๐Ÿ“… Wednesday, 23 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Rp4,9 Triliun Duit Nasabah Amblas Kena Phishing - Bursa Kripto Hong Kong Kini Wajib Buang OTP SMS

$306M Lost to Phishing - Hong Kong Crypto Exchanges Now Required to Drop SMS OTPs

The Securities and Futures Commission of Hong Kong (SFC) has officially ordered all licensed crypto trading platforms and online brokers to stop using SMS-based authentication - and replace it with login methods that are far more resilient against hackers within the next 12 months.

According to the SFC, virtual asset trading platforms (VATPs) and online brokers must phase out one-time passwords (OTPs) sent via SMS, email, or standard authenticator apps. In their place, the regulator mandates the adoption of passkeys, cryptographically verified registered devices, or hardware security keys - combined with device binding systems.

The Numbers Behind the New Rule

The rule does not come without reason. The SFC noted that fraud and identity impersonation accounted for 57% of all security incidents reported to the Hong Kong Cyber Security Accident Coordination Center throughout 2025. Across the global crypto industry, phishing and social engineering attacks accounted for approximately Rp4.9 trillion (US$306 million) out of the total Rp7.7 trillion (US$482 million) in security losses in the first quarter of 2026 alone.

The concrete cases are chilling: one investor lost nearly Rp16 billion (US$1 million) after approving a malicious phishing token transaction on the Ethereum network. In another case, a wallet holder lost around Rp26.4 billion (US$1.65 million) after connecting to a fake crypto exchange and signing a contract that granted hackers unlimited access to their wallet.

Not Just About Logins, but an Ecosystem of Trust

The SFC emphasized that this move aligns with broader efforts to strengthen operational standards across Hong Kong’s digital asset sector - including an overhaul of the Certified Virtual Asset Platform Practitioner professional certification program announced this week, which decouples the certification exam from its mandatory course and lowers assessment fees.

Dr. Ye Zhiheng from the China Securities Regulatory Commission emphasized that financial institutions require coordinated prevention, detection, response, and education measures to safeguard customer accounts against increasingly sophisticated fraud attacks. A similar warning previously came from Binance co-founder Changpeng Zhao, who urged users to tighten wallet security after an investor lost Rp800 billion (US$50 million) in an address poisoning scheme in December 2025.

This rule serves as a reminder that in an industry moving as fast as crypto, the costliest vulnerabilities often stem from the simplest things: a six-digit code sent via text message. If Hong Kong successfully demonstrates that tighter security standards can operate without compromising user convenience, other regulators may well follow suit.

Sourced from crypto.news.


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share