Hong Kong SFC orders brokers, crypto platforms to phase out one-time passwords

Hong Kong SFC orders brokers, crypto platforms to phase out one-time passwords

Licensed virtual asset platforms and online brokers must replace OTPs for client logins and new-device binding by July 8, 2027, while strengthening fraud monitoring, alerts and incident response under tighter cybersecurity rules.

Fact Check
The primary SFC press release (refNo=26PR101) directly confirms the regulator ordered internet brokers and virtual asset trading platforms to phase out one-time passwords for client login and device binding, adopting phishing-resistant methods within 12 months. The claim's mention of passkeys, device binding, and hardware security keys is corroborated by the Cointelegraph article, which explicitly lists passkeys, registered devices with cryptographic verification, and hardware security keys. Crypto Briefing independently confirms Circular 26EC35 and the 12-month timeline. All three sources agree on the core facts.
    Reference123
Summary

Hong Kong’s Securities and Futures Commission has ordered licensed virtual asset service providers and internet brokers to replace one-time passwords used for client logins and new-device registration or binding with phishing-resistant authentication by July 8, 2027. The July 9 circular says OTPs no longer meet the required standard for those two processes, though other OTP uses are unchanged. Large internet brokers are expected to deploy stronger methods immediately, while the broader group has a 12-month implementation period. The regulator also imposed immediate expectations for stronger client notifications, account monitoring, surveillance and incident response, and said firms can be held accountable for client losses if inadequate safeguards fail to prevent, detect and stop large-scale unauthorized transactions after a hacking incident.

Terms & Concepts
  • passkeys: Login credentials that use public-key cryptography instead of reusable secrets, helping prevent phishing.
  • device binding: A security measure that links an account to a specific device after verification to reduce unauthorized access.
  • public-key cryptography: A system that uses paired public and private keys so a private credential does not need to be shared with a website.