Cryptocurrency exchange Binance conducts simulated phishing attacks on its employees and may terminate employees who repeatedly fail tests, according to Binance’s chief security officer Jimmy Su.
The imitation attacks are carried out by Binance’s red team, an internal ethical hacking unit tasked with breaking into systems to identify security vulnerabilities.
“We conduct phishing attacks on our employees every month to see if our security hygiene is improving,” Su told Cointelegraph. “For those that didn’t make it, we’ll give them repair training.”
The measure shows how much time crypto companies will spend preparing for social engineering attacks. Binance, the largest cryptocurrency exchange in the world, reports 323 million registered users, while DefiLlama estimates the exchange has assets worth $137.7 billion.
Jimmy Su, Chief Security Officer at Binance. Source: Binance
In February, AMLBot estimated that 65% of cryptocurrency security incidents in 2025 were due to social engineering. In April, Drift Protocol was hacked for $285 million, following a long-term social engineering campaign.
Su said Binance has been carrying out these simulated attacks for three to four years.
“In the beginning, the safety hygiene left much to be desired, but after all this time the company has improved significantly.”
In one simulated attack, Su said, the red team pretended to be job recruiters.
Related: Trader loses $1 million after signing consent to phishing token
One of the more notable attack methods in recent years is the “Zoom Meeting attack”, in which hackers convince victims to install malware pretending to be an update to a video conferencing application. Many of these attacks start with a imitation job offer, although some employ project funding or a partnership offer as bait.
As of September 2025, the primary user of the Venus protocol lost approximately $13 million after a malicious Zoom client compromised his computer, leading to the attacker being given control of his account. Venus halted the minutes and used an emergency management vote to recover the assets, and later returned $11.4 million worth of items to the victim.
“A job interview is just one scenario. There are others. For example, it could be that we offer a free invitation to a conference just to try to collect personal information and see how many of them actually fall for it,” Su said.
Su stated that employees are encouraged to perform well on tests because the results are reflected in their performance evaluations.
“If someone repeatedly fails a phishing attack, it will have a negative impact on their rating. This is an incentive to remain vigilant.”
Repeated, earnest failures may lead to their rating being reduced to the lowest level, which may result in their rejection, he added.
Warehouse: The fear of an AI-powered DeFi hacker epidemic is overblown for now – but not for long
