
The Hong Kong Securities and Futures Commission (SFC) has ordered licensed crypto trading platforms and online brokers to replace SMS-based authentication with phishing-resistant login methods within the next 12 months. According to the SFC, virtual asset trading platforms (VATPs) and online brokers must stop relying on one-time passwords delivered through SMS, email, or app-generated codes and instead adopt stronger authentication systems that are harder for attackers to compromise. The regulator announced these new cybersecurity requirements on Thursday as part of updated standards for customer account protection, with the measures specifically designed to reduce account takeover through phishing and social engineering attacks. The message is blunt: basic authentication is no longer enough, particularly as phishing campaigns become more adaptive and capable of turning routine access into asset loss for retail users and traders across platforms.
The new regulations respond to a dramatic surge in cybersecurity incidents affecting Hong Kong's financial sector. Hong Kong logged 15,877 cybersecurity incidents in 2025, marking a 27% jump from the prior year, according to the SFC. Phishing accounted for 57% of those cases, followed by botnet attacks at 18% and malware at 15%. The 2025 total represents more than double the 7,752 incidents recorded in 2023. Global phishing losses tied to crypto wallets hit roughly $306 million during Q1 2026 alone, pushing the SFC toward action as attackers increasingly rely on stolen credentials rather than technical exploits to target crypto users. Recent incidents include a crypto investor losing nearly $1 million after signing a malicious phishing token approval transaction on Ethereum, and a wallet holder reportedly losing $1.65 million after connecting to a fake exchange.
Under the new framework, firms will be required to introduce phishing-resistant authentication methods together with device binding. The SFC identified passkeys, registered devices secured through cryptographic verification, and hardware security keys as acceptable alternatives. Passkeys and hardware keys use public-key cryptography to prevent credential theft on fake login pages, while device binding verifies a specific device cryptographically rather than relying on codes that can be intercepted. All licensed platforms must complete the transition within one year, with platforms regulated by the SFC needing to update customer authentication flows, developer documentation and account recovery procedures to comply. The announcement did not specify enforcement penalties for non-compliance. For platforms, the practical implication is that they cannot treat multi-factor authentication as a checkbox. The SFC's explicit ban on SMS/email one-time passwords is especially important because these methods can still be vulnerable to social engineering and interception scenarios where attackers focus on tricking users into providing the second factor or luring them into fraudulent flows.
The SFC has issued a direct order requiring firms to implement phishing-resistant authentication immediately and no later than 12 months from the circular's issue date. Large internet brokers are expected to adopt these measures straight away, according to the regulator, while smaller platforms have a longer transition period. The SFC emphasized that firms must cease using OTPs for client login and device binding, which carry significant risks now that stronger options exist. OTPs sent by text or app can be relayed to an attacker on a fake login page, letting the intruder pass the check in real time. Passkeys and bound devices close that gap by tying access to a specific device or hardware credential rather than a code a client can be tricked into typing. The regulator stated that senior management remains ultimately responsible for protecting client accounts and assets, and it will hold executives accountable for any client losses that stem from lapses in their controls. Firms that miss the 12-month deadline risk enforcement action and reputational damage across the crypto sector.
The new rules cover a broad range of financial services, extending beyond traditional brokers to include licensed corporations dealing in securities, futures and leveraged foreign exchange, along with asset managers that distribute funds through internet trading and the city's licensed crypto platforms. The SFC has also mandated that platforms monitor for suspicious login, trading and withdrawal activity, alert clients to key account events, and respond quickly to breaches. It expects them to keep warning customers about emerging phishing risks, part of a wider push that has drawn in the Hong Kong Police on virtual asset oversight. The circular extends the SFC's campaign that began with earlier measures, including the February 2025 circular that encouraged firms to abandon OTPs, which is now made mandatory. The enforcement reflects the regulator's pattern of tightening security requirements following significant incidents, including the SFC's freezing of about HK$91 million (roughly $11.7 million) across four brokers late last year, including Interactive Brokers' local unit, after unauthorized trades ran through compromised accounts.