Bitget
Hong Kong SFC Mandates Phishing-Resistant Authentication for Crypto Platforms
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On July 9, 2026, the Hong Kong Securities and Futures Commission (SFC) mandated that virtual asset trading platforms and online brokers phase out one-time passwords (OTPs) for user logins within 12 months. This directive aims to combat rising phishing attacks and account takeovers, which accounted for significant financial losses in the crypto industry. The SFC reported that spoofing attacks made up 57% of all security incidents in 2025. Platforms must implement stronger authentication methods, including passkeys and hardware security keys, and enhance monitoring of suspicious activities. The new measures are part of a broader effort to improve cybersecurity standards in the region amid increasing global threats. Firms are required to notify clients of significant account activities and respond promptly to any hacking incidents. Senior management will be held accountable for any failures in implementing these controls.
Key Points: • Hong Kong's SFC mandates the elimination of OTPs for crypto platform logins within 12 months. • Phishing attacks accounted for $306 million in losses in Q1 2026, highlighting the urgency of these measures. • Senior management at firms will be held accountable for cybersecurity control failures.