Binance ‘red teams’ its own staff every month to keep hackers out
Binance, the largest crypto exchange, runs simulated phishing attacks on its employees to test their security hygiene. The company's red team poses as job recruiters or offers fake conference invites to trick employees into revealing personal information.
Intelligence analysis by Llama

Binance regularly tests its employees for security hygiene by conducting simulated phishing attacks. The company's red team poses as job recruiters or offers fake conference invites to trick employees into revealing personal information. Employees who fail the tests are given remediation training, and repeated failures can lead to dismissal.
Imagine you're at work and someone calls you, saying they're from a company you want to work for. They ask you for your password and other personal info. That's a phishing attack. Binance, a big crypto company, tests its employees to see if they can spot these fake calls. If they fail, they get extra training to help them be more careful.
Analysis
A $60B Vote of Confidence
Binance, the largest crypto exchange in the world, reports 323 million registered users, while DefiLlama estimates the exchange holds $137.7 billion in assets. The company's efforts to combat social engineering attacks are a major concern in the crypto industry, where 65% of security incidents in 2025 were driven by social engineering.
Why Social Engineering Matters
In February, AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering. In April, Drift Protocol suffered a $285 million hack, which came after a long-term social engineering campaign. Binance's chief security officer, Jimmy Su, said the company has been running these simulated attacks for three to four years.
The Road Ahead
Su said employees are incentivized to perform well on the tests because the results are reflected in their performance reviews. "If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That's the incentive to be vigilant," he said. Repeated, severe failures could lead to their rating to "bottom out," which could see them dismissed, he said.
Key points
- Binance runs simulated phishing attacks on its employees to test their security hygiene.
- The company's red team poses as job recruiters or offers fake conference invites to trick employees into revealing personal information.
- Employees who fail the tests are given remediation training, and repeated failures can lead to dismissal.
- Binance's efforts to combat social engineering attacks are a major concern in the crypto industry.
- The company's measures show the lengths crypto companies will go to prepare for these attacks.
Binance's efforts to combat social engineering attacks could set a new standard for the crypto industry. If the company's measures are successful, it could reduce the number of security incidents caused by social engineering.
Despite Binance's efforts, social engineering attacks remain a major concern in the crypto industry. If employees are not vigilant, they could still fall victim to these attacks, which could result in significant financial losses.



