Hong Kong’s Securities and Futures Commission (SFC) just gave crypto platforms and online brokers a deadline. Twelve months to kill OTP-based logins and switch to passkeys. No exceptions.
The reason? Spoofing. The SFC reports a 57% spike in SMS-based authentication attacks. One-time passwords sent via text are getting intercepted at scale. It’s become a weak link that attackers are happily exploiting.
Passkeys aren’t new. They’re already the standard on most modern devices — biometric or PIN-based authentication that doesn’t leave the user’s device. No code to intercept. No SMS to hijack. Just a cryptographic handshake between your phone and the service.
The crypto industry should be paying attention. Exchange accounts hold real money, and OTP-based 2FA has been a known weak point for years. SIM-swapping attacks alone have drained millions from crypto wallets. Moving to passkeys closes that door entirely.
Twelve months sounds like a lot of runway. But compliance changes always take longer than expected. Platforms that start early won’t be scrambling when the deadline hits.
