Crypto

Binance tests staff monthly with fake phishing attacks



Binance runs simulated phishing attacks against its employees every month to reduce social engineering risks. 

Summary

  • Binance runs monthly phishing simulations to measure employee awareness and identify weak security habits early.
  • Workers who fail receive training, while repeated severe failures can lower ratings and risk dismissal.
  • Recruiter lures and fake conference invitations mirror scams already causing large losses across cryptocurrency firms.

Chief security officer Jimmy Su said the exchange’s red team creates fake attacks to test whether staff recognise suspicious messages, links and requests. Employees who fail must complete follow-up training. Repeated failures can also affect performance ratings and may lead to dismissal.

The programme targets human errors that attackers use to enter crypto companies. Binance has operated the drills for three to four years, according to Su. He said the company’s security habits had improved during that period. Binance reports 323 million registered users, while DefiLlama tracks about $137.5 billion in assets linked to the exchange.

Binance ties phishing tests to staff reviews

The red team uses methods that resemble real attacks. One test may present a fake recruiter offering a job. Another may promise free access to a conference and request personal details. The team records whether employees open the message, follow a link or share information that could expose company systems.

Su said workers who fail receive remedial training. Repeated failure “will negatively impact their rating,” he said. Severe cases may push a worker’s rating to the lowest level and result in dismissal. The policy gives employees a direct work-related reason to verify unexpected messages before responding.

Binance has described its red team as an internal group of ethical hackers that tests systems from an attacker’s point of view. The exchange also works with external researchers through bug bounty programmes. Its security model covers technical weaknesses and employee behaviour because attackers may enter through trusted accounts or devices.

Social engineering drives crypto security cases

The drills come as social engineering causes a large share of reported crypto losses. AMLBot reviewed more than 2,500 investigations and found that 65% of the cases it handled in 2025 began with social engineering rather than direct software exploits. Phishing represented 18% of its cases, while device compromise accounted for 13%.

Attackers often spend days or months building trust before asking a target to open a file, approve a wallet request or run a command. This method can defeat technical controls when a worker has access to private keys, administrator accounts or internal systems. Stolen credentials can lead directly to liquid assets that move across blockchains within minutes.

As crypto.news reported, the April 2026 attack on Drift Protocol drained about $285 million after attackers compromised an administrator key. Researchers linked the breach to social engineering and operational security failures rather than faulty smart contracts. The attacker changed market settings and withdrawal limits before removing assets across dozens of transactions.

Fake meetings and job offers remain common lures

Su identified fake job interviews as one scenario used in Binance’s tests. Real attackers use the same approach against developers, executives and investment teams. They may move a conversation from LinkedIn, Telegram or email into a video meeting, then claim that the victim’s camera or microphone needs an update.

North Korea-linked hackers have used compromised Telegram accounts and deepfake Zoom calls to contact crypto professionals. The attackers impersonated known contacts and asked victims to install files that claimed to fix audio problems. Those files instead delivered malware capable of accessing devices, browser data and crypto wallets.

A Venus Protocol user lost about $13.5 million in September 2025 after approving a malicious transaction. Venus paused its lending platform and recovered the assets through an emergency governance process. The case showed how a user-level compromise can place assets at risk even when a protocol’s contracts remain intact.

Frequent drills aim to reduce predictable errors

Monthly simulations let Binance compare failure rates and update training when attackers change their methods. A single annual course may not prepare staff for new lures built around current events, trusted contacts or job offers. Frequent tests also show whether workers report suspicious messages instead of only deleting them.

However, simulations cannot remove every risk. Attackers can hijack genuine accounts, copy earlier conversations and use artificial intelligence to create convincing audio, video and written messages. Firms still need access controls, transaction limits, device monitoring and fast incident response alongside employee training.

Su said Binance’s early security habits “left a lot to be desired,” but repeated testing brought improvement. The exchange treats staff awareness as part of its wider defence system rather than a one-time compliance task. Employees still need to verify unusual requests through a separate channel before opening files, sharing information or approving transactions.



Source link

What's your reaction?

Excited
0
Happy
0
In Love
0
Not Sure
0
Silly
0

You may also like

More in:Crypto

Leave a reply

Your email address will not be published. Required fields are marked *