🟢 Verified 📰 News

Even Binance phishes its own staff — why social engineering is crypto's biggest threat

· ✍️ altrookie editorial · 👁️ Read-only

Binance, the world's largest crypto exchange, said it sends fake phishing attacks to its own employees every month and c…


Binance, the world's largest crypto exchange, said it sends fake phishing attacks to its own employees every month and can dismiss staff who repeatedly fall for them. According to Binance chief security officer Jimmy Su, the goal is to keep the company's “security hygiene” sharp. The bigger lesson for everyone else is why a giant exchange bothers: fooling people, rather than breaking software, has become the leading way crypto is stolen — and the same tricks target ordinary users.

The simulated attacks are run by Binance's “red team,” an in-house group that tries to break into its own systems to find weaknesses. Su said the company has been phishing its own staff for three to four years, sending fake messages and giving extra training to those who fail. Employees' results feed into their performance reviews, and repeated, serious failures can cost someone their job.

The reason for that intensity is in the numbers. Security firm AMLBot estimated that 65% of crypto security incidents in 2025 came from social engineering — manipulating a person rather than exploiting code. In April, Drift Protocol lost about $285 million in a hack that followed a long-running social engineering campaign.

The methods are worth knowing because they reach beyond company walls. Su said the red team sometimes poses as job recruiters, and a well-known variant is the “Zoom meeting attack,” where victims are talked into installing malware disguised as an update to the video app — often after a fake job offer, funding pitch or partnership proposal. In September 2025, a Venus Protocol user lost roughly $13 million after a malicious Zoom client took over his computer; the project later paused and used an emergency vote to return positions worth about $11.4 million. Another lure Su described is a free conference invite designed just to collect personal information.

You don't have to work at an exchange to be a target — the same scripts land in ordinary inboxes and chats. Be suspicious of unexpected job offers, requests to “install this app to join the call,” and free invitations that ask for personal details. As a rule, don't install software you didn't go looking for, double-check meeting and download links, and never approve a transaction or sign a request you don't fully understand. This is information, not advice, but slowing down is usually what keeps an attack from working.