Closed-door seminar in Hong Kong centered on security and compliance
On Sept. 16, BlockSec held its Harbouring Trust closed-door seminar in Hong Kong, with support from East Asia, Jumio and TiDB. The event focused on security buildout, compliance boundaries and business execution under the trend of crypto institutionalization, drawing about 50 decision-makers and business heads from exchanges, wallets, payment and stablecoin firms, licensed traditional financial institutions, public blockchain teams and professional service providers.

Opening remarks: trust in Web3 requires joint work
Michele Fung, a board member of the Fintech Association of Hong Kong and APAC lead at Unlimit, delivered the opening remarks. She said security and compliance are no longer static exercises limited to code audits and management procedures. In her description, they have become a dynamic system embedded in law, technology and accountability, forming part of the foundation for the next stage of the crypto economy.
Fung also said the association has been working to connect the industry, promote policy dialogue and support technological innovation, adding that it was encouraging to see security-focused firms such as BlockSec taking part in the buildout of Hong Kong’s crypto sector. She closed with the line, “A single effort is hard to sustain, while collective action moves faster,” saying that a secure, trusted and sustainable Web3 environment cannot be built by any one institution alone and requires close coordination among regulators, security service providers, fintech companies, industry experts and developers.
Keynote: as crypto becomes institutionalized, the nature of risk changes
BlockSec co-founder and Chinese University of Hong Kong associate professor Zhou Yajin delivered a keynote titled “Security and Compliance in Crypto Institutionalization.” He broke institutionalization into four layers: blockchain has become de facto infrastructure for rapid settlement across financial institutions; trading volume in new assets such as stablecoins and tokenized equities is growing quickly; market participation is expanding from crypto-native players to traditional financial institutions; and the sector is moving away from unchecked expansion as regulatory rules become clearer.

Zhou said the risk profile is changing along with that shift. Attackers are using AI to raise attack efficiency, while illicit networks have developed crime-as-a-service systems covering customer acquisition, chat operations, website building and money laundering. He also said stablecoins are being used as money-laundering infrastructure, and that criminals commonly rely on two- to four-hop transfers to evade controls, making traditional anti-money-laundering systems that screen only one hop relatively easy to bypass.
On-site interaction and pre-event survey
Guests also took part in a compliance quiz during the event and joined a group photo session.
Before the seminar, organizers sent each invited guest a questionnaire of no more than 10 questions and received 41 responses. The results showed that fund security and continuous monitoring, stablecoins and cross-border payment corridors, and regulatory policy and licensing ranked almost level at the top of attendee interest. The survey also found that 78% of respondents hoped to meet payment and stablecoin institutions at the event.

Organizers collected 23 questions that guests most wanted to raise. Those questions were grouped by theme and presented anonymously, forming the full set of material used in the day’s Hot Seat session.
Panel one: compliance boundaries, operating practice and growth
The first panel was conducted in Cantonese with live subtitle translation. It was moderated by BlockSec head of compliance strategy Yanyee He and featured Corey Tang, head of compliance at PingPong; Winnie Cheung, consulting director at PwC Hong Kong; and Kelvin Lo, Web3.0 payment business lead at LianLian LDC.
On where to draw the line on compliance compromise, panelists outlined a three-dimensional test: hard regulatory requirements in the relevant jurisdiction, the company’s own risk appetite, and whether the return from a given project can cover compliance costs. If any one of those conditions is not met, the business should not proceed.

On timing, the shared view in the room was that compliance needs to enter early, at the stage of project initiation, market expansion and client onboarding. If teams wait until a business line is already live and then try to add process controls, the burden falls across the back-end organization.
Panelists also pushed back on the idea that compliance is merely a cost center. In the discussion, compliance was described as something that can turn into a marketing advantage. Trust itself can bring business, create barriers to entry and become a point of differentiation when working with traditional financial institutions.
They also said Hong Kong still faces a clear talent shortage in Web3 compliance. General job seekers often lack familiarity with Securities and Futures Commission, or SFC, rules, while many crypto-native practitioners lack compliance and risk-control awareness.

Panel two: risk defenses and industry coordination
The second panel was moderated by BlockSec COO Ruby Xu and featured Bitget Wallet CEO Karry, Bybit head of on-chain risk control Alan Xin, EX.IO GROUP deputy CEO Toya Zhang and VDX chief strategy officer Paolo Chen.
During the session, a guest who had firsthand experience with the $1.5 billion theft case reconstructed the sequence of events. According to the account shared on site, North Korean hackers compromised the computer and cloud environment of a developer at a multisig service provider, then altered the transaction interface to carry out the theft. In that review, the incident was described as a supply-chain security problem rather than a breach of Bybit’s own systems. After the attack, the platform did not suspend withdrawals. It disclosed related information to the community through livestreams, regained user and industry confidence quickly and restored business operations at speed.
The discussion also said the case has now been filed in the United States and that fund recovery is progressing in an orderly way. The incident has pushed the industry to pay closer attention to the “what you see is what you sign” issue in multisig setups and to risk controls around external supply chains.

On the balance between product iteration and security, speakers challenged the view that older systems are safer simply because they change less. The point made in the room was the opposite: outdated systems can be easier for AI tools to scan for vulnerabilities. Practical measures discussed included keeping security teams independent and giving them authority to halt any product release, involving them early in product design reviews, and setting up internal red-team exercises supported by AI.
On implementation paths, the panel said wallet payment models can assign on-chain security and KYT controls to service providers, while fiat-related steps can be handled with local licensed institutions responsible for KYC. In RWA, the discussion said the market is extending from tokenized U.S. equities toward private equity. In May this year, Hong Kong-licensed virtual asset trading platform EX.IO announced that it had completed the listing and distribution of Asia’s first compliant tokenized depositary receipt product linked to SpaceX equity.
As for how traditional financial institutions can enter the sector, the view shared on site was that their core objective is to retain existing clients. They can fill gaps in systems, compliance and liquidity through third-party service providers rather than building a full end-to-end stack on their own.

Closing remarks
BlockSec thanked East Asia, Jumio and TiDB for supporting the event and also thanked attendees. The company said it will continue to deepen its work in security auditing, attack detection, fund tracing and compliance capabilities, alongside regulators, financial institutions and industry partners involved in the institutionalization of the crypto economy.
For background on the event and how the agenda was designed, the organizer referred readers to its earlier preview, “Harbouring Trust Hong Kong: Closed-door exchange on Sept. 16.”

