Bitget Hong Kong SFC Mandates Phishing-Resistant Authentication for Crypto Platforms
Article Content
- •Hong Kong's SFC mandates the elimination of OTPs for crypto platform logins within 12 months.
- •Phishing attacks accounted for $306 million in losses in Q1 2026, highlighting the urgency of these measures.
- •Senior management at firms will be held accountable for cybersecurity control failures.
On July 9, 2026, the Hong Kong Securities and Futures Commission (SFC) mandated that virtual asset trading platforms and online brokers phase out one-time passwords (OTPs) for user logins within 12 months. This directive aims to combat rising phishing attacks and account takeovers, which accounted for significant financial losses in the crypto industry. The SFC reported that spoofing attacks made up 57% of all security incidents in 2025. Platforms must implement stronger authentication methods, including passkeys and hardware security keys, and enhance monitoring of suspicious activities. The new measures are part of a broader effort to improve cybersecurity standards in the region amid increasing global threats. Firms are required to notify clients of significant account activities and respond promptly to any hacking incidents. Senior management will be held accountable for any failures in implementing these controls.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (19)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…