Binance, one of the world’s largest cryptocurrency exchanges, is intensifying its internal security protocols by closely tying the results of monthly phishing simulations to employee performance reviews. The company aims to address the growing threat of social engineering, which remains one of the most prevalent risks in the digital asset sector.
Monthly phishing tests form part of Binance security culture
Chief Security Officer Jimmy Su explained that Binance deploys an internal red team of ethical hackers who conduct simulated attacks on employees every month. These exercises are designed to mimic real-world cybercriminal behavior, probing for weak points in human vigilance rather than purely technical vulnerabilities.
Binance launched its internal phishing test program about three to four years ago, after initial results showed a large number of staff struggled to correctly identify phishing attempts. Since then, ongoing tests and targeted training have prompted measurable improvements in employee awareness and conduct.
“Employees who repeatedly fail the simulated attacks are required to complete extra training sessions to boost their security knowledge and awareness,” Su stated. The company’s approach includes consequences for continued underperformance, including poor performance ratings and potential dismissal.
Staff who consistently fail phishing drills risk the lowest performance rating, and ongoing issues can ultimately lead to dismissal from Binance.
Each month, red team members devise realistic attack scenarios, such as fake job recruiting efforts or fraudulent conference invitations. Participants who fall for these simulations must take remedial courses designed to improve their understanding of social engineering threats.
| Attack Scenario | Purpose |
|---|---|
| Fake job recruiter outreach | Collect sensitive information from staff |
| Fraudulent conference invitation | Trick employees into revealing personal details |
| Malicious software links | Install harmful programs on company devices |
Binance includes the results of these exercises as a mandatory component of staff performance reviews, reinforcing the importance of cybersecurity vigilance throughout the organization.
Social engineering drives majority of crypto incidents
Social engineering attacks have become increasingly prevalent in the crypto industry. Analytics provider AMLBot reported in February that social engineering accounted for 65% of all cryptocurrency security incidents in 2025, underscoring a shift in criminal tactics from technical exploits to deception-based methods.
A notable case occurred in April 2025 when Drift Protocol lost $285 million in a hack that exploited long-term social engineering strategies. Criminals also commonly use fake business meeting invitations to spread malicious software disguised as legitimate updates.
In September 2025, a major Venus Protocol user lost around $13 million after attackers tricked them into installing a falsified Zoom client. This allowed hackers to gain control of the victim’s account and seize digital assets. In response, Venus Protocol temporarily paused certain services, implemented emergency measures, and later restored approximately $11.4 million worth of user positions.
Binance, with more than 323 million registered users and over $137.7 billion in assets, continues to see regular phishing drills as an essential barrier against evolving fraud methods and highly convincing scam campaigns.
Mini dictionary: Red team — A group of cybersecurity professionals who imitate the methods used by real attackers to identify vulnerabilities in an organization’s systems and practices, with the goal of improving defense mechanisms before real breaches can occur.




