Hong Kong just banned SMS logins for crypto platforms
Hong Kong's SFC has ordered licensed crypto platforms and online brokers to kill SMS, email and app-based one-time passwords, and switch to phishing-resistant logins like passkeys and hardware keys. They have 12 months, big players have less time.
Phishing scams drained $306 million from crypto in Q1 alone. The SFC is also putting senior management on the hook for losses from weak controls.
SMS 2FA has been the industry's weak spot for years. Will other regulators follow?
Microsoft is removing SMS codes for signing into personal Microsoft accounts, including Xbox accounts.
Soon, you won’t be able to use SMS for login verification or account recovery. Microsoft says the change is for security reasons, as text-message codes are vulnerable to phishing, SIM swaps, and other attacks.
Switch to more secure sign-in methods now, such as:
>Passkeys
>The Microsoft Authenticator app
>A verified backup email address
Microsoft is phasing out SMS text codes for logging into and recovering personal Microsoft accounts.
This targets personal accounts used for services like Xbox, Windows, Outlook, OneDrive, and more. It does not currently apply to work or school accounts.
The company states that SMS-based authentication has become a leading source of fraud, mainly through SIM-swapping attacks and mobile network breaches
Instead of SMS codes, users should set up:
>Passkeys: These use your device’s built-in biometrics for one-tap sign-ins.
>Verified backup email
>Microsoft Authenticator app.
During sign-in, Microsoft will prompt users to “Sign in faster” and create a passkey.
Crypto logins are changing.
Hong Kong’s SFC gave licensed platforms 12 months to replace SMS, email and app OTP logins with passkeys, hardware keys or verified devices.
Here’s why phishing-resistant access is becoming the new baseline: