AUTO-UPDATED

Binance ‘red teams’ its own staff every month to keep hackers out

Binance conducts monthly simulated phishing attacks against its employees to improve internal security hygiene and mitigate the growing threat of social engineering campaigns targeting the cryptocurrency industry.

Key Points

  • Binance’s internal "red team" executes monthly phishing simulations, including fake job recruitment and conference invitations, to test staff vigilance.
  • Employees who repeatedly fail these security tests face negative performance reviews, which can ultimately lead to termination.
  • Chief security officer Jimmy Su reports that the program has significantly improved the company's overall security posture over the last four years.
  • Social engineering remains a primary threat, accounting for approximately 65% of cryptocurrency security incidents in 2025 according to AMLBot data.
  • Binance currently manages $137.7 billion in assets and serves 323 million registered users, making it a high-value target for malicious actors.

Why it Matters

Social engineering has become a leading vector for major financial losses in the decentralized finance sector, as evidenced by recent high-profile hacks involving malicious software. By institutionalizing rigorous security testing, Binance aims to reduce the risk of human error that could compromise the world's largest cryptocurrency exchange.
Cointelegraph Published by Cointelegraph by Felix Ng
Read original