The Hong Kong Securities and Futures Commission (SFC) has issued new rules aimed at reducing account takeovers on virtual asset trading platforms (VATPs) and onlineThe Hong Kong Securities and Futures Commission (SFC) has issued new rules aimed at reducing account takeovers on virtual asset trading platforms (VATPs) and online

Hong Kong Regulator Mandates New Anti-Phishing Rules for Crypto Firms

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com
Hong Kong Regulator Mandates New Anti-Phishing Rules For Crypto Firms

The Hong Kong Securities and Futures Commission (SFC) has issued new rules aimed at reducing account takeovers on virtual asset trading platforms (VATPs) and online brokers. The regulator says platforms in the city must upgrade authentication controls to make logins more resilient to phishing and other social engineering tactics.

The SFC requires stronger phishing-resistant authentication methods and device binding, and it bans one-time passwords delivered via SMS, email, or app-based logins. Companies covered by the rules have 12 months to implement the changes, which the SFC frames as a key part of raising local cybersecurity standards as phishing activity intensifies globally.

Key takeaways

  • The SFC’s new requirements apply to virtual asset trading platforms (VATPs) and online brokers operating in Hong Kong.
  • One-time passwords through SMS, email, or app-based logins are prohibited for these platforms.
  • Phishing-resistant authentication and device binding are required, with options such as passkeys and hardware security keys.
  • Covered firms must complete implementation within 12 months from issuance.
  • The SFC linked the update to rising phishing and social engineering losses in the broader crypto industry.

What the SFC is requiring for crypto login security

In a statement released Thursday, the Hong Kong regulator outlined specific expectations for authentication on VATPs and online brokers. The SFC’s document sets out requirements for phishing-resistant methods and device binding, aiming to prevent attackers from hijacking accounts through fraudulent login prompts or compromised credentials.

According to the SFC, the new standards disallow one-time passwords delivered by SMS, email, or via app-based logins. Instead, the commission points to stronger alternatives designed to reduce the effectiveness of phishing scams—for example, passkeys, registered devices with cryptographic verification, and hardware security keys.

The formal requirements are available through the SFC’s publication gateway: SFC requirements document.

Why Hong Kong is tightening rules now

The SFC’s move arrives at a moment when phishing and social engineering incidents continue to disrupt crypto users worldwide. The SFC said that in the first quarter of 2026, phishing-related tactics accounted for a significant portion of reported industry losses.

As reported by Cointelegraph earlier, industry losses totaled $482 million in the period, with $306 million attributed to phishing attacks and social engineering scams. The SFC also referenced a separate local data point: counterfeiting and fraud incidents represented 57% of security incidents reported to the Hong Kong Cyber Security Accident Coordination Center in 2025.

In remarks carried in the SFC materials, Dr. Ye Zhiheng, executive director of the Intermediaries Department of the China Securities Regulatory Commission, said that protecting customers from increasingly complex counterfeiting and fraud attacks requires comprehensive measures spanning prevention, detection, response, and education.

Real-world phishing losses underscore the risk

The SFC’s tightening reflects a pattern already visible in recent crypto incidents: attackers often use phishing to trick users into signing approvals or connecting wallets to fraudulent pages. These actions can grant attackers control over funds or enable unauthorized transfers.

Cointelegraph reported on Wednesday that a crypto investor lost nearly $1 million after signing a malicious phishing token approval transaction on Ethereum. Earlier coverage also described another case in which a wallet holder reportedly lost $1.65 million after connecting to a fake exchange and signing a malicious contract that gave attackers unlimited access to funds. Researcher Ryan Coleman made the assessment in a post shared on X: RyanColeXBT.

Additional examples cited in earlier reporting highlight the variety of phishing delivery methods. Cointelegraph noted that on May 25, on-chain analyst “b-block” warned scammers used Google to deploy malicious phishing ads impersonating decentralized exchange Uniswap, reportedly stealing more than $400,000 from victims. That earlier report is here: Cointelegraph on fake Uniswap ads.

Broader industry leaders have also called attention to wallet security weaknesses that phishing exploits. Cointelegraph previously connected such risks to discussions from Binance co-founder Changpeng Zhao after major investor losses, including a $50 million address poisoning incident in December 2025. Earlier coverage on that topic is here: Zhao’s remarks and related loss.

Device binding and passkeys: what changes for users and platforms

Although phishing attacks often start with a message that looks legitimate, the SFC’s approach targets the authentication layer that attackers rely on. By requiring phishing-resistant authentication and device binding, the rules are designed to reduce the chances that credentials or approvals obtained through a scam lead directly to account compromise.

For platforms, the practical implication is that they cannot treat multi-factor authentication as a checkbox. The SFC’s explicit ban on SMS/email one-time passwords is especially important because these methods can still be vulnerable to social engineering and interception—scenarios where attackers focus on tricking users into providing the second factor or luring them into fraudulent flows.

Instead, the SFC highlights methods that tie authentication to trusted hardware or cryptographic verification. Passkeys, cryptographic device registration, and hardware security keys all share a common theme: the login mechanism should be harder for attackers to replicate via fraudulent prompts, and stronger controls should ensure that only authorized devices can complete authentication.

For Hong Kong users, the change may eventually translate into a more consistent login experience with fewer fallback authentication options. For investors and traders, stronger login security is not just a compliance issue; it can be a direct determinant of whether account takeover attempts succeed—particularly when platforms integrate authentication with deposit, withdrawal, and trading permissions.

Still, one key uncertainty remains: how quickly different VATPs and online brokers will choose among the SFC’s allowed phishing-resistant alternatives, and how smooth the migration will be for end users. With a 12-month deadline, platform execution and user onboarding processes will likely be crucial in determining how effectively the new rules reduce real-world phishing losses.

With the SFC setting a clear timeline and banning weaker authentication methods, attention should now turn to how quickly Hong Kong platforms roll out passkeys or device-bound cryptographic authentication—and whether regulators will later expand requirements as phishing tactics evolve.

This article was originally published as Hong Kong Regulator Mandates New Anti-Phishing Rules for Crypto Firms on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.

Market Opportunity
REAL Logo
REAL Price(ASSET)
$0.28103
$0.28103$0.28103
-2.01%
USD
REAL (ASSET) Live Price Chart

Get Covered, Share 1M USDT

Get Covered, Share 1M USDTGet Covered, Share 1M USDT

Higher VVIP tiers, higher compensation odds.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

The post One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight appeared on BitcoinEthereumNews.com. Frank Sinatra’s The World We Knew returns to the Jazz Albums and Traditional Jazz Albums charts, showing continued demand for his timeless music. Frank Sinatra performs on his TV special Frank Sinatra: A Man and his Music Bettmann Archive These days on the Billboard charts, Frank Sinatra’s music can always be found on the jazz-specific rankings. While the art he created when he was still working was pop at the time, and later classified as traditional pop, there is no such list for the latter format in America, and so his throwback projects and cuts appear on jazz lists instead. It’s on those charts where Sinatra rebounds this week, and one of his popular projects returns not to one, but two tallies at the same time, helping him increase the total amount of real estate he owns at the moment. Frank Sinatra’s The World We Knew Returns Sinatra’s The World We Knew is a top performer again, if only on the jazz lists. That set rebounds to No. 15 on the Traditional Jazz Albums chart and comes in at No. 20 on the all-encompassing Jazz Albums ranking after not appearing on either roster just last frame. The World We Knew’s All-Time Highs The World We Knew returns close to its all-time peak on both of those rosters. Sinatra’s classic has peaked at No. 11 on the Traditional Jazz Albums chart, just missing out on becoming another top 10 for the crooner. The set climbed all the way to No. 15 on the Jazz Albums tally and has now spent just under two months on the rosters. Frank Sinatra’s Album With Classic Hits Sinatra released The World We Knew in the summer of 1967. The title track, which on the album is actually known as “The World We Knew (Over and…
Share
BitcoinEthereumNews2025/09/18 00:02
Not a loophole: Singapore AI export controls let China tap US AI legally

Not a loophole: Singapore AI export controls let China tap US AI legally

American AI technology is reaching Chinese tech giants through a route that US export controls were never designed to close: Singapore. The city-state sits outside
Share
The Cryptonomist2026/07/10 14:46
LIST: Bayanihan initiatives amid soaring oil prices

LIST: Bayanihan initiatives amid soaring oil prices

Here is a running list of initiatives and efforts you can support to help sectors affected by the oil price hikes
Share
Rappler2026/04/02 18:14

Record Ads, Stock Down 7%

Record Ads, Stock Down 7%Record Ads, Stock Down 7%

Jul 29: Meta earnings face the market's question.