Binance phish-tests staff monthly
Binance runs monthly simulated phishing attacks on staff and can fire repeat failures, per CSO Jimmy Su.

Binance runs fake phishing attacks against its own employees every month and can fire staff who keep failing them, according to chief security officer Jimmy Su. The exchange's internal red team poses as recruiters, conference organizers and partners to see who clicks.
The numbers behind the drill
Binance has run these simulated attacks for three to four years, testing a workforce behind a platform with 323 million registered users and, per DefiLlama, $137.7 billion in assets. AMLBot estimated in February that 65% of 2025's crypto security incidents traced back to social engineering, not code exploits. The scale of recent damage backs that up: Drift Protocol lost $285 million in April after a long social-engineering campaign, and a Venus Protocol user lost roughly $13 million in September after a fake Zoom client handed an attacker control of his machine. Su says employees who repeatedly fail the monthly test get remediation training first, then a hit to their performance rating, and a pattern of failures can end in dismissal.
Why the target moved from code to people
The read here is simple: exchanges have spent a decade hardening infrastructure, and attackers responded by going around it instead of through it. A phishing email that gets one employee to install a fake Zoom update bypasses cold storage, multisig and every audit a protocol has ever paid for. Binance's answer is to treat its own staff as the attack surface and drill them like a fire alarm, monthly, with real consequences attached to failure. That's a different posture than most of the industry, where security training is an annual slideshow nobody remembers. Making it show up in a performance review is the part that actually changes behavior, because it ties a vague security culture goal to something an employee's manager checks every quarter. The uncomfortable implication is that firms without this kind of recurring, consequence-bearing test are running on hope. Given that AMLBot's own number puts social engineering behind two-thirds of last year's incidents, hope isn't holding.
What would prove this out
The test of Su's approach is whether Binance's own incident rate for social-engineering breaches actually falls over the three to four years he says the program has run, and whether other major exchanges start publishing similar recurring red-team numbers instead of one-off penetration test summaries. If competitors start citing pass rates the way Binance does, this becomes an industry standard rather than a talking point.
