Tuesday, August 11, 2026 Latest news About 📈 Live coin prices →
Regulation

Hong Kong Just Banned Text and Email Logins for Crypto — Should Your Exchange Copy It?

Hong Kong's regulator is killing SMS and email one-time passwords for crypto trading after a wave of phishing attacks. Here's what it means for your login.

Elena Novak3 min read
Hong Kong Just Banned Text and Email Logins for Crypto — Should Your Exchange Copy It?

If you trade crypto through a platform licensed in Hong Kong, the way you log in is about to change. The city’s securities regulator, the Securities and Futures Commission (SFC), has ordered internet brokers and crypto trading platforms to stop letting customers sign in using one-time passwords sent by SMS, email, or basic authenticator apps, according to BeInCrypto. The move comes after a surge in phishing-related cybersecurity incidents across the region.

In plain terms: the codes you’re used to getting texted to your phone before you can access your exchange account are being phased out. The SFC issued a formal circular telling platforms they must switch client logins away from these methods, citing scammers who have been intercepting or tricking users out of these simple codes to break into accounts.

Why your “secure” login might not be so secure

Most of us think of a text-message code as solid protection — it’s the classic “two-factor authentication” we’ve been told to turn on for years. But regulators and security researchers have increasingly flagged SMS and email OTPs as weak links. Phishing pages can trick people into typing their code into a fake site, and SIM-swap fraud lets criminals hijack a phone number entirely to receive those codes themselves.

Hong Kong’s regulator is essentially saying that the login method millions of crypto users rely on every day isn’t good enough anymore, especially as phishing scams targeting crypto accounts have been rising in the region, per BeInCrypto’s reporting.

What this means if you don’t even live in Hong Kong

You don’t need a Hong Kong address for this to matter. Regulators around the world tend to watch each other closely, and Hong Kong has positioned itself as one of the more active jurisdictions building formal rules for crypto exchanges. When a regulator here tightens security requirements, it often becomes a template that other authorities reference later.

For everyday holders, the practical takeaway is simple, even without waiting for your own regulator to act: if your exchange offers a stronger login option — like a hardware security key, a passkey, or an authenticator app that generates codes without relying on your phone number or inbox — it’s worth switching now rather than waiting to be told to.

The bigger picture for crypto trust

Crypto has spent years fighting a reputation problem tied to hacks and stolen funds, and a huge share of those losses trace back not to broken blockchains but to compromised logins and phishing scams against ordinary users. A rule like this — even if it only applies in Hong Kong for now — is a reminder that account security, not just exchange solvency, is a core part of keeping your holdings safe.

Whether other regulators follow Hong Kong’s lead remains to be seen. But for anyone holding crypto on a centralized platform, this is a good nudge to check what login protections you’re actually using — and to upgrade them before a scammer forces the issue for you.

More Regulation