Cryptocurrency exchange Binance subjects its employees to simulated phishing attacks every month as part of efforts to strengthen defenses against social engineering. An internal red team of ethical hackers designs and executes the exercises to identify weaknesses in staff security practices. Employees who fail receive remediation training. Results form part of performance evaluations. Repeated severe failures can lower ratings and may result in dismissal.
The program has operated for three to four years. Security hygiene across the organization has improved markedly over that period. Simulated scenarios include fake recruitment approaches and offers of complimentary conference invitations designed to extract personal information.
Social engineering accounted for roughly 65 percent of crypto security incidents in 2025. Recent examples include a 285 million dollar exploit at Drift Protocol that followed an extended social-engineering campaign and a 13 million dollar loss at Venus Protocol linked to a malicious video-conferencing application. Binance serves 323 million registered users and holds approximately 137.7 billion dollars in assets.