Binance treats its own employees as a potential attack surface — and tests them for it every single month. The exchange's Binance red team, an internal ethical hacking unit, runs simulated phishing attacks against staff on a monthly basis, according to Chief Security Officer Jimmy Su. Employees who repeatedly fail can see their performance ratings hit, and in serious cases, face dismissal.
Source: X(formerly Twitter)
Su told the exchange conducts phishing attacks on its own staff monthly specifically to track whether security awareness is genuinely improving over time. The scenarios aren't generic spam-style tests — they're built to mirror real attack patterns seen across the crypto industry. One version has the red team posing as job recruiters, reaching out with fake opportunities designed to see who engages. Another dangles a free conference invitation, testing whether employees will hand over personal information in exchange for access.
Binance has run this program for roughly three to four years, according to Su, and he said the company's overall "security hygiene" has improved substantially since the early days of the initiative, when employee awareness reportedly left a lot to be desired.
The consequences of failing scale with how often it happens. A single failure triggers mandatory remedial training. But Su was direct about what happens beyond that: repeated failures negatively affect an employee's performance rating, and severe, repeated lapses can push that rating low enough to result in termination. He framed the system as a deliberate incentive — tying real career consequences to test results to keep staff genuinely vigilant rather than treating the drills as a formality.
The exchange hasn't published failure rates or a count of how many employees have lost their jobs through the program, so the scale of enforcement remains unclear from outside the company. What is clear is that the tests span more than one department — HR-facing fake recruitment attempts and marketing-adjacent fake event invitations both point to a program built to cover multiple points of entry rather than a single team.
The reasoning behind this level of internal scrutiny isn't abstract. Social engineering — tricking a person rather than breaking a system — has become one of the dominant ways crypto platforms actually get breached. Industry data from AMLBot estimated that roughly 65% of Binance security incidents in 2025 were driven by social engineering rather than pure technical exploits.
Recent history backs that up. The February 2025 Bybit hack, in which North Korea-linked actors were blamed for stealing roughly $1.5 billion, remains the starkest example of what a single compromised access point can cost an exchange. Drift Protocol suffered a $285 million hack in April 2026 following a long-running social engineering campaign. And in September 2025, a Venus Protocol user lost roughly $13 million after a fake Zoom client compromised his device — a version of the same "job interview" or "partnership call" lure Binance's red team now tests employees against directly. Venus later recovered and returned positions worth $11.4 million to the affected user through an emergency governance vote, though the broader lesson for exchanges was clear: the weakest point in a security system is often a person answering an email.
For a platform Binance's size — reporting 323 million registered users and holding an estimated $137.7 billion in assets per DefiLlama — a single employee falling for a convincing fake recruiter message represents a real, not hypothetical, risk.
Binance's monthly phishing drills mark a shift in how top exchanges are approaching security — treating human behavior with the same seriousness as code audits. With social engineering behind a majority of last year's crypto incidents, the Binance red team program reflects an industry lesson learned the hard way: the biggest vulnerability isn't always in the smart contract.
This article is based on statements from Binance CSO Jimmy Su and other publicly available reporting as of July 27, 2026. Binance has not published specific failure rates, dismissal counts, or other internal metrics related to this program. This is not financial or investment advice.