Testing People, Not Just Systems: Inside Binance’s Red Team Tactics

two gold bitcoins sitting next to a binance sign

Binance is the world’s leading blockchain ecosystem and one of the leading global cryptocurrency exchange providers, founded in 2017. 

Amid the expanding crypto adoption worldwide, there is a continuously growing threat in the industry, and one of them remains to be the single greatest catalyst for cybersecurity incidents worldwide: social engineering or phishing. 

To address this concern, Binance regularly conducts trainings to its employees to test its cybersecurity framework, while most companies only rely on informational videos and call it a day. 

Binance has established ‘Red Team’, its own internal ethical hacking unit, that launches real-life scenarios that mirror real-world phishing and social engineering tactics. The unit’s goal is simple: identify human vulnerabilities.  

Increasing Crypto Scams Worldwide 

Binance, the largest crypto exchange in the world, has reportedly claimed 323 million registered users. The exchange is estimated to hold almost $137.7 billion in assets. 

According to a media report, 65% of crypto security incidents in 2025 were driven by social engineering, and it was due to people getting tricked in the pretense of financial crimes. 
 
Most knowns attack methods include the use of the “Zoom meeting attack”, where hackers usually trick its victims by installing malware disguised through fake jobs opportunity that sends out Zoom meeting links. 
 
One of the known incidents of this type of attack occurred in September 2025, where a major Venus’s protocol user lost roughly $13 million after a Zoom meeting with a malicious client, unintentionally granting the attacker a control over his account.  

Venus paused the protocol and used an emergency governance vote to recover the assets, recovering a worth of $11.4 million to the victim’s user. 

What it Takes to be a Platform Built on Trust 

Binance’s Red Team focuses on real-life scenarios. Employees are regularly tested with undisclosed fake job offers, fraudulent Zoom updates, and invitations to bogus conferences.  

These exercises are not just about compliance training — they are designed to expose staff to the same tactics hackers use in the wild. Repeated failures carry consequences, with disciplinary measures up to dismissal. 

Moreover, Binance Chief Security Officer Jimmy Su states that the exchange’s willingness to discuss and share the program publicly shows to the regulators and institutional partner that Binance takes operational security seriously on a day-to-day basis. 

This puts the spotlight on how Binance treats cybersecurity threats with strict measures, especially given that 65% of security incidents stem from social engineering. 

Although the approach was controversial, it appears to be effective. After three to four years, Binance reported that this practice significantly improved its security hygiene. 

Sign up for our Newsletter

Click edit button to change this text. Lorem ipsum dolor sit amet, consectetur adipiscing elit