Hong Kong · China · Ethereum · Cointelegraph
The measures raise Hong Kong's cybersecurity standards as the global crypto industry saw an increase in phishing attacks
Compiled by KHAO Editorial — aggregated from 2 sources. See llms.txt for citation guidance.
◎ Multiple-sources
Counterfeiting and fraud attacks accounted for 57% of the security incidents reported to the Hong Kong Cyber Security Accident Coordination Center in 2025, according to announcement.
Key facts
- On Wednesday, a crypto investor lost nearly $1 million after signing a malicious phishing token approval transaction on Ethereum, the latest reported incident of phishing scam-related crypto industry
- On May 25, onchain analyst “b-block” warned that scammers used Google to deploy malicious phishing ads impersonating decentralized exchange Uniswap, reportedly stealing more than $400,000 from victims
- Leading crypto industry figures, including Binance co-founder Changpeng Zhao, have previously called for better wallet security measures to avoid phishing scams, after an investor lost $50 million
- In May 2024, one victim lost $71 million to an address poisoning scam in an unusual case that ended with the attacker returning the full amount two weeks later
Summary
Hong Kong’s regulator has ordered crypto platforms and online brokers to meet newly issued phishing-resistant login requirements within the next 12 months. The Hong Kong Securities and Futures Commission (SFC) on Thursday issued new requirements for phishing-resistant authentication methods for virtual asset trading platforms (VATPs) and online brokers in the special administrative region. The new standards require stronger phishing-resistant authentication methods and device binding while prohibiting the use of one-time passwords through SMS, email or app-based logins. The requirements outlined stronger alternatives such as passkeys, registered devices with cryptographic verification and hardware security keys, which the SFC described as phishing-resistant solutions. The measures raise Hong Kong's cybersecurity standards as the global crypto industry saw an increase in phishing attacks and social engineering scams in the first quarter of 2026.