Crypto World
Binance Details Staff Phishing Campaigns to Counter Social Engineering
Binance says it has been running internal, simulated phishing attacks against its own staff for several years—testing how well employees resist social engineering attempts and tying repeat failures to remediation training and performance consequences. The exchange’s chief security officer, Jimmy Su, described the program as a way to measure whether “security hygiene” is improving inside a growing organization.
Su told Cointelegraph that Binance’s internal red team performs phishing simulations on a monthly basis. Employees who fail receive remediation training, while continued poor performance can affect their performance review ratings and, in extreme cases, lead to dismissal.
Key takeaways
- Binance conducts monthly phishing simulations via an internal red team, according to its chief security officer Jimmy Su.
- Failed phishing tests are followed by remediation training, aiming to improve employees’ security habits over time.
- Results can influence performance reviews; repeated failures may lower ratings to the point that employment risk increases.
- Su says Binance has run these simulated attacks for roughly three to four years, with security hygiene improving compared with earlier stages.
- The described tactics reflect broader industry risk: social engineering continues to be a major driver of crypto security incidents.
How Binance tests resistance to social engineering
Binance’s approach centers on realism: the red team acts as an attacker to probe the company’s human layer, not just technical controls. Su said the simulations are designed to show whether employees have become more vigilant over time, adding that the program has been running for about three to four years.
“We do phishing attacks on our own employees on a monthly basis just so we understand if our security hygiene is improving,” Su told Cointelegraph. The goal, he said, is to spot weaknesses early—before malicious actors can exploit them in real incidents.
“The ones that have failed it, we will do remediation training.”
Su also said that early on, security hygiene “left a lot to be desired.” But after continuing the internal testing for a sustained period, Binance has seen meaningful improvement. That long-running cadence matters because human error is rarely solved through a one-time training session; it often requires repeated exposure, feedback, and accountability.
Escalating accountability: training and performance reviews
Binance’s internal program isn’t only about education—it’s also about incentives. Su stated that employees are encouraged to perform well because simulation results are reflected in performance reviews.
“If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That’s the incentive to be vigilant.”
He added that repeated, severe failures could cause a person’s rating to “bottom out,” which could ultimately lead to dismissal. While exact thresholds or timelines were not specified, the direction is clear: Binance treats recurring susceptibility to phishing as a measurable risk rather than a purely training-based issue.
For employees and managers, this changes the information security conversation. Instead of treating phishing defenses as optional training, the simulations become part of how the organization assesses readiness—suggesting a shift toward continuous security evaluation.
The tactics: recruiter lures and Zoom-style schemes
Su described at least one scenario used in the red team’s simulations: the team poses as job recruiters. That reflects a common pattern in real-world phishing—using credible context and urgency to lower an employee’s guard, especially when the target might be inclined to respond to hiring-related messages.
He also referenced well-known social engineering techniques that have circulated widely in the crypto ecosystem, including “Zoom meeting attacks,” in which attackers try to get victims to install malware disguised as a meeting update. These attacks often begin with a lure such as a fake job opportunity, and they can also use other hooks like proposed funding or partnerships.
The Binance description aligns with incidents seen across the sector. Earlier coverage cited by Cointelegraph notes that AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering. Separately, a major hack suffered by Drift Protocol in April was described as following a long-term social engineering campaign.
One example of the “Zoom client” pattern occurred in September 2025, when a major Venus Protocol user reportedly lost around $13 million after a malicious Zoom client compromised their computer and granted an attacker control over their account. Venus paused the protocol and used an emergency governance vote to recover the assets, later returning positions worth $11.4 million to the victim, according to the related Cointelegraph reporting referenced in the original article.
Why internal phishing testing is becoming standard in crypto
Binance’s public discussion of internal simulated phishing comes at a time when social engineering is widely recognized as a persistent—and often underestimated—attack surface in digital-asset businesses. The reason these programs can matter is that even sophisticated security stacks cannot fully prevent compromise if employees can be tricked into revealing access, installing malware, or granting approvals.
Binance is also operating at a scale where human processes can become especially important. The exchange says it has 323 million registered users, and DefiLlama estimates Binance holds $137.7 billion in assets. In environments this large, attackers have strong incentives to focus on the easiest pathway to access—often the human decision layer.
Su indicated that Binance has treated phishing resilience as an ongoing operational discipline rather than a compliance box. He described scenarios that include collecting personal information through seemingly benign interactions, such as offering free conference invites as a way to see how many targets would share details.
That emphasis on varied lures is an important point for investors and operators watching the sector: attackers adapt, and defensive training must adapt too. Simulations that only teach one “shape” of attack can become outdated quickly, while programs that rotate scenarios help test whether employees can recognize patterns rather than memorize scripts.
What readers should watch next is whether other major exchanges and custody platforms adopt similar accountability-driven simulation programs—and, crucially, whether regulators and internal auditors begin to treat phishing resistance testing as a measurable control rather than a general training activity.
Crypto World
Uniswap launches Permissioned Pools for compliant onchain trading
Uniswap Labs has launched Permissioned Pools on Uniswap v4, adding onchain access checks for regulated assets that cannot trade freely between every wallet.
Summary
- Permissioned Pools check issuer-managed allowlists before swaps or liquidity actions can proceed through Uniswap v4.
- Superstate, Securitize, and Dowgo helped build compliant trading infrastructure for tokenized funds, equities, and securities.
- Regular Uniswap v4 pools remain permissionless, giving developers a separate option for restricted regulated assets.
The open-source hook standard lets approved users swap tokenized funds, securities, equities and other restricted assets through automated market maker pools. Uniswap announced the product on July 23, 2026, after working with firms that issue and manage regulated onchain assets. It keeps issuer compliance controls visible and enforceable onchain.
Launch partners include Superstate, Securitize and Dowgo. Each partner helped shape parts of the standard or its compliance links. The launch does not change regular Uniswap v4 pools. Those pools remain permissionless, while issuers can choose the restricted format when an asset requires identity checks, transfer rules or investor eligibility controls.
How Uniswap Permissioned Pools work
Permissioned Pools check an issuer-managed allowlist before every swap. The hook also checks the list before a user creates a liquidity provider position. When a wallet lacks approval, the transaction cannot continue. The issuer controls the list and its rules, rather than Uniswap or a public interface. Uniswap said the checks run “at the protocol level, not on the frontend,” which makes the restriction part of the pool’s smart-contract process.
The design uses Uniswap v4 hooks, which let developers add custom instructions to a pool at set points in a transaction. It also uses v4 virtual accounting to calculate exchanges while the regulated assets remain inside a permissioned contract. Approved traders still use an AMM instead of a traditional order book. Liquidity providers supply the assets, while the pool’s code handles pricing and settlement under the issuer’s access rules.
Launch partners connect regulated assets to AMMs
Superstate joined as an early design partner and helped develop the format for tokenized equities and funds. The company issues onchain financial products and operates services for tokenized funds and company shares. Its July 23 update said the standard could connect eligible tokenized equities with AMMs, lending markets and other approved financial applications.
Securitize worked with Uniswap Labs before the wider standard launched. The firms focused on making assets issued through Securitize’s DS Protocol compatible with compliant onchain trading. Dowgo contributed an ERC-3643 integration, a token standard that supports identity checks and transfer controls. Uniswap said Dowgo plans to use Permissioned Pools after it receives DLT TSS authorisation under the European Union’s DLT Pilot Regime. Dowgo says its application remains under review by France’s ACPR.
Regular Uniswap v4 pools remain permissionless
The new system applies only when an issuer or developer deploys a Permissioned Pool for a selected asset. It does not add a general identity check to Uniswap v4. Developers can continue creating standard pools without asking Uniswap Labs for approval, and users can continue accessing those pools under the protocol’s existing rules.
This split gives regulated issuers a separate route to AMM liquidity without turning the wider protocol into a closed trading venue. Uniswap said developers can choose either model: build permissionlessly on v4 or deploy a restricted pool for an asset with legal transfer conditions. The issuer remains responsible for the allowlist and investor access, while the hook enforces those decisions during swaps and liquidity actions.
Tokenized asset growth raises demand for compliance controls
Permissioned Pools follow Uniswap’s June rollout of tokenized securities across its web app, wallet and API. That earlier update gave eligible users access to blockchain-based products linked to companies such as Apple, Nvidia and Tesla. Uniswap warned that some products may not represent direct ownership and may face KYC, transfer or geographic restrictions. The new pool standard gives issuers another way to enforce such rules directly in trading infrastructure.
Uniswap cited an estimate that the tokenized asset market could reach $11 trillion by 2030. Current figures remain far below that forecast. As crypto.news reported, tokenized real-world assets stood near $34 billion in May 2026, including about $1.55 billion in tokenized equities. Related coverage also found that transfer agents often control wallet allowlists and the official ownership records behind tokenized securities.
Regulators continue to examine how these products protect ownership and shareholder rights. As previously reported, the U.S. Securities and Exchange Commission delayed a proposed tokenized-stock exemption after exchanges raised questions about investor safeguards and record keeping. Securitize chief executive Carlos Domingo said any framework should “apply to the right instruments.” Permissioned Pools address transaction access at the smart-contract level, but each issuer must still follow the securities laws and licensing rules that apply to its product and market.
Crypto World
Upbit expands KRW market with two major DeFi token listings
Upbit has added Morpho (MORPHO) and Euler (EUL) to its Korean won market, expanding direct KRW trading for two Ethereum-based decentralized lending projects in Korea.
Summary
- Upbit added MORPHO and EUL KRW pairs, giving traders access to two DeFi lending tokens.
- Euler’s KRW trading launch moved to 2:00 p.m. KST, two hours later than initially scheduled.
- EUL gained about 74% before launch, while MORPHO posted a smaller rise and heavier volume.
MORPHO/KRW opened on July 25 at 6:00 p.m. KST, while Upbit planned EUL/KRW for July 26.
However, Upbit changed Euler’s launch timetable shortly before trading. The exchange moved the start from 12:00 p.m. to 2:00 p.m. KST on July 26. The notice said, “The trading support start time for EUL will change.” Deposits and withdrawals for both assets remain limited to the Ethereum network. The listings also broaden access beyond existing BTC and USDT pairs already available for both assets on Upbit.
Upbit delays EUL trading after adding the KRW pair
Upbit did not give a detailed reason for the two-hour delay. Its notice said trading may start later when the exchange has not secured enough liquidity. The platform had already created the EUL/KRW market page, but users still had to follow the revised 2:00 p.m. KST start time.
The exchange also placed temporary controls on the launch. Upbit will block buy orders for about five minutes after trading begins. During the same period, it will restrict sell orders priced more than 10% below the previous closing price. For roughly two hours, users may place limit orders only. Upbit set the reference close at 0.00003019 BTC, equal to 2,845 won in its notice.
EUL price surges before the scheduled Upbit launch
EUL recorded the stronger market response. At the time of writing, Binance data placed the token near $2.22, up about 74% over 24 hours, with trading volume above $200 million. CoinMarketCap data also linked the move to the Upbit listing and reported a sharp rise in volume before the KRW market opened.
The reaction follows earlier cases in which Korean won listings drove fast changes in EUL trading. As crypto.news reported in September 2025, EUL rose more than 30% after Bithumb announced a KRW pair. The token had also gained after Coinbase added it to its asset roadmap in July 2025. Those earlier moves show that new exchange access can quickly change short-term demand, although gains can reverse when initial activity slows.
Morpho gains another route to Korean won liquidity
Morpho’s KRW pair opened a day earlier. Upbit scheduled MORPHO/KRW trading for 6:00 p.m. KST on July 25 and supported deposits and withdrawals through Ethereum only. Market trackers recorded a smaller price move than EUL, but they also showed a sharp increase in MORPHO trading volume after the announcement.
MORPHO traded near $1.95 on July 26, up about 1.5% over 24 hours. CoinGecko placed its market value above $1.2 billion and reported that daily volume had increased by more than 400% from the previous day. The listing adds a direct won pair for a token that Upbit already offers in its BTC and USDT markets.
The new KRW access also follows a series of Morpho product and funding updates.Morpho launched Midnight on Base in July, offering fixed-rate and fixed-term lending. The network said it held more than $11 billion in deposits. In June, Morpho raised $175 million from investors including Paradigm, a16z Crypto and Ribbit Capital, with the transaction reportedly valuing the project at about $2 billion.
Upbit backs two modular Ethereum lending protocols
Morpho and Euler both provide infrastructure for onchain lending, but they use different systems. Morpho lets developers and asset managers create lending markets and vaults with selected collateral, risk settings and interest models. MORPHO supports governance and other functions across the network.
Euler v2 uses modular vaults that users and developers can build for different lending markets. Its Euler Vault Kit supports the creation of vaults, while the Ethereum Vault Connector can link positions across compatible vaults. EUL serves governance, rewards and fee-related functions within the protocol.
Euler rebuilt its platform after a 2023 exploit drained about $197 million from its earlier version. The attacker later returned most of the funds. As crypto.news previously reported, Euler expanded through v2 and later launched on networks including Sonic. The protocol reported more than $2 billion in total borrowing and about $4 billion in deposits by October 2025.
Upbit’s back-to-back MORPHO and EUL listings give Korean traders new won-denominated access to two lending protocols. However, the fast EUL price rise and the exchange’s opening controls point to high volatility around the launch. Upbit advised users to confirm the Ethereum network and token contract before sending funds, because unsupported deposits may require a long return process.
Crypto World
Bitcoin Miner Poolin Files Bankruptcy, Seeks $52M Texas Asset Sale
Singapore-based Bitcoin mining company Poolin on July 22 filed for Chapter 11 bankruptcy protection in New Jersey, alongside its US affiliates Lonestar Dream Inc. and Lonestar Taproot LLC. The firm is also looking for court approval for a $52 million sale of its Texas mining properties.
The bankruptcy filing comes nearly four years after Poolin froze customer withdrawals, leaving thousands of wallet users with IOU tokens and turning a mining business failure into a long-running creditor dispute.
Poolin Enters Chapter 11 With $173 Million in Liabilities
Court records filed in the US Bankruptcy Court for the District of New Jersey show Poolin listed between 10,001 and 25,000 creditors, with petition assets estimated between $1 million and $10 million.
Chief Restructuring Officer Michael DuFrayne’s declaration placed prepetition obligations at about $173.1 million, with roughly $163.7 million tied to unsecured IOUs issued to Poolin Wallet customers.
The company’s current bankruptcy case is focused on selling its Texas assets rather than rebuilding its mining operations. Lonestar Dream stopped mining and hosting activities at its Pyote and Tarbush sites on July 10, according to the filing documents.
Poolin has entered asset purchase agreements with Thor CALAP LLC for a combined $52 million stalking-horse bid. The offer includes $15 million for the Pyote property and associated power rights and equipment, plus $37 million for Tarbush power rights and equipment. The deal remains subject to competing bids and court approvals.
The company spent more than three months marketing the asset, contacting over 335 potential buyers, including cryptocurrency miners and artificial intelligence and high-performance computing operators. The process resulted in 28 confidentiality agreements, seven letters of intent and three additional expressions of interest.
Poolin’s Texas expansion struggled after the company moved mining operations from China as Beijing imposed a ban on mining in the year 2021. It expected to receive up to 600 megawatts of power, but only 100 megawatts were made available. This meant the equipment the firm had bought for its US run ended up being more than was necessary.
Some of that equipment was sold, resulting in a loss of $8.8 million from fiscal year 2023 to 2025. In the end, Lonestar Dream and Lonestar Taproot accumulated about $45.9 million in losses.
The Collapse of Poolin Wallet Remains Central to Creditor Claims
Poolin’s financial problems go beyond mining, as back in June 2022, when Bitcoin fell below $20,000, it triggered margin calls from Tether against collateral the firm had pledged through the Poolin Wallet. It then transferred almost all of that collateral to Antalpha and borrowed about $213 million against crypto assets valued at just under $356 million.
However, in September 2022, Poolin Wallet suspended withdrawals and issued around $163.7 million worth of IOU tokens to customers, with about 11,700 wallet users holding balances above $100, according to the filing.
Bitcoin later fell below $16,800 in November 2022, after which Poolin ceased operations, and Antalpha liquidated the collateral. Management estimated that about $260 million was owed to Antalpha against digital assets valued near $265 million at the time.
Poolin was once one of the largest Bitcoin mining pools globally, reaching roughly 14% of the Bitcoin network’s mining share in 2019. However, the company’s remaining value now depends on the Texas asset sale and the outcome of the bankruptcy process.
The court-supervised auction will determine how much creditors recover, and any distribution will depend on competing bids, sale expenses, administrative claims, and approval of the proposed liquidation plan.
The post Bitcoin Miner Poolin Files Bankruptcy, Seeks $52M Texas Asset Sale appeared first on CryptoPotato.
Crypto World
Sberbank sets Dec. 1 deadline for Russia crypto trading launch
Sberbank plans to launch cryptocurrency trading infrastructure and a digital depository by Dec. 1, 2026.
Summary
- Sberbank plans to launch regulated crypto trading, custody, settlement, and depository services by December 1.
- Russia’s new crypto framework starts September 1, with licensing compliance required by July 1, 2027.
- Non-qualified investors may buy up to 300,000 rubles yearly after passing a mandatory knowledge test.
The system will support regulated crypto trading, custody and settlement for eligible customers in Russia.
The project follows the approval of new rules covering crypto exchanges, brokers, banks and digital depositories. Russia will introduce the wider regulatory framework on Sept. 1, 2026, while companies will receive additional time to meet licensing requirements.
Sberbank plans digital custody and off-chain records
According to Interfax, Sberbank’s digital depository will record customers’ cryptocurrency ownership and account for many transactions outside public blockchain networks. The bank will also manage active wallets for deposits, withdrawals and transfers.
Alexander Vedyakhin, Sberbank’s first deputy chairman, said the bank intends to complete the required systems before the December deadline.
“Sber plans to implement the necessary infrastructure and launch the digital depository by Dec. 1, 2026.”
Sberbank has not yet named the cryptocurrencies that its platform will support. The bank has also not disclosed fees, customer eligibility rules or withdrawal limits. These details may depend on supporting regulations that Russian authorities still need to approve.
Under the planned structure, customers could hold recorded crypto rights inside Sberbank’s system. The bank would then use its controlled wallets when customers deposit, withdraw or transfer assets to external addresses.
Russia introduces rules for investors and intermediaries
The Bank of Russia said the new framework will allow qualified and non-qualified investors to purchase cryptocurrencies through regulated intermediaries. However, different limits will apply to each group.
Non-qualified investors must pass a knowledge test before buying eligible cryptocurrencies. They may purchase up to 300,000 rubles of crypto each year through one intermediary. Public access will focus on assets that meet liquidity and market-size standards set by regulators.
Qualified investors must also complete testing, but they will have access to a wider range of assets without the same annual limit. Banks, brokers and asset managers may offer services under their existing licences and added crypto requirements.
Meanwhile, new cryptocurrency exchanges and digital repositories will require separate approval. The Bank of Russia will supervise the market and set standards for custody, accounting and customer protection.
Russia will continue to prohibit cryptocurrency payments for goods and services inside the country. However, companies may use crypto for approved cross-border settlements. Residents may also need to report some foreign crypto holdings and transactions to tax authorities.
The framework takes effect on Sept. 1, 2026. Companies covered by the new rules will have until July 1, 2027 to secure licences and bring their systems into compliance.
Sberbank expands its existing digital asset services
Sberbank has operated in Russia’s regulated digital asset sector since joining the register of information system operators in 2022. The bank has issued digital financial assets and structured products linked to Bitcoin, Ethereum and cryptocurrency baskets.
Ascrypto.news previously reported, Sberbank was preparing a crypto wallet and digital asset depository before the new framework’s launch. The report said the bank could also consider access to foreign crypto exchanges, depending on final regulatory requirements.
Sberbank has also tested cryptocurrency-backed lending. In December 2025, the bank completed a pilot loan with Russian Bitcoin miner Intelion Data. The company pledged mined cryptocurrency as collateral.
Reuters reported that Sberbank later considered offering similar loans to corporate customers. The bank said miners and companies holding digital assets had shown interest in using crypto as collateral.
The bank has also explored cryptocurrency custody services. In July 2025,Reuters reported that Sberbank had submitted proposals to the central bank on storing Russian customers’ crypto assets through regulated banking infrastructure.
Russian financial companies prepare for crypto trading
Other Russian financial institutions are also preparing services under the new framework. According to crypto.news, VTB and T-Bank were developing digital depository services, while Moscow Exchange was considering regulated cryptocurrency operations.
Alfa-Bank has also tested limited crypto services and custody tools. These projects show that large Russian financial groups are positioning their systems around the new rules before the July 2027 licensing deadline.
The regulated market will divide responsibilities among banks, brokers, exchanges and repositories. Brokers may process customer orders, while exchanges provide trading services. Digital repositories will record customer rights and custody arrangements.
Sberbank’s Dec. 1 launch target places its project within the regulatory transition period. Before opening the service, the bank must complete its wallet, trading, accounting and custody systems. It must also publish supported assets, fees and customer access requirements.
Crypto World
Binance Runs Monthly “Red Team” Tests on Staff to Thwart Hackers
Binance’s chief security officer, Jimmy Su, says the exchange is actively testing its own workforce against simulated phishing attempts—and tying repeated failures to employment outcomes. Su told Cointelegraph that the internal “red team” runs phishing exercises on a monthly basis to gauge whether security awareness among staff is improving.
According to Su, employees who fail the exercises aren’t just retrained once. Instead, Binance uses remediation training for those who miss the mark, and persistent, repeat failures can ultimately affect their standing at the company, reflecting the role that social engineering plays in real-world cyber incidents.
Key takeaways
- Binance conducts monthly simulated phishing attacks against employees as part of an ongoing internal security program.
- The simulations are carried out by Binance’s red team, a unit focused on ethical hacking and vulnerability discovery.
- Failed employees receive remediation training, while repeated failures can negatively affect performance reviews and potentially job outcomes.
- Binance says the program has been running for three to four years, with Su describing significant improvements in security hygiene over time.
- The company uses multiple real-world lures—such as fake recruiter outreach and other “information collection” tactics—to test staff resilience.
Why Binance is testing its own staff
Su said Binance runs phishing simulations “just so we understand if our security hygiene is improving,” framing the effort as a practical measurement exercise rather than a theoretical awareness campaign. The red team’s role, as described by Su, is to attempt intrusions and interactions that mirror real attack paths, then feed results back into training.
Binance is often described as a large-scale target in crypto due to its user base and market footprint. Su did not provide additional internal metrics in the interview, but the context underscores the stakes: Binance reports 323 million registered users, while DefiLlama estimates the exchange holds $137.7 billion in assets.
For investors and traders, the takeaway is that big exchanges treat human behavior as part of their threat model. The more a firm relies on operational processes—such as customer support, account access, identity verification, and internal tooling—the more social engineering becomes a risk factor that technical defenses alone can’t fully eliminate.
Social engineering remains a recurring breach pathway
Su’s comments land in the context of broader industry reporting on social engineering as a driver of crypto security incidents. In February, AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering. Later, in April, a long-term social engineering campaign preceded Drift Protocol’s $285 million hack, according to earlier coverage referenced by Cointelegraph.
Su also said the simulated attacks have been in place for three to four years. He suggested that security hygiene has improved substantially since the program began: “In the beginning, the security hygiene left a lot to be desired. But after this amount of time, the company has improved significantly,” he said.
This matters because it highlights a specific operational change: Binance is not treating awareness training as a one-time checkbox, but as an ongoing feedback loop. The key shift for organizations is moving from “teach and forget” to “test, measure, and enforce.”
What the simulations look like: recruiting lures and data-harvesting scenarios
One scenario Binance uses is impersonation of job recruiters. Su said the red team poses as recruiters—an approach that mirrors a common pattern seen in phishing incidents across industries, where “legitimate-sounding” contact becomes the entry point for further manipulation.
Su also described another lure: fake “free conference invites” aimed at collecting personal information and determining how many employees fall for it. He emphasized that the job interview process is only one of multiple scenarios used by Binance’s red team.
These details are important because social engineering attacks in crypto don’t always arrive as obvious “click this link” attempts. They can be structured like legitimate professional outreach, scheduling requests, or follow-ups—channels that can appear normal to staff who might otherwise be trained to recognize traditional phishing emails.
Another well-known technique referenced in the interview is the “Zoom meeting attack,” where attackers trick victims into installing malware disguised as a video conferencing update. Many such campaigns begin with a fake job opportunity, but they can also use other professional hooks like project funding or partnership proposals.
How failure is handled: remediation, reviews, and potential dismissal
Binance’s approach doesn’t end with simulated testing. Su said employees who fail the phishing simulations undergo remediation training. He also described incentives tied to the results, stating that performance reviews reflect test outcomes.
Su’s framing is direct: “If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That’s the incentive to be vigilant.”
He further said repeated severe failures could “bottom out” performance ratings, potentially leading to dismissal. While Su did not outline exact thresholds or timelines for dismissal in the interview, the principle is clear: Binance is treating repeated susceptibility to social engineering as a personnel risk, not just a training gap.
Outside centralized exchanges, similar social engineering dynamics have produced major losses in DeFi ecosystems as well. For example, Cointelegraph referenced a September 2025 incident in which a Venus Protocol user reportedly lost around $13 million after a malicious Zoom client compromised a computer and led the attacker to gain control over the victim’s account. Venus paused the protocol and used an emergency governance vote to recover assets, later returning positions worth $11.4 million to the victim, according to earlier coverage cited in the article.
Those examples reinforce the broader point behind Binance’s internal testing: even when attackers target individuals rather than systems, the outcome can still be catastrophic at scale.
What readers should watch next is whether Binance’s approach—monthly red-team phishing tests, remediation, and performance-linked consequences—becomes a more standard pattern across large crypto firms as regulators and stakeholders increasingly focus on operational security beyond code and infrastructure.
Crypto World
Binance Runs Phishing Attacks on Staff to Fight Social Engineering
Cryptocurrency exchange Binance runs simulated phishing attacks against its own employees and can fire staff who repeatedly fail the tests, according to Binance chief security officer Jimmy Su.
The fake attacks are conducted by Binance’s red team, an internal ethical hacking unit whose job is to break into systems to identify vulnerabilities.
“We do phishing attacks on our own employees on a monthly basis just so we understand if our security hygiene is improving,” Su told Cointelegraph. “The ones that have failed it, we will do remediation training.”
The measure shows the lengths crypto companies will go to prepare for social engineering attacks. Binance, the largest crypto exchange in the world, reports 323 million registered users, while DefiLlama estimates the exchange holds $137.7 billion in assets.

Jimmy Su, chief security officer at Binance. Source: Binance
In February, AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering. In April, Drift Protocol suffered a $285 million hack, which came after a long-term social engineering campaign.
Su said Binance has been running these simulated attacks for three to four years.
“In the beginning, the security hygiene left a lot to be desired. But after this amount of time, the company has improved significantly.”
One of the simulated attacks involves the red team posing as job recruiters, said Su.
Related: Trader loses $1M after signing phishing token approval
One of the more well-known attack methods in recent years has been the “Zoom meeting attack,” where hackers trick victims into installing malware disguised as an update to the video conferencing app. Many of these attacks start with a fake job opportunity, though some use project funding or a partnership proposal as the lure.
In September 2025, a major Venus Protocol user lost roughly $13 million after a malicious Zoom client compromised his computer, leading him to grant an attacker control over his account. Venus paused the protocol and used an emergency governance vote to recover the assets, later returning positions worth $11.4 million to the victim.
“The interview process is just one scenario. There are other ones. For example, it could be that we are offering some kind of free conference invite just to try to collect personal information and see how many of them will actually fall for it,” said Su.
Su said employees are incentivized to perform well on the tests because the results are reflected in their performance reviews.
“If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That’s the incentive to be vigilant.”
Repeated, severe failures could lead to their rating to “bottom out,” which could see them dismissed, he said.
Magazine: Fears of AI-driven DeFi hack epidemic overstated for now — but not for long
Crypto World
Top 3 US Stock Market Stories From This Week
US stocks fell this week as investors reacted to disappointing Big Tech earnings, oil above $100 and sharp swings in semiconductor shares.
The Nasdaq lost around 2% between July 19 and July 25. The S&P 500 fell 0.6%, while the Dow dropped 0.4%. Technology stocks faced the heaviest pressure.
Here are the three biggest US stock market stories retail traders need to know.
Big Tech’s AI Bill Shakes Wall Street
Tesla and Alphabet triggered a broad technology sell-off after their earnings reports raised concerns about the cost of AI investment.
Tesla shares fell 14.5% after the company reported negative free cash flow for the first time in more than two years. Investors also remained concerned about weaker vehicle demand and the cost of funding new products.
Alphabet dropped 7% after raising its expected 2026 capital spending to around $200 billion. The company reported strong cloud growth, but the higher spending forecast overshadowed those gains.
As a result, the Nasdaq fell more than 2% on Thursday. The sell-off also increased pressure on Microsoft, Amazon and Meta ahead of their earnings.
The market has rewarded companies that spend heavily on AI. However, investors now want clearer evidence that this spending will produce stronger profits.
$100 Oil Brings Inflation Fears Back
Brent crude moved above $100 a barrel after rising tensions between the US and Iran raised fears of disruption to global oil supplies.
The price increase quickly spread across financial markets. Treasury yields climbed as traders considered whether higher energy costs could keep inflation elevated.
Higher yields usually put pressure on growth stocks. They reduce the present value of future earnings and make bonds more attractive compared with expensive equities.
The oil rally also hurt companies that depend on fuel or transport. Airlines, logistics firms and consumer businesses could face higher operating costs if crude prices remain elevated.
Meanwhile, energy and defence stocks gained support. Investors moved toward sectors that could benefit from higher oil prices and increased geopolitical risk.
Crypto also faced pressure during the risk-off move. Bitcoin often trades like a high-growth asset when bond yields rise and investors reduce exposure to speculative markets.
Chip Stocks Swing Between Hope and Fear
Semiconductor stocks experienced some of the week’s biggest moves as traders shifted between optimism over AI demand and concern about excessive spending.
The Philadelphia Semiconductor Index rose more than 5% on Tuesday. Micron, Western Digital and Sandisk posted double-digit gains as investors bought the sector after an earlier sell-off.
Super Micro Computer also jumped almost 20% after reporting more than $60 billion in new orders. The update showed that demand for AI servers and data-centre equipment remained strong.
However, the recovery did not last. The semiconductor index fell 4.5% on Friday as wider concerns about AI spending returned.
Intel dropped almost 8% despite issuing stronger-than-expected guidance. Investors focused on its higher investment plans and the cost of competing in advanced chip production.
The moves showed how sensitive semiconductor stocks have become. Strong demand can still support the sector, but high valuations leave little room for disappointing earnings or rising costs.
For retail traders, the main risk remains volatility. AI-related stocks can move sharply even when companies report solid results.
The post Top 3 US Stock Market Stories From This Week appeared first on BeInCrypto.
Crypto World
The Harsh Reality of New Crypto: Just 7% of Major Tokens Beat Their Launch Price
The firm tracked 113 coins since their token generation event (TGE) price, with only 8 of them now above that price, a median return of -95.7%.
The sample is limited to projects with a market capitalization above $100 million as of July 21, CryptoRank told CryptoPotato.
CryptoRank Study: Eight Exceptions to the Rule
Eight coins included in the survey are in profit, led by HYPE, ONDO, EVA, and NIGHT.
Hyperliquid’s HYPE was up 1,519% from its launch price at the time of the survey’s publication on July 21st. Ondo Finance’s ONDO followed at 101.4%, with EverValue Coin (EVA) and Midnight Network (NIGHT) up a more modest 20.3% and 16.5% respectively.
These figures are revealing, as we can see that even among those that are up, only a small handful showed outsized performance, with six of the eight achieving double-digit increases at best. It’s worth noting that HYPE was also listed in the new S&P Pantera Digital Asset Index, which excluded many high-performing crypto assets, including Bitcoin.
Why the Decline?
CryptoRank states that sell-offs, thin liquidity, and regulatory uncertainty were the main causes of major drawdowns in these projects, although the market has also observed major crashes due to exploits and other factors in the last two years.
Only 7.1% of Tokens Launched Since 2024 Are Still in Profit
Out of 113 projects with a market capitalization above $100M, only 8 are trading above their TGE price, while 105 are already in the red.
This highlights how difficult it has been for newly launched tokens to sustain… pic.twitter.com/PbjCiBD5Jd
— CryptoRank.io (@CryptoRank_io) July 21, 2026
The tokens studied spanned a wide range of niches in the crypto industry, including DeFi, gaming, and various infrastructure projects. The findings come as the broader market recovers, with bitcoin climbing above $66,000 this week on higher ETF inflows and weaker US inflation data.
The post The Harsh Reality of New Crypto: Just 7% of Major Tokens Beat Their Launch Price appeared first on CryptoPotato.
Crypto World
Top 5 Trump News That Moved Markets This Week
Donald Trump’s threats against Iran and a new wave of tariffs dominated financial markets between July 19 and July 25.
Oil prices climbed as geopolitical risks increased. Meanwhile, trade measures targeting dozens of economies raised fresh concerns about inflation, corporate costs and interest rates.
Here are the five Trump developments that mattered most for markets this week.
1. Iran Threat Sends Oil Above $100
Trump threatened Iran with major military action after further Houthi attacks on commercial shipping. He said Tehran could face consequences if the attacks continued.
The comments immediately increased fears of disruption in the Red Sea and the Strait of Hormuz. Both routes play an important role in global oil and shipping markets.
Brent crude briefly rose above $100 a barrel. Higher oil prices can increase transport and production costs, which may push inflation higher.
That could delay interest rate cuts or force central banks to maintain tighter policy. Technology stocks and Bitcoin also faced pressure as bond yields climbed and investors reduced exposure to riskier assets.
2. Trump’s Tariff Wall Gets Wider
Trump ordered new tariffs of 10% or 12.5% on goods from 60 economies. The affected markets include China, India, the European Union, Japan and South Korea.
The measures cover a large share of US trade. They could raise costs for retailers, manufacturers and companies that rely on imported components.
Businesses may pass some of those costs to consumers. That would keep inflation elevated and make it harder for the Federal Reserve to reduce interest rates.
The tariffs could also hurt corporate profit margins. Consumer goods companies, automakers and technology manufacturers face some of the highest risks.
3. Canada Becomes the Latest Trade Target
Trump announced additional 50% tariffs on around $20 billion of Canadian products. The affected goods include dairy, wine, furniture, cement and sporting equipment.
Energy and critical minerals received exemptions. However, the decision still raised fears of retaliation from Canada and further disruption to North American supply chains.
The Canadian dollar weakened during the week as trade uncertainty increased. US companies that import Canadian products may also face higher costs when the tariffs begin in August.
The dispute could reduce trade between two closely connected economies. It may also increase prices for construction materials and some consumer products.
4. Defence Firms Face a China Supply Chain Test
Trump signed an order tightening restrictions on foreign materials used by US defence contractors. Companies will face tougher rules when seeking permission to buy critical minerals or components from China and other restricted markets.
The order could benefit American rare-earth miners and metal processors. Shares in some domestic suppliers rose after the announcement.
However, defence and aerospace companies may face higher costs during the transition. China remains a major supplier of several minerals used in military equipment and advanced electronics.
Supply shortages could delay production and increase government contract costs.
5. Aluminum Tariffs Get an Investment Clause
Trump introduced a new system linking aluminum tariff relief to investment in US production. Companies that build or expand American smelters may import a matching amount of aluminum at a reduced tariff rate.
The policy could support US aluminum producers and encourage new domestic investment. It could also create higher costs for businesses that cannot qualify for the reduced rate.
Automakers, construction companies and beverage manufacturers use large amounts of aluminum. Any rise in metal prices could affect their margins and eventually reach consumers.
Overall, Trump’s actions this week placed oil, tariffs and inflation back at the centre of market attention. Investors will now watch whether the measures trigger retaliation, higher consumer prices or a wider Middle East conflict.
The post Top 5 Trump News That Moved Markets This Week appeared first on BeInCrypto.
Crypto World
Robinhood in Talks with Crypto.com over Prediction Markets: WSJ
Cointelegraph is committed to providing independent, high-quality journalism across the crypto, blockchain, AI, and fintech industries.
All news, reviews, and analyses are produced with full journalistic independence and integrity. For more details on our standards and processes, please read our Editorial Policy.
-
Fashion1 day agoWeekend Open Thread: Brooks Brothers
-
Politics7 days agoDemocrats look to World Cup watch parties to register thousands of voters
-
News Videos6 days agoBig Money Is Entering XRP
-
Tech5 days agoSail Virtually Aboard The “Itanic” With IA-64 Emulator
-
Tech5 days ago
Turtle Beach Command Series KB7 review: a nifty screen-equipped gaming keyboard
-
Crypto World5 days agoGrayscale Files For Worldcoin ETF, WLD Registers Sharp Rise
-
NewsBeat6 days agoUnregistered fitter used Gas Safe logo on business flyers
-
Business4 days agoNew Jersey voter registration controversy explained: How 6,600 noncitizens got on the rolls, and what happens next
-
Entertainment4 days agoJohnny Depp’s R-Rated Gothic Cult Classic Gets New Release Ahead of Sydney Sweeney Remake
-
Crypto World3 days agoEthics, other provisions in crypto Clarity Act to be further discussed
-
Tech6 days agoWatch Flock Safety CEO Garrett Langley discuss the future of surveillance at TechCrunch Disrupt 2026
-
Crypto World6 days agoCircle’s President Sold Over 360,000 Shares, The Filings Explain Why
-
NewsBeat5 days agoShanghai science forum photos show China’s AI and robotics advances in rivalry with US
-
Tech6 days agoSubway Sandwich Computers Get a Second Life as Gaming Machines
-
Sports2 days ago2026 3M Open leaderboard: Scottie Scheffler finds putter in Round 1, sits three back
-
News Videos2 days agoThe Peugeot Family: How 200 Years of an “Old Money” Dynasty Died in A Boardroom
-
Fashion2 days ago16 Dresses for the High Summer Event
-
Tech6 days agoThe 35 Best Board Games for Family Game Night
-
Tech6 days agoHow To Use Claude’s Reflect Dashboard And Learn When It’s Time To Touch Grass
-
Entertainment6 days agoStephen Colbert Returns to Social Media After Late Show End

You must be logged in to post a comment Login