Cryptocurrency trade Binance runs simulated phishing assaults in opposition to its personal workers and might hearth employees who repeatedly fail the checks, in response to Binance chief safety officer Jimmy Su.
The faux assaults are performed by Binance’s pink group, an inner moral hacking unit whose job is to interrupt into programs to determine vulnerabilities.
“We do phishing assaults on our personal workers on a month-to-month foundation simply so we perceive if our safety hygiene is bettering,” Su instructed Cointelegraph. “Those which have failed it, we’ll do remediation coaching.”
The measure exhibits the lengths crypto corporations will go to arrange for social engineering assaults. Binance, the most important crypto trade on the earth, studies 323 million registered customers, whereas DefiLlama estimates the trade holds $137.7 billion in property.

Jimmy Su, chief safety officer at Binance. Supply: Binance
In February, AMLBot estimated that 65% of crypto safety incidents in 2025 have been pushed by social engineering. In April, Drift Protocol suffered a $285 million hack, which got here after a long-term social engineering marketing campaign.
Su mentioned Binance has been working these simulated assaults for 3 to 4 years.
“At first, the safety hygiene left quite a bit to be desired. However after this period of time, the corporate has improved considerably.”
One of many simulated assaults entails the pink group posing as job recruiters, mentioned Su.
Associated: Dealer loses $1M after signing phishing token approval
One of many extra well-known assault strategies lately has been the “Zoom assembly assault,” the place hackers trick victims into putting in malware disguised as an replace to the video conferencing app. Many of those assaults begin with a faux job alternative, although some use venture funding or a partnership proposal because the lure.
In September 2025, a significant Venus Protocol person misplaced roughly $13 million after a malicious Zoom consumer compromised his laptop, main him to grant an attacker management over his account. Venus paused the protocol and used an emergency governance vote to get well the property, later returning positions value $11.4 million to the sufferer.
“The interview course of is only one state of affairs. There are different ones. For instance, it could possibly be that we’re providing some form of free convention invite simply to attempt to accumulate private data and see what number of of them will truly fall for it,” mentioned Su.
Su mentioned workers are incentivized to carry out properly on the checks as a result of the outcomes are mirrored of their efficiency evaluations.
“If somebody repeatedly fails the phishing-simulation assault, that can negatively influence their score. That’s the motivation to be vigilant.”
Repeated, extreme failures may result in their score to “backside out,” which may see them dismissed, he mentioned.
Journal: Fears of AI-driven DeFi hack epidemic overstated for now — however not for lengthy
