EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Binance conducts monthly "red team" tests for employees to prevent hackers

2026-07-26 12:11:08
Bookmark

Jimmy Su, chief security officer of Binance, said the exchange is actively conducting simulated fishing tests for employees and linking repeated failures to employment results. Su revealed that the internal "red team" conducts fishing drills once a month to assess whether employees 'safety awareness has improved.

According to Su, employees who failed the test did not receive only one retraining. Binance conducts remedial training for those who fail to meet the standards, and continued repeated failures may ultimately affect their position within the company, reflecting the role played by social engineering in real cybersecurity incidents.

Key Points

Binance conducts monthly simulated phishing attacks against employees as part of its ongoing internal security plan. The simulated attack was performed by the Binance Red Team, which focuses on ethical hacking and vulnerability discovery. Employees who fail tests receive remedial training, while repeated failures can have a negative impact on performance evaluations and even work results. Binance said the program has been in operation for three to four years, and Su said employees 'safety literacy has improved significantly during this period. Companies use a variety of real baits-such as fake recruiter contacts and other "information-gathering" strategies-to test employees 'resilience.

Why Binance tests employees

Su said Binance conducted fishing simulations "just to understand whether our safety literacy is improving" and viewed the move as a practical measure rather than a theoretical awareness campaign. According to Su, the red team's responsibility is to try to simulate intrusions and interactions in real attack paths, and then feed the results back into training. Binance is often described as a large target in the cryptocurrency space due to its user base and market size. Su did not provide more internal data in the interview, but the context highlighted the risks: Binance reported 323 million registered users, while the exchange is estimated to hold US$137.7 billion in assets.

The key revelation for investors and traders is that large exchanges view human behavior as part of their threat models. The more companies rely on operational processes-such as customer support, account access, authentication, and internal tools-the more social engineering becomes a risk factor that technical defenses cannot completely eliminate.

Social engineering is still a common route of intrusion

Su's comments are based on widespread industry reports that social engineering is a major driver of cryptocurrency security incidents. It is estimated that 65% of cryptocurrency security incidents in 2025 will be driven by social engineering. In addition, previous reports pointed out that a long-term social engineering attack led to a $285 million hacking attack on a protocol. Su also said the mock attack had been in place for three to four years. He believes that safety literacy has improved dramatically since the program was launched: "At first, safety literacy was not ideal. But over time, the company has improved significantly."

This is important because it highlights a specific operational change: Binance does not view awareness training as a one-time task, but rather as an ongoing feedback loop. For organizations, the key shift is from "teach and forget" to "test, measure, execute".

Simulated attack form: Recruitment bait and data collection scenarios

One scenario used by Binance is impersonating a recruiter. Su said red teams would disguise themselves as recruiters-a method that mimics a common pattern in phishing incidents across industries, where "legal-sounding" connections become entrances to further manipulation. Su also described another bait: fake "free meeting invitations" designed to collect personal information and test how many employees are deceived. He emphasized that the job interview process is just one of the many scenarios used by the Binan Red Team.

These details are important because social engineering attacks in the cryptocurrency space do not always appear in the obvious form of "clicking on this link". They may be structured as legitimate professional connections, schedule requests or follow-up-channels that may seem normal to employees who may have been trained to recognize traditional phishing emails. Another well-known technology mentioned in the interview was the "Zoom conferencing attack," in which attackers trick victims into installing malware disguised as video conferencing updates. Many such attacks start with fake job offers, but other professional decoys may also be used, such as project financing or partnership proposals.

Failure Handling: Remediation, Evaluation and Potential Firing

Binance's approach does not stop at simulation testing. Su said employees who fail the fishing simulation need to receive remedial training. He also described incentives linked to results, noting that performance reviews would reflect test results. Su bluntly said: "If someone repeatedly fails a phishing simulation attack, it will have a negative impact on their rating. That's the incentive to be vigilant." He further said that repeated serious failures could lead to performance ratings being "bottomed out" and could even be fired. Although Su did not clearly state the specific criteria or timeline for dismissal in the interview, the principle is clear: Binance views repeated exposure to social engineering as a personnel risk, not just a training gap.

Beyond centralized exchanges, similar social engineering developments have also caused significant losses in the DeFi ecosystem. For example, previous reports mentioned an incident in which a user of a certain protocol allegedly hacked into a computer through a malicious Zoom client, causing the attacker to control his account and lose approximately US$13 million. The agreement was subsequently suspended and enabled an emergency governance vote to recover assets, ultimately returning positions worth $11.4 million to victims.

These examples reinforce the broader view behind Binance's internal testing: Even if attackers target individuals rather than systems, the consequences can still have catastrophic effects on a large scale. The next thing readers should focus on is whether Binance's approach-monthly red-team fishing testing, remedial training, and performance-linked consequences-will become a more standard model for large cryptocurrency companies as regulators and stakeholders increasingly focus on operational security beyond code and infrastructure.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP