Thursday, August 27, 2026|20°C Partly Cloudy
Next edition scheduled
Your Personal Daily Intelligence
Edition 2026-07-11

CRYPTO

Hong Kong Gives Crypto Platforms One Year to Replace One‑Time Passwords with Stronger Authentication

Hong Kong's Securities and Futures Commission has set a July 8, 2027 deadline for licensed virtual asset service providers and internet brokers to replace one‑time passwords wit...

By cryptoslate · 48d ago · Source: cryptoslate

Full article

Hong Kong's Securities and Futures Commission has set a July 8, 2027 deadline for licensed virtual asset service providers and internet brokers to replace one‑time passwords with phishing‑resistant authentication for client logins and new device registration, according to a July 9 circular.

The regulator said one‑time passwords do not meet the required security standard for those processes and should not be used when clients log in or bind a new device. The rule applies only to those two situations; existing client sessions remain unaffected. Large internet brokers are expected to implement the new methods immediately, while the broader group of licensed platforms has a 12‑month implementation period.

Firms must review client notifications, account monitoring, surveillance and incident‑response procedures, and they are required to suspend or restrict accounts when signs of fraud are detected. The SFC also requires firms to monitor irregular logins, new‑device activity, trading patterns that deviate from a client’s history, and large‑value withdrawals. Clients should receive prompt notifications of successful logins and of high‑risk changes such as new device registrations or passkey creation or revocation. Passkeys use public‑key cryptography, requiring a private key stored on the user’s device or a passkey manager, and may be combined with additional verification factors such as biometrics or account passwords. Device binding may also incorporate robust verification mechanisms.

The SFC said firms can be held accountable for client losses if inadequate measures fail to prevent, detect or stop large‑scale unauthorized transactions after a hacking incident. Senior management overseeing operations and information technology is ultimately responsible for the rollout, with the deadline serving as the final test of compliance.

Source transparency

Publisher
cryptoslate
Reliability
high
Published
7/11/2026, 10:00:36 AM
Retrieved
7/11/2026, 10:00:36 AM
Relevance
80%
Confidence
85%
Read original at cryptoslate

Botwin's Morning Wire publishes the full source article for reading convenience. Please visit the publisher for the original presentation and any updates.