employee their job?
Yes, in extreme cases. Su said test results feed into performance reviews, creating a clear incentive to stay vigilant. “If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating,” he told Cointelegraph.
Repeated, severe failures could push a rating to “bottom out,” which could lead to dismissal. For most staff, the first response remains training—not termination—so the program doubles as coaching and deterrence.
That mix of monthly testing, remediation, and career consequences is Binance’s answer to a breach landscape where people, not just code, are the attack surface.