EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Binance conducts monthly red team tests on internal employees to prevent hackers

2026-07-26 12:12:30
Bookmark

Binance conducts simulated phishing tests on employees, and those who fail many times face the risk of dismissal.

Su Jimi, chief security officer of Binance, a cryptocurrency exchange, said that Binance regularly conducts simulated phishing attacks on its employees and may fire employees who fail the test many times. These simulated attacks are carried out by Binance's "red team"-an internal team of ethical hackers responsible for breaking into systems to discover security vulnerabilities.

"We test employees for phishing attacks every month to see if our security awareness is improving," Su told Cointelegraph. "For employees who fail, we will arrange remedial training." This measure shows that cryptocurrency companies are fully prepared to guard against social engineering attacks. As the world's largest cryptocurrency exchange, Binance reports that it has 323 million registered users, while DefiLlama estimates that the platform holds US$137.7 billion in assets.

Social engineering attacks become major threat

In February this year, AMLBot estimated that 65% of cryptocurrency security incidents in 2025 were triggered by social engineering attacks. In April, Drift Protocol suffered a months-long social engineering attack that resulted in the theft of $285 million. Su said Binance has been conducting such simulated attacks for three to four years. "At first, awareness of safety protection really needed to be improved. But after this period of time, the company's overall level has improved significantly." Su mentioned that one of the simulated attacks was the red team disguised as recruiters.

Typical tactics such as "Zoom Conference Attack"

A well-known attack in recent years has been the "Zoom conferencing attack"-in which hackers trick victims into installing malware disguised as video conferencing software updates. Many of these attacks start with fake job opportunities, and some use project funding or cooperation proposals as bait. In September 2025, a major Venus agreement owner was hacked into his computer due to a malicious Zoom client, losing approximately US$13 million. The attacker then took control of his account. Venus suspended the agreement and recycled assets through an emergency governance vote, ultimately returning positions worth $11.4 million to victims.

"The interview process is just one scenario. There are others, like we might offer some kind of free meeting invitation, try to collect personal information and see how many people will actually fall for it,"Su said.

Test results are linked to performance

Su said that employees are motivated to perform well in tests because the results will be reflected in performance reviews. "If someone repeatedly fails in a fishing simulation test, it will have a negative impact on their rating. That's the incentive to be vigilant." He added that multiple serious failures could cause the rating to "bottom out", at which time employees could be fired.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP