Hong Kong’s Securities and Futures Commission (SFC) has introduced new cybersecurity rules requiring licensed virtual asset trading platforms (VATPs) and online brokers to adopt phishing-resistant authentication methods, marking a major step to improve crypto investor protection.
Under the new requirements announced on Thursday, firms must stop relying on one-time passwords (OTPs) sent through SMS, email or authentication apps for customer logins. Instead, they are required to deploy stronger security measures, including passkeys, registered devices with cryptographic verification and hardware security keys. All licensed platforms have 12 months to comply.
Hong Kong🇭🇰 Strengthens Position as Leading Global Asset and Wealth Management Hub
The Securities and Futures Commission (SFC) released 《Asset and Wealth Management Activities Survey 2025》. ⬇️https://t.co/qzQLdIW3bX
Key Highlights:
1️⃣Total Assets Under Management (AUM)…— Hong Kong Ethereum Community Hub (@ethereumhkhub) July 9, 2026
The regulator said the move is aimed at reducing the growing threat of phishing and account takeover attacks targeting crypto users.
Why is Hong Kong replacing SMS login codes?
The SFC said traditional one-time passwords are increasingly vulnerable to phishing attacks, where scammers trick users into revealing login credentials or approving fake transactions.
Under the new framework, crypto platforms must adopt authentication methods that are resistant to phishing and strengthen device verification to make unauthorized account access more difficult.
The regulator added that stronger security controls are necessary as fraud and impersonation attacks continue to increase across the financial sector.
According to the Hong Kong Cyber Security Accident Coordination Centre, counterfeiting and fraud accounted for 57% of all reported cybersecurity incidents in 2025.
READ ALSO: BlackRock Prepares Bitcoin Premium Income ETF to Expand Crypto Offerings
Phishing scams continue to drain crypto investors
The new rules come as phishing attacks remain one of the biggest security threats in the crypto industry.
During the first quarter of 2026, phishing attacks and social engineering scams accounted for $306 million of the industry’s total $482 million in reported losses.
The trend has continued throughout the year. On Wednesday, a crypto investor reportedly lost nearly $1 million after signing a malicious token approval transaction on Ethereum. Earlier this month, another wallet holder lost about $1.65 million after connecting to a fake crypto exchange and approving a malicious smart contract that gave attackers access to the funds.
Industry pushes for stronger wallet security
Security researchers have also warned of phishing campaigns that use fake websites and online advertisements to steal digital assets. In May, scammers reportedly impersonated decentralized exchange Uniswap through malicious Google ads, stealing more than $400,000 from victims.
The rise in phishing attacks has prompted calls for stronger wallet security across the industry. Binance co-founder Changpeng Zhao has previously urged users and platforms to improve security measures following several high-profile phishing and address poisoning scams that resulted in millions of dollars in losses.
Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads, and CoinMarketCap Community for seamless access to high-quality industry insights
Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.























































































