Hong Kong gives crypto platforms one year to replace one-time passwords

The reported rule would require exchanges to adopt safer authentication, with firms potentially liable for user losses if they keep relying on SMS-based security.

Summary

Hong Kong is giving crypto platforms a one-year window to move away from one-time passwords as a primary security tool, with operators facing potential responsibility for user losses if they fail to upgrade. The shift points to tougher expectations around account protection in a market where compromised logins and social-engineering attacks have remained a persistent risk. In practice, the change would push platforms toward stronger authentication methods and tighter internal controls, raising the bar for retail user protection in one of Asia's key digital-asset hubs.

Terms & Concepts
  • one-time passwords: Single-use login or verification codes
  • authentication: Process of verifying a user's identity
  • crypto platforms: Digital-asset trading or service providers