Hong Kong SFC mandates crypto platforms and online brokers phase out OTP logins for passkeys within 12 months following a 57% surge in spoofing attacks.
Regulation & Gov ·
Hong Kong's Securities and Futures Commission has mandated that crypto platforms and online brokers replace one-time password logins with passkeys within a 12-month window. The directive follows a 57 percent increase in spoofing attacks targeting users of these platforms, prompting regulators to tighten authentication standards.
One-time passwords have become a focal point for fraud schemes in which attackers impersonate legitimate services to trick users into revealing their credentials. Passkeys, which rely on cryptographic keys rather than user-generated codes, eliminate the human-factor vulnerability inherent in OTP systems. The shift addresses a specific attack vector that has grown significantly within the regulated sector.
The timeline allows platforms to implement the required infrastructure changes, though the extent of technical or operational challenges for smaller firms remains unclear. Enforcement mechanisms and whether extensions or phased compliance pathways may be granted have not been detailed in available reports.