
Chief Security Officer Jimmy Su said the exchange has run internal red-team simulations for more than three years, as crypto firms step up defenses against social-engineering attacks.
Binance Chief Security Officer Jimmy Su said the exchange conducts monthly internal phishing simulations through its red team and has been doing so for more than three years to test whether employee security behavior is improving. Staff who fail the tests undergo remedial training, while repeated failures can hurt performance reviews and may ultimately lead to dismissal. Su said the company’s security hygiene has improved meaningfully since the program began. The practice highlights how major crypto firms are hardening internal defenses as social engineering remains a major driver of industry breaches. AMLBot said roughly 65% of crypto security incidents in 2025 were tied to social engineering, while fake recruiter outreach and conference invitations are among the lures used in Binance’s drills.