News
Platform news and market context
News
Platform news and market context
Binance CSO Reveals Monthly Phishing Drills and Remediation Training to Thwart Hackers
Cryptocurrency exchange Binance conducts monthly simulated phishing attacks on its own employees to bolster security against social engineering, according to Chief Security Officer Jimmy Su. Staff who repeatedly fail these internal tests may face termination, as their results are linked to performance reviews.

In an effort to guard against the growing threat of social engineering, which has become a primary cause of security breaches in the cryptocurrency industry, Binance is methodically testing the security awareness of its employees.
According to Jimmy Su, the chief security officer at Binance, the exchange deploys simulated phishing campaigns against its own staff. He confirmed that employees who consistently fail these internal security assessments could potentially be dismissed.
These mock attacks are orchestrated by Binance’s "red team," an in-house unit of ethical hackers tasked with infiltrating the company's systems to uncover security weaknesses.
“We do phishing attacks on our own employees on a monthly basis just so we understand if our security hygiene is improving,” Su explained to Cointelegraph. “The ones that have failed it, we will do remediation training.”
This rigorous internal measure highlights the significant lengths crypto firms are willing to go to defend against social engineering tactics. As the world's largest crypto exchange, Binance serves 323 million registered users and, according to DefiLlama estimates, manages assets valued at $137.7 billion.
Su mentioned that Binance has been implementing these simulated attacks for the past three to four years.
The Pervasive Threat of Social Engineering
The danger posed by such attacks is substantial. In February, a report from AMLBot estimated that social engineering was the driver behind 65% of crypto security incidents in 2025. A notable example occurred in April when Drift Protocol suffered a $285 million hack that originated from an extended social engineering campaign.
To illustrate the types of simulations used, Su described a scenario where the red team impersonates job recruiters to test employees.
“The interview process is just one scenario. There are other ones. For example, it could be that we are offering some kind of free conference invite just to try to collect personal information and see how many of them will actually fall for it,” stated Su.
A notorious hacking technique in recent times has been the "Zoom meeting attack." In this method, cybercriminals deceive their targets into downloading malware that is disguised as a legitimate update for the video conferencing application. These attacks often begin with a fraudulent job offer, although some exploit lures like project funding or partnership proposals.
A real-world case from September 2025 saw a major Venus Protocol user lose approximately $13 million. The incident occurred after a malicious Zoom client compromised the user's computer, allowing an attacker to gain control of his account. In response, Venus suspended its protocol and initiated an emergency governance vote to reclaim the funds, later returning positions valued at $11.4 million to the victim.
Performance Reviews and Potential Dismissal
To ensure staff take the drills seriously, Su said employees are incentivized through their job performance evaluations. The outcomes of the security tests are directly incorporated into their reviews.
He cautioned that repeated and serious failures on these tests could cause an employee's performance rating to “bottom out,” a situation that could ultimately lead to their dismissal from the company.
Discussion about this post
No comment yet
Be the first to share your opinion!