Hong Kong’s securities regulator just dropped a new rulebook for crypto platforms and online brokers. The headline: SMS-based and email one-time passwords are out. Passkeys, hardware security keys, and cryptographically verified devices are in.
The Hong Kong Securities and Futures Commission (SFC) published the requirements on Thursday, giving virtual asset trading platforms and online brokers 12 months to get compliant. The goal is simple — make phishing a lot harder.
It’s not hard to see why they’re pushing this. Phishing and social engineering scams accounted for $306 million of the $482 million the crypto industry lost in Q1 2026 alone, according to Hacken. That’s nearly two-thirds of all losses from one attack vector.
Hong Kong’s own numbers tell a similar story. The local Cyber Security Accident Coordination Center reported that counterfeiting and fraud attacks made up 57% of security incidents in 2025.
“To protect customer accounts from increasingly complex counterfeiting and fraud attacks, comprehensive measures must be implemented in conjunction with prevention, detection, response and education,” said Dr. Ye Zhiheng, the SFC’s executive director of intermediaries.
This isn’t just theoretical. This week, a crypto investor lost nearly $1 million after signing a malicious phishing token approval on Ethereum. Earlier this month, someone else lost $1.65 million connecting to a fake exchange. These aren’t sophisticated exploits — they’re old-school social engineering dressed up in Web3 clothes.
The SFC wants platforms to use phishing-resistant authentication methods. Think passkeys, registered devices with cryptographic checks, and hardware security keys that can’t be phished with a convincing fake login page.
Binance co-founder Changpeng Zhao has called for better wallet security before, especially after an investor lost $50 million in an address poisoning scam last December. The problem isn’t going away — the industry just needs to stop using authentication methods designed for a world without phishing.
