Hong Kong Tightens Crypto Platform Authentication With Passkeys and Hardware Keys

Hong Kong Tightens Crypto Platform Authentication With Passkeys and Hardware Keys

N
News Editor 01
2026-07-23 04:00:14
Hong Kong’s SFC is prioritizing passkeys, cryptographically verified registered devices, and hardware security keys for crypto platforms as phishing and fraud losses keep climbing.
Hong Kong SFCcrypto platformsaccount securitypasskeysphishing

Hong Kong is raising the security threshold for crypto platform accounts. Under new guidance, the Securities and Futures Commission (SFC) is prioritizing passkeys, cryptographically verified registered devices, and hardware security keys as preferred authentication methods, with the focus squarely on phishing resistance and account fraud prevention.

The shift targets one of the weakest points in crypto security: accounts protected only by passwords or one-time codes. A passkey uses device-based cryptographic authentication instead of a traditional password. A hardware security key is a physical device that confirms identity and adds protection against fake websites and phishing links. In practical terms, the guidance points platforms toward device-level verification for sensitive actions such as login and withdrawals.

Authentication rules move beyond passwords and SMS-style checks

As Hong Kong’s main financial markets regulator, the SFC is using the new framework to push platforms toward stronger cyber defenses. The source says the regulator wants to reduce risks tied to accounts secured only by passwords or single-use codes. Ye Zhiheng, executive director of the Intermediaries Division at the China Securities Regulatory Commission, said effective protection against increasingly complex scams and fraud requires a mix of prevention, detection, response, and education.

That framing matters. It suggests account security is no longer treated as a narrow login issue, but as part of a broader control system that includes monitoring, response procedures, and user awareness. For investors, that could mean stricter account setup, more device binding, and tighter verification steps on key transactions. The process may become less convenient, but the policy direction is tied to actual losses already seen across the market.

Phishing and social engineering accounted for major crypto losses

The backdrop is a sharp rise in phishing-driven incidents. In the first quarter of 2026, phishing and social engineering attacks were responsible for $306 million out of the crypto sector’s $482 million in recorded losses worldwide, according to the source material. Data from the Hong Kong Cyber Security Incident Coordination Center also showed that scams and fraud made up 57% of all reported security incidents in 2025.

Recent cases show how these attacks work in practice. On Wednesday, an investor lost about $1 million on Ethereum after approving a malicious token operation. In just the first half of 2026, global scam losses linked to phishing reached $366 million. These incidents often do not require attackers to break core blockchain infrastructure. In many cases, victims are tricked into signing approvals, connecting wallets to fake interfaces, or interacting with malicious links.

High-value incidents have increased pressure on regulators

Earlier this month, a wallet owner reportedly lost $1.65 million after connecting to a fraudulent exchange and signing a malicious contract. Researcher Ryan Coleman said that action gave attackers unlimited access to the victim’s funds. At the end of May, on-chain analyst b-block said scammers were using Google ads to distribute phishing links designed to imitate Uniswap, leading to more than $400,000 in losses.

Calls for stronger wallet protection have been building for some time. In December 2025, Binance co-founder Changpeng Zhao and others urged stronger safeguards after an investor lost $50 million in an address poisoning scam. An earlier case in May 2024 saw a user lose $71 million to the same type of attack, though all assets were returned by the attacker two weeks later. Investigators believed the rapid recovery may have been connected to tracking the suspect’s probable IP address.

Taken together, the new authentication push reflects a direct response to how crypto users are actually being compromised. In Hong Kong, platform account protection is moving toward stricter, device-centered security controls.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.