Hong Kong SFC bans OTPs, boosts crypto platform security

Hong Kong’s SFC bans OTPs for crypto platforms, requiring stronger authentication like passkeys and hardware keys, with a 12-month deadline. Senior management will be held accountable for security failures.

The Hong Kong Securities and Futures Commission (SFC) has ordered virtual asset trading platforms and online brokerages to stop using one-time passwords (OTPs) for customer login and device binding. This decision comes in response to a rise in phishing and impersonation attacks targeting users. Instead, the SFC now requires the adoption of stronger authentication methods, such as passkeys, cryptographically registered devices, and hardware security keys. These methods are considered more resistant to phishing attempts and provide enhanced protection for users. Large internet brokerages must comply with these new measures immediately, while other institutions have a 12-month deadline. The directive also mandates improved monitoring of abnormal logins, trading, and withdrawals, as well as prompt customer notifications in case of incidents. Senior management will be held personally accountable for losses caused by internal control failures. The SFC aims to set a higher cybersecurity standard for the crypto sector amid rising online fraud.

Related News