Newsroom
9 July, 2026 / News / AI / 681 reads / Tags: phishing, kong, sfc, hong, authentication

The Hong Kong Securities and Futures Commission has directed licensed virtual asset trading platforms and online brokers to replace one-time password authentication with stronger phishing-resistant methods within 12 months
The Hong Kong Securities and Futures Commission issued updated requirements for customer account protection on July 9, 2026. Licensed virtual asset trading platforms and online brokers must stop using one-time passwords sent via SMS, email, or generated through apps for logins and device binding.
Instead, firms need to implement phishing-resistant options combined with device binding. Acceptable methods include passkeys, devices secured through cryptographic verification, and hardware security keys. The transition must occur within one year, with larger firms expected to move faster.
The SFC cited data from the Hong Kong Cyber Security Incident Coordination Center showing that counterfeiting and fraud made up 57% of reported security incidents in 2025. This regulatory step addresses the increase in phishing and social engineering attacks targeting crypto users.
Global crypto security losses reached $482 million in the first quarter of 2026, with phishing and related scams accounting for $306 million of that total. Additional reports indicated phishing-linked losses climbed to $366 million in the first half of the year.
Multiple cases demonstrated the impact of phishing tactics. One investor lost nearly $1 million after approving a malicious token transaction on Ethereum. Another wallet holder lost about $1.65 million following connection to a fake exchange and signing of a malicious contract.
Scammers also used Google advertisements to impersonate a decentralized exchange, resulting in over $400,000 in losses. Earlier incidents included a $50 million loss from address poisoning in late 2025.
The SFC reminded senior management at licensed firms that they hold ultimate responsibility for adequate controls. Firms must enhance monitoring of suspicious login, trading, and withdrawal activities, notify clients of significant account events, and provide regular warnings about emerging risks.
This update forms part of ongoing efforts to maintain high operational standards in Hong Kong's digital asset sector. The SFC continues to develop its framework for virtual asset activities while addressing specific vulnerabilities in customer access and account security.
| Aspect | Previous Approach | New Requirement |
|---|---|---|
| Authentication Methods | OTP via SMS, email, or apps | Phishing-resistant with device binding |
| Timeline | No specific mandate | Full transition in 12 months |
| Focus | Basic multi-factor | Prevention of account takeovers |
The SFC's circular sets clear expectations for platforms operating in the jurisdiction as part of its commitment to customer protection amid evolving threats.









