Hong Kong SFC bans OTPs for crypto platforms, mandating stronger authentication to combat phishing scams, and holding senior management accountable. The post HongHong Kong SFC bans OTPs for crypto platforms, mandating stronger authentication to combat phishing scams, and holding senior management accountable. The post Hong

Hong Kong SFC Bans One-Time Passwords For Crypto Platforms To Combat Rising Phishing Threats

이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 [email protected]으로 연락주시기 바랍니다
Hong Kong SFC Bans One-Time Passwords For Crypto Platforms To Combat Rising Phishing Threats

The Hong Kong Securities and Futures Commission (SFC) has issued a circular requiring virtual asset trading platforms and internet brokerages to replace one-time password (OTP) authentication with more robust security methods, as spoofing and fraud attacks on customer accounts continue to intensify.

The regulator cited growing threats from impersonation scams, noting that phishing and spoofing attacks accounted for 57% of all security incidents reported to the Hong Kong Cybersecurity Incident Response Centre in 2025. In response, the SFC is now mandating that platforms phase out OTPs for both customer login and device binding processes — practices it has flagged as increasingly inadequate against sophisticated modern attacks.

Firms are required to adopt stronger alternatives, such as passkeys and bound-device authentication, which the SFC describes as offering more resilient and fraud-resistant verification. While all covered entities must comply within 12 months of the circular’s issuance, large internet brokerages are expected to implement the new measures immediately.

Broader Security Obligations and Accountability

Beyond authentication upgrades, the circular outlines a wider set of obligations spanning detection, response, and client education. Virtual asset trading platforms and brokerages must implement surveillance systems capable of identifying suspicious login, trading, and withdrawal activity. Firms are also required to notify clients promptly of significant account events and respond swiftly to any hacking incidents. Ongoing client warnings about emerging cyber threats and impersonation scams are expected as well.

The SFC made clear that senior management at these firms bears ultimate responsibility for the adequacy of account protection controls. Institutions found to have inadequate internal safeguards will be held accountable for any resulting client losses — a pointed signal to compliance teams across Hong Kong’s digital asset sector.

The circular builds on earlier regulatory signals. The SFC had been monitoring OTP-related risks since late 2024 and, in a February 2025 circular, strongly encouraged licensed corporations to move away from OTPs — making today’s mandate a firm regulatory deadline rather than a voluntary recommendation. For crypto platforms operating in Hong Kong, the message is unambiguous: legacy authentication methods are no longer acceptable.

The post Hong Kong SFC Bans One-Time Passwords For Crypto Platforms To Combat Rising Phishing Threats appeared first on Metaverse Post.

Get Covered, Share 1M USDT

Get Covered, Share 1M USDTGet Covered, Share 1M USDT

Higher VVIP tiers, higher compensation odds.

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, [email protected]으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

Gold at $4,000: Time to Buy?

Gold at $4,000: Time to Buy?Gold at $4,000: Time to Buy?

Central banks buy. $5K in sight, but rates weigh.