
Hong Kong's Securities and Futures Commission ordered virtual asset trading platforms and online brokers to introduce phishing-resistant login systems within 12 months.
The new rules ban one-time passwords sent through SMS, email and authentication apps, replacing them with stronger security methods.
“To protect customer accounts from increasingly complex and changing counterfeiting and fraud attacks, comprehensive measures must be implemented in conjunction with prevention, detection, response and education,” said China Securities Regulatory Commission executive director Dr Ye Zhiheng.
The regulator recommended passkeys, registered devices with cryptographic verification and hardware security keys as stronger alternatives.
The changes follow rising phishing attacks, which caused US$306 million of the crypto industry's US$482 million in total losses during the first quarter of 2026.
A crypto investor also lost nearly US$1 million this week after approving a malicious transaction on Ethereum (CRYPTO:ETH), highlighting the growing threat from phishing scams.
Industry figures, including Binance founder Changpeng Zhao, have previously called for stronger wallet security as phishing and social engineering attacks continue to target crypto users.
At the time of reporting, Ethereum price was $1,746.78.