Hong Kong's Securities and Futures Commission (SFC) has announced new cybersecurity rules for crypto trading platforms and online brokers, mandating phishing‑resistant authentication within 12 months. One‑time passwords via SMS, email or apps are banned, to be replaced by stronger measures such as passkeys and hardware tokens.

Key Takeaways

  • SFC requires phishing‑resistant authentication within 12 months
  • SMS, email and app‑based OTPs will be prohibited
  • Passkeys, hardware tokens and biometric options become mandatory

The Hong Kong Securities and Futures Commission (SFC) unveiled a comprehensive regulatory framework on July 8, directing all cryptocurrency‑asset trading platforms and online brokers to adopt phishing‑resistant authentication methods within the next year. This decisive move reflects SFC’s heightened focus on safeguarding investors amid escalating cyber‑threats worldwide.

What the New Rules Entail

The framework contains two core provisions. First, one‑time passwords (OTPs) delivered via SMS, email or mobile applications are outright banned. Second, firms must replace these weak mechanisms with more robust alternatives such as passkeys, hardware security tokens, biometric verification (fingerprint or facial recognition) or other multi‑factor authentication (MFA) solutions. The overarching goal is to minimise the risk of phishing attacks and protect user data from unauthorized access.

Background and Global Context

Hong Kong has emerged as a leading hub for crypto trading in the Asia‑Pacific region over the past five years. However, 2023‑24 saw a spate of high‑profile phishing scams that inflicted significant losses on retail investors, prompting regulators to demand stricter security standards. The European Union’s MiCA (Markets in Crypto‑Assets) regime and similar initiatives worldwide have set a precedent for comprehensive crypto oversight, and Hong Kong’s latest measures align the city with these international benchmarks.

Potential Impact on the Industry

Smaller exchanges and boutique brokers may face substantial costs and operational hurdles to upgrade their authentication infrastructure. Larger firms, many of which already employ sophisticated security stacks, are likely to gain a competitive edge through enhanced user confidence. Analysts predict that the heightened trust could translate into higher trading volumes over the long term, while simultaneously curbing fraudulent activity.

Looking Ahead

SFC has indicated that this framework is only the first phase of a broader cybersecurity agenda. Future directives may mandate encrypted data transfers, continuous risk assessments, and periodic third‑party audits. Platforms are required to submit quarterly progress reports, ensuring transparency and accountability throughout the transition period.