ADVERTISEMENT

Events

IAMTN Annual Summit 2026
14 Oct 26
London
Money20/20 USA 2026
18 Oct 26
Las Vegas

Hong Kong Tightens Crypto Login Rules with Phishing-resistant Security Standards

Hong Kong’s Securities and Futures Commission (SFC) has introduced new cybersecurity rules requiring licensed virtual asset trading platforms (VATPs) and online brokers to adopt phishing-resistant authentication methods, marking a major step to improve crypto investor protection.

Under the new requirements announced on Thursday, firms must stop relying on one-time passwords (OTPs) sent through SMS, email or authentication apps for customer logins. Instead, they are required to deploy stronger security measures, including passkeys, registered devices with cryptographic verification and hardware security keys. All licensed platforms have 12 months to comply.

The regulator said the move is aimed at reducing the growing threat of phishing and account takeover attacks targeting crypto users.

Why is Hong Kong replacing SMS login codes?

The SFC said traditional one-time passwords are increasingly vulnerable to phishing attacks, where scammers trick users into revealing login credentials or approving fake transactions.

Under the new framework, crypto platforms must adopt authentication methods that are resistant to phishing and strengthen device verification to make unauthorized account access more difficult.

The regulator added that stronger security controls are necessary as fraud and impersonation attacks continue to increase across the financial sector.

According to the Hong Kong Cyber Security Accident Coordination Centre, counterfeiting and fraud accounted for 57% of all reported cybersecurity incidents in 2025.

READ ALSO: BlackRock Prepares Bitcoin Premium Income ETF to Expand Crypto Offerings

Phishing scams continue to drain crypto investors

The new rules come as phishing attacks remain one of the biggest security threats in the crypto industry.

During the first quarter of 2026, phishing attacks and social engineering scams accounted for $306 million of the industry’s total $482 million in reported losses.

The trend has continued throughout the year. On Wednesday, a crypto investor reportedly lost nearly $1 million after signing a malicious token approval transaction on Ethereum. Earlier this month, another wallet holder lost about $1.65 million after connecting to a fake crypto exchange and approving a malicious smart contract that gave attackers access to the funds.

Industry pushes for stronger wallet security

Security researchers have also warned of phishing campaigns that use fake websites and online advertisements to steal digital assets. In May, scammers reportedly impersonated decentralized exchange Uniswap through malicious Google ads, stealing more than $400,000 from victims.

The rise in phishing attacks has prompted calls for stronger wallet security across the industry. Binance co-founder Changpeng Zhao has previously urged users and platforms to improve security measures following several high-profile phishing and address poisoning scams that resulted in millions of dollars in losses.

 

Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads, and CoinMarketCap Community for seamless access to high-quality industry insights

Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.

ADVERTISEMENT
ADVERTISEMENT

Spotlight

-
00:00
00:00
Update Required Flash plugin
-
00:00
00:00