Cryptocurrency trade Binance runs simulated phishing assaults towards its personal workers and may fireplace workers who repeatedly fail the assessments, in accordance with Binance chief safety officer Jimmy Su.
The faux assaults are carried out by Binance’s pink staff, an inside moral hacking unit whose job is to interrupt into methods to establish vulnerabilities.
“We do phishing assaults on our personal workers on a month-to-month foundation simply so we perceive if our safety hygiene is enhancing,” Su informed Cointelegraph. “Those which have failed it, we’ll do remediation coaching.”
The measure reveals the lengths crypto firms will go to arrange for social engineering assaults. Binance, the most important crypto trade on the planet, studies 323 million registered customers, whereas DefiLlama estimates the trade holds $137.7 billion in belongings.

Jimmy Su, chief safety officer at Binance. Supply: Binance
In February, AMLBot estimated that 65% of crypto safety incidents in 2025 have been pushed by social engineering. In April, Drift Protocol suffered a $285 million hack, which got here after a long-term social engineering marketing campaign.
Su mentioned Binance has been operating these simulated assaults for 3 to 4 years.
“At first, the safety hygiene left quite a bit to be desired. However after this period of time, the corporate has improved considerably.”
One of many simulated assaults entails the pink staff posing as job recruiters, mentioned Su.
Associated: Dealer loses $1M after signing phishing token approval
One of many extra well-known assault strategies in recent times has been the “Zoom assembly assault,” the place hackers trick victims into putting in malware disguised as an replace to the video conferencing app. Many of those assaults begin with a faux job alternative, although some use challenge funding or a partnership proposal because the lure.
In September 2025, a significant Venus Protocol person misplaced roughly $13 million after a malicious Zoom consumer compromised his pc, main him to grant an attacker management over his account. Venus paused the protocol and used an emergency governance vote to get better the belongings, later returning positions price $11.4 million to the sufferer.
“The interview course of is only one situation. There are different ones. For instance, it could possibly be that we’re providing some type of free convention invite simply to attempt to accumulate private data and see what number of of them will really fall for it,” mentioned Su.
Su mentioned workers are incentivized to carry out nicely on the assessments as a result of the outcomes are mirrored of their efficiency opinions.
“If somebody repeatedly fails the phishing-simulation assault, that can negatively influence their score. That’s the inducement to be vigilant.”
Repeated, extreme failures might result in their score to “backside out,” which might see them dismissed, he mentioned.
Journal: Fears of AI-driven DeFi hack epidemic overstated for now — however not for lengthy


