Skip to main content
Esc

Type to search

Articles / crypto-defi-blockchain / SFC Requires Brokers and Crypto Platforms to Stop Using OTPs for Client Login

SFC Requires Brokers and Crypto Platforms to Stop Using OTPs for Client Login

Jul 10, 2026 · Source: fintechnews.hk · Topic:  crypto-defi-blockchain · fintech
Transition Period
12 months
Firms must complete the transition to stronger authentication methods within this timeframe.

§ 01 Executive Snapshot

  • What: The SFC mandates Hong Kong brokers and crypto platforms to cease using one-time passwords for client login.
  • Who: Securities and Futures Commission (SFC), internet brokers, virtual asset trading platforms.
  • Why it matters: This regulation aims to enhance client security against phishing attacks and holds firms accountable for protecting client assets.

§ 02 Key Developments

  • The SFC has ordered firms to implement stronger, phishing-resistant authentication methods immediately.
  • Firms are required to complete the transition within 12 months from the issuance of the circular.
  • Large internet brokers are expected to adopt these new measures without delay.

§ 03 Strategic Context

  • The regulation reflects a growing concern over the risks associated with one-time passwords, which have been exploited in phishing attacks.
  • This move aligns with global trends toward enhancing cybersecurity protocols within financial services to safeguard client information.

§ 04 Strategic Implications

  • Immediate consequence: Firms will need to invest in new authentication technologies, impacting operational budgets and compliance strategies.
  • Long-term implication: Strengthened security measures may restore client trust and reduce the incidence of fraud in the sector.

§ 05 Risks & Constraints

  • Potential risk: Firms may face challenges in adopting new technologies quickly enough to comply with the SFC's timeline.
  • Potential risk: Increased scrutiny may lead to operational disruptions as firms adjust to new regulatory requirements and enhance their security frameworks.

§ 06 Watchlist / Forward Signals

  • A key milestone to watch is the completion of the transition by firms within the mandated 12-month period.
  • Monitoring the effectiveness of new authentication methods and the response to phishing incidents will signal the success of this regulatory change.
§ 07

Frequently Asked Questions

What is the new requirement from the SFC regarding client login?

The SFC mandates that Hong Kong brokers and crypto platforms cease using one-time passwords for client login.

Why is the SFC implementing this regulation?

This regulation aims to enhance client security against phishing attacks and holds firms accountable for protecting client assets.

How long do firms have to transition to new authentication methods?

Firms are required to complete the transition within 12 months from the issuance of the circular.

§ 08

Related Articles