Binance Red Team Fights Crypto Social Engineering from Within
Binance, one of the largest cryptocurrency exchanges, takes its internal security seriously. Its Binance Red Team, an ethical hacking unit, conducts monthly phishing simulations against employees to test their awareness and resistance to social engineering attacks.
The program has been in place for three to four years, according to Chief Security Officer Jimmy Su. The simulated attacks are designed to mirror real attack patterns seen across the crypto industry, with scenarios including fake job recruiters and conference invitations that aim to trick employees into handing over personal information.
Employees who repeatedly fail these tests can face negative consequences, including mandatory remedial training for a single failure. However, repeated failures can lead to a decline in an employee's performance rating, potentially resulting in termination.
The reasoning behind this level of internal scrutiny is the prevalence of social engineering attacks in the crypto industry. AMLBot estimates that 65% of Binance security incidents in 2025 were driven by social engineering rather than technical exploits.