[ Story · STORY ]

Binance phish-tests staff monthly

Binance runs monthly simulated phishing attacks on staff and can fire repeat failures, per CSO Jimmy Su.

STORY·July 26, 2026·3 min read·By Gintautas Nekrosius
A single red fishhook dangling above a grid of identical cream-colored office chairs
The weakest link in exchange security isn't code. It's a calendar invite.

Binance runs fake phishing attacks against its own employees every month and can fire staff who keep failing them, according to chief security officer Jimmy Su. The exchange's internal red team poses as recruiters, conference organizers and partners to see who clicks.

The numbers behind the drill

Binance has run these simulated attacks for three to four years, testing a workforce behind a platform with 323 million registered users and, per DefiLlama, $137.7 billion in assets. AMLBot estimated in February that 65% of 2025's crypto security incidents traced back to social engineering, not code exploits. The scale of recent damage backs that up: Drift Protocol lost $285 million in April after a long social-engineering campaign, and a Venus Protocol user lost roughly $13 million in September after a fake Zoom client handed an attacker control of his machine. Su says employees who repeatedly fail the monthly test get remediation training first, then a hit to their performance rating, and a pattern of failures can end in dismissal.

Why the target moved from code to people

The read here is simple: exchanges have spent a decade hardening infrastructure, and attackers responded by going around it instead of through it. A phishing email that gets one employee to install a fake Zoom update bypasses cold storage, multisig and every audit a protocol has ever paid for. Binance's answer is to treat its own staff as the attack surface and drill them like a fire alarm, monthly, with real consequences attached to failure. That's a different posture than most of the industry, where security training is an annual slideshow nobody remembers. Making it show up in a performance review is the part that actually changes behavior, because it ties a vague security culture goal to something an employee's manager checks every quarter. The uncomfortable implication is that firms without this kind of recurring, consequence-bearing test are running on hope. Given that AMLBot's own number puts social engineering behind two-thirds of last year's incidents, hope isn't holding.

What would prove this out

The test of Su's approach is whether Binance's own incident rate for social-engineering breaches actually falls over the three to four years he says the program has run, and whether other major exchanges start publishing similar recurring red-team numbers instead of one-off penetration test summaries. If competitors start citing pass rates the way Binance does, this becomes an industry standard rather than a talking point.

Gintautas Nekrosius is the founder and editor of Stack and Story. He spent more than a decade in technology and crypto, including senior marketing roles at companies in the Animoca Brands and NordVPN groups, and worked on token launches and go-to-market from the inside. He started Stack and Story to write the independent read he could not find: crypto and markets explained plainly, by someone who has seen how the machine works. The publication holds no tokens and takes no trades.

DisclosureStack and Story holds no position in the assets discussed and earns nothing from their movement. This is analysis, not financial advice. Do your own research.

Understand crypto. Decide for yourself.

The numbers that moved, and the reason they did, every Sunday, free.

Free · Independent · Unsubscribe anytime · Privacy