Amid rampant online fraud, the Hong Kong Securities and Futures Commission (SFC) issued Circular 26EC35 on 9 July 2026. It requires internet brokers and licensed virtual asset trading platforms to stop using one-time passwords (OTP) for client login and device binding authentication. Instead, they must adopt phishing-resistant authentication methods. The primary compliance path centres on passkeys, with hardware security keys such as YubiKey being one of the main solutions explicitly referenced by the authorities.
How Serious Is the Fraud Threat?
The circular was issued against a backdrop of increasingly severe phishing attacks involving the theft of client login credentials. In 2025, phishing attacks accounted for 57% of security incidents reported to the Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT). That same year, Hong Kong recorded 31,571 technology crimes with total losses of HK$6.32 billion — a 23.2% year-on-year increase — of which online fraud cases made up over 87% of all technology crimes. Once an investor’s account is compromised, losses often involve the entire position. Regulators have therefore decided to start with authentication, the “first line of defence.”
Requirements of SFC Circular 26EC35
The circular targets two high-risk moments: client login to internet trading accounts and device binding (when a client links a new phone or computer to the account). OTP must be discontinued for both and replaced with phishing-resistant authentication methods. The SFC specifically names compliant options including passkeys and cryptographically bound devices.
Regarding the timeline, large internet brokers must implement the changes immediately. Other brokers and virtual asset trading platforms must implement them as soon as possible, and no later than 12 months after the circular’s issuance (i.e., by 8 July 2027). The SFC also requires the industry to strengthen monitoring and surveillance to detect suspicious logins, transactions, and withdrawals; promptly notify clients of significant account events; and respond appropriately to hacking incidents. Senior management will be held accountable if client losses result from control failures.
Executive Director of the SFC’s Intermediaries Division, Mr. Raymond Yeh, stated: “Protecting client accounts from increasingly sophisticated phishing attacks requires a holistic approach combining prevention, detection, response, and education. Licensed institutions should strengthen the first line of defence with robust authentication solutions.”
Why OTP Is No Longer Reliable
OTP (one-time verification codes sent via SMS or email) appears secure but is essentially still a “shared secret” — information known to and verifiable by both the service provider and the user. Any shared secret can be stolen, intercepted, or obtained through social engineering. Phishing websites can trick users into entering the verification code, which fraudsters then immediately forward to the real website to complete the login (a man-in-the-middle attack). SIM swapping can also intercept SMS codes. In recent years, AI tools have significantly lowered the barrier to phishing attacks, enabling non-technical fraudsters to create highly realistic fake login pages within minutes.
Passkey: The Mainstream Phishing-Resistant Authentication Solution
Passkeys are digital authentication credentials based on the FIDO2/WebAuthn standards and are natively supported by major platforms including Apple, Google, and Microsoft. At their core is public-key cryptography: during registration, the authenticator (device or hardware key) generates a unique public-private key pair for each service — the private key remains locked in the secure chip, while the public key is given to the service provider. During login, the service provider issues a random challenge; the authenticator signs it with the private key, and the user only needs to complete verification via Face ID, fingerprint, PIN, or by touching the key.
Because the signature is cryptographically bound to the service provider’s domain, even if a user mistakenly enters a fake website, the authenticator will only sign for the genuine domain. Fake websites can never obtain a valid signature, rendering phishing attacks fundamentally ineffective. No secret ever leaves the device, so fraudsters have nothing to steal or replay.
Hardware Security Keys: One of the Major Solutions
Passkeys can be stored on different carriers: built-in authenticators on phones (Face ID/fingerprint), cloud-synced password managers, and hardware security keys. Hardware keys (such as YubiKey) are physical devices independent of phones and computers. The private key is isolated in a hardware security chip, protected from malware on the host device and not subject to cloud synchronisation, thus providing the highest level of security.
YubiKey is the most widely known hardware security key on the market. It resembles a small USB device (some models support NFC) and supports multiple protocols including FIDO2/WebAuthn, FIDO U2F, and PIV smart card. The SFC circular does not specify any brand, but Interactive Brokers’ (IB) official tutorial page explicitly mentions “dedicated physical security keys (FIDO2 certified, such as YubiKey, Google Titan, Token2, etc.).” As a result, YubiKey has become the most frequently referenced hardware solution in Hong Kong brokers’ compliance deployments.
Adoption Status in the Hong Kong Industry
Following the circular, major brokers have acted swiftly. Multiple platforms have announced support for passkeys or hardware keys:
- Interactive Brokers (IB): In response to SFC requirements, it is rolling out passkey authentication for all client accounts, with a deadline of 31 August 2026. Accounts that have not activated passkeys will be restricted to closing positions and withdrawals only — no new positions or new withdrawal instructions can be established. IB’s official tutorial states that users can activate and store passkeys on cloud-supporting mobile devices or dedicated physical security keys (FIDO2 certified, such as YubiKey, Google Titan, Token2, etc.). (Link)
- Futu Securities (Futu HK): Has launched passkey functionality supporting Face ID/fingerprint/screen lock login, as well as binding of USB or NFC physical security keys (which users must purchase themselves). It also works with third-party password managers such as Google Password Manager and 1Password. (Link)
- HashKey Exchange: Supports passkeys for two-factor authentication; they can be used for login, withdrawals, and other sensitive operations. Official documentation explicitly states they can be created on FIDO2-compatible USB security keys (also known as U2F keys).
- OSL: Its official 2FA guide provides two methods — Authenticator App (recommended) and YubiKey hardware security key (Settings > Security > YubiKey > Add). It is one of the earliest Hong Kong licensed platforms to support direct YubiKey binding. However, OSL currently uses YubiKey OTP mode and does not yet offer a passkey option. (Link)
How to Get Started
For investors, the simplest starting point is to use the built-in passkey on a phone (Face ID/fingerprint), then add a hardware key as a higher-security option if needed. In the “Security Settings” of the broker or virtual asset platform, select the option to create a passkey and follow the prompts to complete registration with biometrics or a hardware key. If using a YubiKey, it is recommended to register two keys (one primary and one backup) and store the backup key securely to avoid being locked out if the primary is lost.
Hong Kong investors and users can purchase brand-new YubiKeys online via the Carousell website of NetMon, the authorised value-added distributor of Yubico products in Hong Kong.
Limitations and Reminders
It should be noted that FIDO2 defends against credential theft — phishing, credential stuffing, man-in-the-middle attacks during authentication, and password database breaches. It cannot prevent malware from being installed on the user’s own device, nor can it stop session hijacking after login. These require endpoint protection and session management. Additionally, if an account retains weaker backup authentication methods (such as password reset via phone), attackers may still exploit those pathways. Therefore, comprehensively removing weak authentication methods is as important as introducing strong authentication.
Conclusion
From OTP to passkeys, the SFC’s circular marks a new stage in financial authentication: phishing resistance is no longer optional but a compliance requirement. Passkeys have become the mainstream solution, while hardware security keys such as YubiKey provide physical-level protection for investors seeking the highest security — login no longer relies on “remembering” and “receiving,” but on “possessing.” As the July 2027 compliance deadline approaches, more brokers and virtual asset platforms can be expected to join the passkey ranks.