Crypto

Binance Fires Staff Who Repeatedly Fail Internal Phishing Tests, Security Chief Reveals

The exchange subjects workers to monthly ethical hacking simulations where failing can cost employees their jobs.

Global cryptocurrency platform Binance subjects its workforce to regular simulated phishing campaigns, enforcing operational rules under which repeated failures can lead to employee termination.

The mandatory drills, managed by the exchange’s internal ethical hacking unit—known as a red team—are designed to test and reinforce employee resistance against social engineering tactics. Chief Security Officer Jimmy Su stated that Binance has operated these mock attacks on a monthly basis for three to four years to evaluate whether internal security standards are improving across the company.

Employees who fall for simulated phishing lures are initially mandated to complete remediation training. However, performance during these security evaluations directly influences annual performance reviews. Su noted that continuous or severe failures can cause an employee’s evaluation rating to drop to the lowest possible level, ultimately leading to dismissal.

To test personnel, the internal red team deploys schemes modeled after real-world cyberthreats. Common tactics include masquerading as executive recruiters extending false employment offers or dispatching fake conference invitations intended to trick workers into surrendering personal credentials.

Human manipulation has increasingly outpaced purely technical compromises as the primary threat vector targeting digital asset platforms. While smart contract bugs can be mitigated through code audits, human-targeted exploits trick individuals into bypassing technical controls, a vulnerability addressed in federal cybersecurity guidance on social engineering. Security tracking firm AMLBot estimated that approximately 65 percent of all crypto security incidents in 2025 were driven by social engineering.

One widespread tactic used by threat actors involves compromised video conferencing software, commonly referred to as a Zoom meeting attack. Cybercriminals establish contact under the guise of job interviews, partnership deals, or project funding before coercing targets to download fake software updates that secretly contain malware.

Such lures have resulted in substantial capital losses across the industry. In April, decentralized finance platform Drift Protocol fell victim to a $285 million compromise following an extended social engineering operation. In another major event in September 2025, a high-value user on Venus Protocol lost roughly $13 million after executing a malicious video conferencing application that compromised their system. Venus Protocol later executed emergency governance procedures to freeze protocol activity, successfully recovering and returning $11.4 million in positions to the user.

Rigorous internal security measures are critical for major institutions safeguarding digital assets. Binance currently reports 323 million registered users, with asset tracking service DefiLlama estimating that the exchange holds $137.7 billion in platform reserves.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button