Crypto
Home›Crypto›Regulation›Binance runs monthly phishing tests on staff to spot s…
Binance runs monthly phishing tests on staff to spot security gaps
Binance’s chief security officer says the exchange can fire employees who repeatedly fail the monthly simulated attacks.
Binance runs internal, monthly simulated phishing attacks against its own employees as part of its effort to improve security hygiene, according to Cointelegraph. Binance chief security officer Jimmy Su said the exchange uses an internal red team, an ethical hacking unit, to test defenses and identify vulnerabilities. Su said the purpose of the exercises is to measure whether staff security practices are improving, and that employees who repeatedly fail the tests face remediation training, with the exchange able to terminate those who keep failing. Cointelegraph reports that Binance has been running these simulated attacks for three to four years. The outlet also notes that simulated social engineering has been a common driver of breaches across the industry. AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering, and Cointelegraph cites a recent example where Drift Protocol was hit by a $285 million hack following a long term social engineering campaign. Cointelegraph adds that Binance’s scenarios can include the red team posing as job recruiters, and it references widely used techniques such as the “Zoom meeting attack,” where victims are tricked into installing malware disguised as an update. The outlet also points to a Venus Protocol incident in September 2025, where a malicious Zoom client led to losses of roughly $13 million, with assets later recovered and positions worth $11.4 million returned to the victim.