Code & Chain · Signal Desk

Hong Kong SFC orders crypto platforms to adopt anti-phishing authentication, banning SMS and email OTP within a year

Original sourceAltcoinvest

Summary

Hong Kong's Securities and Futures Commission requires virtual asset trading platforms and online brokers to switch to phishing-resistant authentication within 12 months, banning SMS, email, or in-app one-time passwords. Acceptable alternatives include passkeys, registered device cryptographic veri…

Key points

  • Directly impacts compliance timelines and security architectures for all platforms serving Hong Kong users, with immediate operational relevance.
  • Hong Kong takes the lead with mandatory requirements for crypto platforms to eliminate weak authentication, raising the bar against phishing attacks.
  • Platforms must deploy hardware or biometric authentication within a year, potentially boosting demand for security keys and anti-phishing technologies.

Editorial note

This page is Code & Chain's editorial summary of public sources. It may be prepared with AI assistance and published through an automated workflow. Refer to the original sources; this content is not investment, legal, or tax advice.