Need help? Support
BITCOIN
Tether Dominance USDT.D

Hong Kong ends SMS OTP for crypto

Published 583 words 3 min read

TLDR

Hong Kong will phase out SMS and email one time passwords for crypto logins within a year, forcing licensed platforms to adopt stronger authentication and accept more liability for account hacks.

  1. The SFC has ordered licensed crypto platforms and internet brokers to stop using OTP logins and new device binding by July 8, 2027, or cover user losses from phishing.
  2. OTPs are being replaced by phishing?resistant methods such as passkeys, hardware keys and strong device binding after a sharp rise in credential theft driven by fake regulator and broker messages.
  3. For users this means more secure, but slightly more complex logins, while other jurisdictions are likely to study Hong Kongs model as a template for future crypto security rules.

Deep Dive

1. What Hong Kong Has Changed

Hong Kongs Securities and Futures Commission (SFC) issued a circular telling licensed virtual asset trading platforms and online brokers to stop using SMS, email and app one time passwords for client logins and new device registration by 8 July 2027. Platforms that keep relying on OTPs past that date can be held responsible for customer losses tied to phishing and weak authentication, rather than treating them as user mistakes.

Reports summarizing the circular note that large brokers are expected to comply immediately, while smaller firms have a 12 month transition window to upgrade authentication and monitoring controls for affected accounts. The rule is scoped to logins and binding new devices; OTPs can still be used in other flows, provided overall controls are strong enough to stop fraud at scale.

What this means

Crypto platforms in Hong Kong now have a clear deadline and legal incentive to move away from simple code based logins toward stronger, less phishable security models.

2. Why OTPs Are Being Targeted

The SFCs move follows a surge in phishing incidents where attackers impersonated brokers and regulators via text and email, capturing passwords plus OTP codes and draining accounts. Hong Kong logged 15,877 cybersecurity incidents in 2025, up 27 percent year on year, with phishing making up more than half of cases according to one summary of the circular.

In its guidance, the SFC argues that OTPs sent via SMS or email are too easy to intercept or trick users into sharing. It instead pushes phishing resistant methods based on public key cryptography, where a private key stays on the users device or hardware token and only signs challenges from legitimate services.

3. Impact For Users And Markets

For Hong Kong users, the practical change will be more prompts to register passkeys, hardware keys, or device based biometrics and fewer simple SMS login codes. Logins may feel less convenient at first, but the risk of account takeover should drop if platforms also improve monitoring and rapid response.

For platforms, stronger authentication is now directly tied to their regulatory duty to protect client assets, and senior managers can be held personally accountable for failures, as highlighted in an SFC focused recap on liability and OTP phase out.

Regulators in other hubs like Singapore and the UK face similar phishing pressure, and Hong Kongs approach will likely be watched as a model for linking concrete security standards to crypto licensing.

Conclusion

Hong Kong is effectively saying that weak login security for custodial crypto platforms is no longer acceptable and that platforms, not users, will bear more of the cost when things go wrong. If implemented well, the shift from SMS and email codes to passkeys and hardware backed authentication should lower phishing driven losses, and it may nudge other regulators toward similar, more opinionated security rules for centralized crypto venues.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top