Hong Kong SFC bans OTP logins for brokers and crypto
Hong Kong’s SFC ordered online brokerages and virtual asset platforms to stop OTP logins and device binding and adopt passkeys within 12 months; spoofing made up 57% of incidents.
Hong Kong’s Securities and Futures Commission issued a circular on Thursday directing licensed internet brokerage firms and virtual asset trading platforms to stop using one-time passwords for customer logins and device registration and to adopt passkeys or other stronger authentication methods within 12 months. The regulator said large internet brokers should move to the new methods immediately.
The SFC cited data from the Hong Kong Cyber Security Incident Coordination Centre showing spoofing accounted for 57% of reported security incidents in 2025. The circular said one-time passwords are vulnerable to phishing and SIM-swap attacks that allow attackers to impersonate customers and gain access to accounts.
The regulator asked firms to replace SMS- and app-based OTPs with cryptographic passkeys or strong device-based authentication that resist impersonation. Firms were told to complete risk assessments and submit implementation plans that show how they will meet the 12-month deadline.
The SFC also required firms to strengthen detection and surveillance systems to flag suspicious login, trading and withdrawal activity, to notify clients promptly about significant account activity, and to maintain clear incident-response processes. Firms must regularly warn customers about emerging impersonation scams and other cybersecurity risks.
Senior management at licensed internet brokers and virtual asset platforms were reminded that they bear ultimate responsibility for controls that protect customer accounts and assets. The regulator said it will hold firms accountable for customer losses resulting from deficiencies in internal controls.
The circular did not mandate a single vendor or technology standard. Firms may select solutions that meet the SFC’s guidance and reduce the risk of account takeovers. Dr. Yip Chi-hang, Executive Director of the Intermediaries Division of the SFC, urged firms to strengthen authentication, monitor for suspicious activity and respond quickly to incidents.
The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.








