Four people in business attire seated at a table
Crypto

Binance ties monthly phishing-test failures to reviews and potential dismissal

Security chief Jimmy Su said an internal red team runs the drills to measure employee “security hygiene.”

By AI News Crypto Editorial Team5 min read

Binance chief security officer Jimmy Su said the exchange runs simulated phishing attacks against employees every month and uses the results in performance reviews. Repeated, severe failures can “bottom out” an employee’s rating and “could see them dismissed,” he said.

Key Takeaways

  • Monthly phishing simulations are run against Binance employees by an internal red team designed to surface human-layer security gaps.
  • Staff who fail are put through remediation training, and repeated severe failures can flow into performance ratings up to potential dismissal.
  • The program has been operating for three to four years, and Binance says employee security hygiene has improved significantly over that period.
  • Social engineering was linked to an estimated 65% of crypto security incidents in 2025, per AMLBot.

Binance runs simulated phishing attacks on its own employees every month through an internal “red team,” an ethical-hacking unit tasked with breaking into systems to identify vulnerabilities, according to chief security officer Jimmy Su.

“We do phishing attacks on our own employees on a monthly basis just so we understand if our security hygiene is improving,” Su said. “The ones that have failed it, we will do remediation training.”

The program is explicitly tied to incentives and penalties. Su said results are reflected in performance reviews, and repeated failures can negatively impact an employee’s rating. “If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That’s the incentive to be vigilant.” He added that repeated, severe failures could lead to a rating “bottom out,” which “could see them dismissed.”

Inside the Red Team: Recruiter and Conference-Invite Lures

Su described the simulations as designed to mirror the lures that routinely show up in real-world compromises. One scenario has the red team pose as job recruiters to see whether employees engage with a social-engineering pitch.

“The interview process is just one scenario. There are other ones. For example, it could be that we are offering some kind of free conference invite just to try to collect personal information and see how many of them will actually fall for it,” Su said.

Operationally, Binance is treating employee behavior as a measurable control, not a one-off awareness slide deck. Su said the exchange has been running the simulated attacks for three to four years, and that early outcomes were poor before improving over time. “In the beginning, the security hygiene left a lot to be desired. But after this amount of time, the company has improved significantly.”

Why Social Engineering Keeps Showing Up in Big Crypto Losses

The exchange is positioning the drills against a threat mix where people are often the entry point. AMLBot estimated in February that 65% of crypto security incidents in 2025 were driven by social engineering.

Recent examples cited alongside Su’s comments include the “Zoom meeting attack,” where victims are tricked into installing malware disguised as a Zoom update. These campaigns often start with fake job opportunities, though lures can also be framed as project funding or partnership proposals.

In September 2025, a major Venus Protocol user lost roughly $13 million after a malicious Zoom client compromised his computer, leading him to grant an attacker control over his account. Venus paused the protocol and used an emergency governance vote to recover assets, later returning positions worth $11.4 million to the victim.

The source also references a $285 million Drift Protocol hack tied to a long-term social engineering campaign that occurred “in April,” but the year is not specified.

Signals Traders Can Track From Exchange Security Posture

For traders, the immediate takeaway is counterparty risk optics. Binance describes itself as the largest crypto exchange in the world and reports 323 million registered users. DefiLlama estimates Binance holds $137.7 billion in assets. At that scale, internal controls that reduce credential theft and access compromise matter because the blast radius is not theoretical.

The next signal is whether Binance publishes outcomes, not just process. Su’s claim of significantly improved hygiene over three to four years sets up a natural follow-through: aggregate pass or fail rates, trendlines over time, or any disclosure tying drills to measurable reductions in security incidents.

Two external reference points could also move the narrative. One is whether follow-on reporting pins down the year of the “April” Drift Protocol $285 million incident. The other is whether third-party estimates update materially, including AMLBot’s 65% social-engineering share and DefiLlama’s Binance asset estimate.

Counterparty Risk Is Often a People Problem, Not a Code Problem

I read Binance’s approach as an attempt to turn “security culture” into something enforceable. Monthly simulations plus remediation training is table stakes. The differentiator is the HR linkage, because it changes the payoff matrix for employees who treat phishing as someone else’s problem.

The threshold that matters is whether Binance is willing to disclose outcome metrics that let the market judge effectiveness, not intent. If those numbers show sustained improvement over time, the setup starts to look structural rather than narrative-driven, and it would matter in practical terms by tightening the human attack surface that often precedes exchange-grade incidents.

Sources