Hong Kong SFC Mandates Phishing-Resistant Authentication for Crypto Platforms

Hong Kong SFC Mandates Phishing-Resistant Authentication for Crypto Platforms

First seen 9 Jul 2026, 18:11 UTC KucoinTheblock.CoBitgetCryptorankFeeds.Feedburner+6 92% similarity 69.5

Article Content

Browse articles
ThreatCluster

On July 9, 2026, the Hong Kong Securities and Futures Commission (SFC) mandated that virtual asset trading platforms and online brokers phase out one-time passwords (OTPs) for user logins within 12 months. This directive aims to combat rising phishing attacks and account takeovers, which accounted for significant financial losses in the crypto industry. The SFC reported that spoofing attacks made up 57% of all security incidents in 2025. Platforms must implement stronger authentication methods, including passkeys and hardware security keys, and enhance monitoring of suspicious activities. The new measures are part of a broader effort to improve cybersecurity standards in the region amid increasing global threats. Firms are required to notify clients of significant account activities and respond promptly to any hacking incidents. Senior management will be held accountable for any failures in implementing these controls.

Key Points: • Hong Kong's SFC mandates the elimination of OTPs for crypto platform logins within 12 months. • Phishing attacks accounted for $306 million in losses in Q1 2026, highlighting the urgency of these measures. • Senior management at firms will be held accountable for cybersecurity control failures.

ThreatCluster AI

Timeline

2025-01-01
Phishing attacks surge in crypto industry
Phishing attacks and social engineering scams caused $306 million in losses in Q1 2026, prompting regulatory action.
Bitget
2025-01-05
SFC reports spoofing attacks
The Hong Kong Cyber Security Incident Coordination Centre reported that spoofing attacks accounted for 57% of security incidents in 2025.
Theblock.Co
2026-07-09
SFC issues new security requirements
The SFC mandates crypto platforms to replace OTPs with phishing-resistant methods, with a 12-month compliance deadline.
Kucoin
2026-07-09
SFC emphasizes accountability for management
The SFC stated that senior management will be held accountable for cybersecurity control failures leading to client losses.
Feeds.Feedburner

Community

Browse all →