Hong Kong just banned SMS logins for crypto platforms
Hong Kong's SFC has ordered licensed crypto platforms and online brokers to kill SMS, email and app-based one-time passwords, and switch to phishing-resistant logins like passkeys and hardware keys. They have 12 months, big players have less time.
Phishing scams drained $306 million from crypto in Q1 alone. The SFC is also putting senior management on the hook for losses from weak controls.
SMS 2FA has been the industry's weak spot for years. Will other regulators follow?