EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Hong Kong orders cryptocurrency platforms to replace OTP logins with stronger security measures

2026-07-10 00:02:26
Bookmark

Hong Kong has ordered cryptocurrency platforms and brokerages to replace one-time password login with a more powerful authentication method within 12 months, and this requirement will take effect nationwide immediately. Regulators also require relevant companies to monitor suspicious logins, transactions and withdrawals, and immediately notify customers when major account activity occurs. Hong Kong authorities have warned that if customers suffer losses due to weak internal controls, companies will be held accountable, and senior management will also bear corresponding responsibility for dereliction of network security.

New regulations require enhanced login security

Hong Kong\'s Securities and Futures Commission (SFC) has issued a directive requiring licensed virtual asset trading platforms and Internet brokerages to phase out one-time password login methods and adopt more powerful authentication methods to address increasingly complex cybersecurity threats. The agency announced the new requirements in a notice issued Thursday. According to the instructions, companies must stop using one-time passwords for customer login and device registration, and instead use authentication methods such as binding a password to a device that can more effectively prevent impersonation attacks. In addition, SFC stated that relevant companies should implement these changes as soon as possible. All licensees need to complete compliance within 12 months at the latest, but regulators are urging large Internet brokerages to immediately begin deploying new identity verification systems.

New measures go beyond login security

In addition to replacing one-time passwords, regulators are also requiring companies to improve their ability to detect suspicious account activity. Licensed institutions must deploy monitoring systems to identify unusual login attempts, trading patterns and withdrawal requests before customer assets are put at risk. At the same time, companies must promptly notify customers when major account activity occurs, respond quickly to suspected hacking incidents, and continue to educate users about phishing attacks, fraud scams and other emerging cybersecurity threats. SFC said the measures were in response to the growing number of cyber incidents targeting online financial services. Data from the Hong Kong Cybersecurity Incident Coordination Center shows that fraud attacks accounted for 57% of all reported cybersecurity incidents in 2025. Dr. Yip Zhiheng, Executive Director of the Intermediary Division of SFC, pointed out that licensees need to adopt a comprehensive approach that combines prevention, detection, response and customer education to respond to increasingly complex phishing attacks. He emphasized that companies should strengthen their identity verification systems, be vigilant against suspicious activities, and respond promptly before financial losses occur.

Senior management assumes greater responsibility

In addition, regulators reminded senior management that the ultimate responsibility for protecting customer accounts lies with company leadership. Executives must ensure that their organizations maintain effective internal controls and adequate cybersecurity safeguards. Therefore, SFC warned that if customers suffer losses due to weak internal security controls, licensees will be held accountable. As cybersecurity threats continue to evolve, regulators expect agencies to strengthen governance while strengthening technical defenses. This latest directive highlights Hong Kong\'s continued efforts to improve cybersecurity standards in the regulated financial sector and enhance trust in the digital asset ecosystem.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP