Jul 26, 2026 · 10:49 AM
Subscribe
Home Crypto

Binance fires employees who repeatedly fail its monthly fake phishing attacks

Binance runs monthly simulated phishing attacks on its own staff via an internal red team, with repeat failures affecting performance ratings and potentially leading to dismissal. The program, confirmed by CSO Jimmy Su, has run for three to four years and directly addresses the social engineering vector used in the $1.5 billion Bybit hack.

Elroy Fernandes
· 5 min read · 574 reads
Binance fires employees who repeatedly fail its monthly fake phishing attacks

Binance says it runs phishing drills against its own staff every month. If employees keep failing, the test can stop being training and start costing them their jobs.

Every month, some Binance employees get what looks like a recruiter message on LinkedIn or a free conference invitation by email. They don't know it. The sender is their own company. That's the point.

Cointelegraph reported this week that Binance's red team, the exchange's internal ethical hacking unit, runs simulated phishing attacks to see who opens links, who follows instructions, and who hands over information that could expose internal systems. Workers who fail are sent into remedial training. Fail repeatedly and it goes into your performance review - and in serious cases, it can cost you your job.

Binance chief security officer Jimmy Su confirmed the program to Cointelegraph, saying: "We do phishing attacks on our own employees on a monthly basis just so we understand if our security hygiene is improving." He said the drills have run for three to four years, and that results have improved during that period. He didn't give failure rates. Keep that caveat in view.

For an exchange at Binance's scale, this isn't theatre. Cointelegraph noted that Binance reports 323 million registered users, while DefiLlama estimates the exchange holds about $137.7 billion in assets. If you're protecting that much customer money, a fake recruiter message is not a small internal exercise. It's a rehearsal for the thing attackers are already doing.

The Bybit lesson is still sitting there

The cleanest example is Bybit. On February 26, 2025, the FBI said North Korean TraderTraitor actors were responsible for stealing about $1.5 billion in virtual assets from the exchange on or about February 21, 2025. That remains the case every crypto security team should have pinned to the wall.

The breach wasn't a brute-force attack on Bybit's own exchange systems. Bybit later said a forensic review found that a Safe Wallet developer's credentials were compromised, allowing attackers to deceive signers into approving a malicious transaction. The Block, citing Sygnia's interim report, described a compromised Safe developer machine and a targeted script that altered what Bybit signers saw when approving the transfer.

That's why Binance's monthly tests matter. Fake recruiters luring developers into calls, chat messages nudging a victim toward a download, free-event bait collecting personal details - the shapes vary but the logic is the same. Su told Cointelegraph those are among the scenarios Binance uses. The attack does not need to break the blockchain if it can break the person who has access to the workflow.

AMLBot gave the same warning in numbers. According to a February 2026 Cointelegraph report based on AMLBot's internal casework, 65% of crypto incidents the firm investigated in 2025 involved social engineering, access failures, compromised devices, weak verification or delayed detection rather than smart contract bugs. AMLBot said the data came from about 2,500 internal investigations and should not be read as an industry-wide crime measure. That's a useful limit. It's still a loud signal.

The hard part is making the test count

Binance can afford a large security machine. The company has said it spends about $300 million a year on compliance and has roughly 1,500 employees in safety and oversight roles. Binance also says its systems intercepted $10.53 billion in potential fraud, scams and anomalous activity between 2025 and the first quarter of 2026. Those are company figures, not independent audit findings, but they show how Binance wants you to read its posture: security as daily operations, not a yearly slide deck.

Most startups handling crypto funds don't have that budget. They don't need it to learn the obvious part. Monthly simulated phishing campaigns are cheap now. The expensive part is cultural: making the result matter enough that employees treat a suspicious message as part of the job, not as an annoying corporate quiz.

Here's the thing. Training that nobody remembers is decoration. Binance's approach is sharper because it ties repeated failure to performance consequences. You can dislike that. You can call it harsh. But after Bybit, Safe, Lazarus and TraderTraitor, the softer version is harder to defend for any firm holding customer assets.

There is still a line to watch. Security programs can become punitive in a way that makes people hide mistakes rather than report them quickly. A good red team exercise should teach staff to pause and verify - and when something looks wrong, escalate rather than click through. It should not teach them to panic after one bad click. Binance says failed employees get remediation first, and that sequence matters.

The real test is not whether a company can shame workers into spotting every fake message. Nobody will. The test is whether the company builds habits strong enough that one mistake doesn't become a $1.5 billion incident. Binance is betting that monthly pressure changes behavior before attackers get their chance.

Also read: Bitcoin mining now draws majority of its power from sustainable sources as hydro leads the green pushBitMart announces it is shutting down as BMX token crashes over 60% and withdrawal fears grip usersWashington puts Bitcoin in the same program as Palantir and Anduril, treating it as geopolitical infrastructure

TOPICS
Elroy is a digital marketer and developer from Goa, with over a decade of experience web development and marketing. He has been associated with several startups and serves currently as an Editor to the Asia Pacific Industrial magazine. He occasionally writes on Startup Fortune about technology and automation.
Related Articles
More posts →
Loading next article…
You're all caught up