Back Finance.Biggo Binance Runs Monthly Mock Phishing Drills on Staff; Repeated Failures Can Lead to Termination
Binance, the world's largest cryptocurrency exchange, has formalized a policy of conducting monthly simulated phishing attacks on all employees, with staff who repeatedly fail the drills facing potential termination.
In an interview with cryptocurrency media outlet CoinTelegraph on the 26th (local time), Binance Chief Security Officer Jimmy Su stated, "We run internal phishing attack drills every month to gauge whether employees' security hygiene is actually improving," adding that "staff who fail the test are provided with remedial training."
These simulated attacks are led by Binance's internal white-hat hacking unit, the "Red Team," which is tasked with attempting to penetrate internal systems like real hackers to identify vulnerabilities.
According to CSO Jimmy Su, the training program began approximately three to four years ago. "Initially, security awareness was significantly lacking, but it has now markedly improved across the company," he assessed.
The simulated attack scenarios faithfully replicate real-world hacking techniques. A representative example involves the Red Team impersonating recruiters. CSO Su outlined various attack vectors, noting that "attempts to harvest personal information using free conference invitations as bait are also included."
The "Zoom meeting attack," a tactic frequently employed by hackers in recent years, is also incorporated into the training scenarios. This method tricks targets into installing malware disguised as a video conferencing app update, often using fake job opportunities, project investment offers, or partnership proposals as lures.
In fact, last September, a major user of the decentralized finance (DeFi) protocol Venus Protocol was infected with a malicious Zoom client, resulting in the theft of approximately $13 million (~19 billion won) in assets. At the time, Venus Protocol temporarily halted the protocol through an emergency governance vote to recover the assets, subsequently returning positions worth roughly $11.4 million (~17 billion won) to the victim.
The results of Binance's simulated phishing drills directly impact employee performance reviews. CSO Jimmy Su asserted, "Repeatedly failing phishing simulation tests negatively affects evaluation scores," and "if serious failures recur, it can lead to the lowest performance rating and result in termination." This represents a stringent HR policy effectively designed to instill a sense of urgency across the entire workforce.
The backdrop to Binance's intensified internal security training is the surging threat of social engineering attacks industry-wide. Anti-money laundering solutions provider AMLBot estimated in a February report that "65% of cryptocurrency security incidents in 2025 stemmed from social engineering."
According to the 2026 Crypto Crime Report released earlier this year by blockchain analytics firm Chainalysis, the total value of cryptocurrency stolen through hacks in 2025 amounted to $3.4 billion. Losses were concentrated in a few large-scale incidents, with the top three accounting for 69% of the total stolen funds. North Korea-linked groups alone were estimated to have siphoned off approximately $2 billion.
In April, the decentralized exchange Drift Protocol suffered a hack worth approximately $285 million (~420 billion won) following a prolonged social engineering campaign. Starting in the fall of 2025, attackers impersonated a quantitative trading firm, building relationships with protocol insiders at various cryptocurrency events. They then exploited Solana's "durable nonce" feature to trick security council members into pre-signing transactions without their knowledge, ultimately gaining admin privileges. Drift assessed with moderate confidence that the operation was the work of a North Korea-linked group.
Note: All three incidents originated from intrusions targeting people and endpoints, not flaws in smart contract code. The Bybit incident stands as the single largest theft in cryptocurrency history.
Binance currently has 323 million registered users, with custodial assets estimated at $137.7 billion (~201 trillion won) by cryptocurrency data platform DefiLlama. As the world's largest exchange tasked with safeguarding astronomical sums of customer assets, the company appears to have adopted the extreme measure of linking individual employee security awareness directly to performance evaluations.
Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
