TLDR
Hong Kongs securities regulator has ordered licensed crypto platforms and online brokers to eliminate OTP-based logins and move to phishing-resistant authentication within 12 months.
- Hong Kongs SFC now bans one-time passwords via SMS, email, and app codes for logins and device binding, requiring alternatives like passkeys, hardware keys, and device binding.
- The shift is driven by rising phishing and fraud losses, with OTPs seen as easy to intercept compared with cryptographically bound devices and security keys.
- Hong Kong users should expect new login flows and stronger security, while other regulators may look to this model when tightening crypto cybersecurity rules.
Deep Dive
1. What Changed In Hong Kong
The Hong Kong Securities and Futures Commission (SFC) has mandated that all licensed virtual asset trading platforms (VATPs) and online brokers stop using one-time passwords (OTPs) delivered via SMS, email, or app-based codes for user logins and device registration within 12 months. The new rules require platforms to adopt phishing-resistant methods such as passkeys, cryptographically verified registered devices, and hardware security keys, alongside device binding that ties access to specific trusted hardware or browsers.Hong Kong regulator orders new anti-phishing measures for crypto platforms
The circular also expects enhanced monitoring of suspicious logins, trading patterns, and withdrawals, prompt customer notifications of significant account events, and swift response to suspected breaches.Hong Kong SFC orders crypto platforms, online brokers to phase out OTP logins Senior management at licensed firms is explicitly held responsible for security failures that lead to client losses.
For any SFC-licensed crypto platform or broker, SMS codes and app OTPs can no longer be the main way you log in or bind devices; passwordless, device-bound methods will become standard.
2. Security Rationale And Risk Data
The SFCs move responds to a clear rise in phishing and social engineering attacks against crypto users. In Q1 2026, phishing scams caused about $306 million of the global crypto industrys $482 million losses, and similar attacks accounted for 57 percent of security incidents reported to Hong Kongs Cyber Security Accident Coordination Center in 2025.Hong Kong SFC forces crypto platforms to ditch SMS authentication
OTPs are vulnerable because attackers can relay codes entered on fake login pages in real time, and SMS OTPs are exposed to SIM swapping and telecom-level interception. Passkeys and hardware security keys use public-key cryptography and device binding, so there is no reusable code to steal and access is tied to a specific device, making phishing and replay attacks much harder.Hong Kong regulator orders new anti-phishing measures for crypto platforms
3. Impact On Crypto Users And Platforms
For retail crypto users in Hong Kong, the practical impact will be new login flows: enrolling passkeys on phones and laptops, using hardware keys for high-value accounts, and seeing more alerts about unusual activity. Some users may find setup more complex, but account takeover risk should drop meaningfully.
Platforms face implementation costs and UX redesign, but those with Hong Kong licenses gain a stronger trust signal as they align their security controls with traditional financial institutions.Hong Kong SFC orders crypto platforms, online brokers to phase out OTP logins Outside Hong Kong, unlicensed offshore exchanges are not directly affected, yet this move increases pressure on global platforms to retire weak OTP-based authentication.
If you use Hong Kong-licensed crypto services, expect stricter, device-bound logins; if you use offshore platforms, this is a good prompt to upgrade your own authentication beyond SMS codes.
Conclusion
Hong Kong is effectively declaring traditional OTP-based logins too weak for regulated crypto and brokerage platforms, forcing a transition to passkeys, hardware keys, and device binding. This raises the security baseline for Hong Kongs digital asset ecosystem and sends a broader signal that crypto platforms are expected to match or exceed banking-grade cybersecurity, even if it means more complex onboarding in the short term.
