Follow

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Subscribe

SFC Mandates Phishing-Resistant Authentication for Crypto Platforms

SFC phishing-resistant authentication SFC phishing-resistant authentication

The Hong Kong Securities and Futures Commission (SFC) issued a circular on 9 July 2026 requiring licensed virtual asset trading platforms (VATPs) and internet brokers to implement SFC phishing-resistant authentication and device binding within 12 months, retiring SMS one-time passwords entirely.

What the SFC circular actually requires

The mandate covers more than login flows. According to Tanner De Witt, the circular extends to device binding and ongoing surveillance of suspicious account activity, meaning firms cannot simply bolt on a passkey and call it done. They will need to instrument their platforms to detect anomalous session behaviour post-login as well.

Acceptable alternatives under the new framework include passkeys, registered devices verified through cryptographic attestation, and hardware security keys. SMS codes, email OTPs, and app-generated codes are all out. All licensed platforms must complete the transition within one year of the circular’s issuance.

The regulator’s timing reflects a specific threat pattern. Tanner De Witt notes that throughout 2025, fraudsters ran large-scale SMS phishing campaigns aimed squarely at clients of Hong Kong internet brokers and virtual asset service providers, using malicious links that impersonated brokers, or spoofed regulators and government bodies to harvest login credentials and one-time passwords on fake sites.

AI-enabled attacks behind the SFC phishing-resistant authentication push

The July circular does not stand alone. A separate SFC circular, reference 26EC32, published in June 2026, addresses AI-enabled cyberattacks specifically, directed at licensed corporations, SFC-licensed virtual asset service providers, and their associated entities.

Davis Polk reports that the June circular noted a 27% year-on-year increase in cybersecurity incidents among licensed firms. Fintech Global reports the SFC linked part of that increase to AI tooling that allows malicious actors to exploit system weaknesses faster and at greater scale than conventional methods.

The SFC also cited data from the Hong Kong Cyber Security Accident Coordination Centre showing counterfeiting and fraud accounted for 57% of reported security incidents in 2025. Dr Ye Zhiheng, executive director of the Intermediaries Department of the China Securities Regulatory Commission, noted that financial institutions require coordinated prevention, detection, response, and education measures to protect customer accounts from increasingly sophisticated fraud.

The phishing loss backdrop pushing regulators to act

The scale of losses gives the regulatory urgency some context. Phishing attacks and social engineering scams accounted for $306 million of the crypto sector’s $482 million in total security losses during Q1 2026 alone. By the end of H1 2026, phishing-related losses across the industry had reached $366 million.

Incident-level data reinforces the pattern. Researcher Ryan Coleman reported a wallet holder losing approximately $1.65 million after connecting to a fake exchange and signing a malicious contract that granted attackers unlimited access. On 25 May, on-chain analyst b-block flagged a campaign using Google advertisements to impersonate Uniswap, reportedly draining more than $400,000 from victims. One Ethereum user lost nearly $1 million after approving a malicious phishing token transaction.

Binance co-founder Changpeng Zhao previously urged stronger security practices after an investor lost $50 million in an address poisoning scam in December 2025. The address-poisoning vector is distinct from phishing but sits in the same broader category of social-engineering and UI-spoofing attacks that regulators are now moving to contain at the platform authentication layer.

Hong Kong’s broader regulatory build-out

The authentication mandate fits within a wider regulatory push. Earlier this week, the SFC revised the Certified Virtual Asset Platform Practitioner programme, separating the certification exam from its mandatory course and lowering assessment fees. The Hong Kong Monetary Authority has also granted issuer licences to two bank-backed institutions for stablecoins, with the first regulated stablecoins expected to enter circulation between mid and late 2026.

For VATPs and internet brokers, the 12-month clock is now running. Firms that have not already piloted passkey or hardware-key infrastructure will need to move fast: a 12-month window covers planning, vendor selection, UAT, and a staged rollout for a client base that has been conditioned to OTP flows for years. The SFC’s willingness to issue both the phishing circular and the AI circular in the same quarter signals it is not done tightening the screws on operational security.

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use