S&P 5007,428.78▲0.2% Nasdaq24,876.91▼0.2% Dow52,747.32▲1.0% Russell 2K2,953.80▲0.2% 10-Yr4.60%−4bp VIX18.21−0.46 WTI$81.23▼1.7% Gold$4,023.80▼1.2% EUR/USD1.139▼0.1% BTC$63,409▼0.7% Nikkei64,931▲0.5%
At close · Tue, Jul 28, 2026
Daily Market Updates.

Crypto

HomeCryptoRegulationHong Kong orders crypto platforms to use phishing-resi…

Hong Kong orders crypto platforms to use phishing-resistant logins

The Hong Kong Securities and Futures Commission requires platforms to adopt phishing-resistant authentication within 12 months and bans SMS, email, and app one-time password logins.

Hong Kong’s securities regulator has ordered crypto platforms and online brokers to upgrade account protection with phishing-resistant login requirements, under new rules from the Hong Kong Securities and Futures Commission, according to Cointelegraph.

The SFC’s standards require stronger phishing-resistant authentication methods and device binding for virtual asset trading platforms and online brokers, and they prohibit the use of one-time passwords via SMS, email, or app-based logins. Cointelegraph also reports that platforms must implement the changes within the next 12 months.

The regulator pointed to alternatives such as passkeys, registered devices using cryptographic verification, and hardware security keys as examples of phishing-resistant solutions.

Cointelegraph links the move to rising phishing attacks and social engineering scams across the global crypto industry in early 2026, citing industry losses of $306 million from phishing and social engineering out of $482 million in total losses in the first quarter of 2026. The story also notes that a Hong Kong executive highlighted the need for comprehensive measures spanning prevention, detection, response, and education.

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.