On 9 July 2026, the SFC gave Hong Kong’s licensed virtual asset trading platforms and internet brokers twelve months to take SMS one-time passwords off their login screens. The deadline is 8 July 2027, and large internet brokers are told to move now rather than in a year. Of everything the SFC has published this year, this circular is likely to require technical, not just policy, resourcing.

The circular is reference 26EC35, and it does two things: it sets expectations for how clients log in and bind devices, and it sets expectations for how firms watch accounts once clients are inside. Most of the coverage has focused on the first half. The second half is where we think the enforcement risk actually sits.

What the circular requires

Four workstreams, in the SFC’s own order.

Prevention comes first. Firms should use “strong and phishing-resistant authentication solutions for client login and device binding”. The operative sentence on SMS codes is worth quoting exactly, because it is narrower than the headlines suggest: “The SFC does not consider OTP to be a phishing-resistant authentication solution, and internet brokers and VASPs should not use it for the processes mentioned under paragraph 5 above.” Paragraph 5 covers two processes only, login and device registration. This is not a blanket ban on one-time passwords. The circular itself still contemplates SMS as a notification channel.

Detection comes second, and it is the part firms are underestimating. The SFC wants monitoring against predefined thresholds set by reference to each client’s profile, trading history, device usage and login patterns. It names the red flags it expects you to catch: trades inconsistent with previous patterns, orders placed at unusual hours, transactions resulting in significant losses within a short period, sudden large volumes in illiquid or small-cap stocks, and transactions conducted shortly after a password reset, a change of contact details or the binding of a new device. On the login side, it wants device ID logs reviewed for binding requests from odd locations, multiple accounts bound to one device, logins from several locations in a short window, and unusually long login sessions.

Third, incident response: contain, protect client assets, notify affected clients, and report to the SFC immediately. Fourth, client education on phishing.

One framing point matters for how firms brief their boards. This is an expectations circular, not subsidiary legislation. The word “must” appears exactly once in the whole document, at paragraph 22, and it is about suspending accounts when you spot something suspicious during the transition. Everything else is expressed as “should” or “expects”. That does not make it optional, for reasons we come to below, but it does change how you characterise it internally.

Who is in scope

The circular defines two populations in its footnotes.

“Internet brokers” means licensed corporations engaged in internet trading and licensed for Type 1, Type 2, Type 3, and/or Type 9 regulated activity, the last of those only to the extent they distribute funds under management through their own internet-based trading facilities. That definition tracks the SFC’s existing Cybersecurity Guidelines.

“SFC-licensed VASPs” currently means licensed virtual asset trading platform operators and nothing else, because Schedule 3B to the AMLO contains a single VA service: operating a VA exchange. As at the SFC’s list of 29 May 2026, there are 13 licensed platforms.

The circular is addressed to licensed corporations, which on its face leaves registered institutions (banks) outside it. However, the underlying Cybersecurity Guidelines reach persons licensed by or registered with the SFC. Nor is it resolved on the face of the text whether “SFC-licensed VASPs” captures the deemed-to-be-licensed applicants under Schedule 3G. If either question decides your position, seek advice rather than assume an answer.

The 12-month clock, and what is due before it

Only the authentication work gets the twelve months. Paragraph 21 expects firms to review notification, surveillance and incident-response arrangements and make the necessary enhancements immediately, with the SFC saying it will take “a pragmatic approach” on timing. Client education is “as soon as practicable”. Robust authentication is the item with the hard date of 8 July 2027, and there the circular adds that “large internet brokers are expected to implement these solutions immediately”.

Two points arise from this provision. The circular never defines a large internet broker, so if you are anywhere near the line, document the assessment you made and why. And on the face of the text, the immediate expectation is written for brokers, not for platforms. We would not build a compliance plan on that distinction, but it is a fair question to raise with your case officer.

During the transition, firms are expected to test before deployment, roll out to clients as soon as practicable, and communicate the change with proper support. If you think you will miss the date, paragraph 23 tells you to notify your case officer immediately. In our experience, firms that self-report early are more likely to be supervised, whereas firms that remain silent and miss the deadline are more likely to be investigated.

What “phishing-resistant” actually means

The reason SMS codes fail is not that the message can be read. It is that a phishing site can relay the code in real time. The 2025 attacks the SFC describes worked exactly this way: fraudsters sent SMS messages impersonating brokers, referencing purported information requests from regulators, and harvested credentials including the OTP on a fake site while running a man-in-the-middle attack against the real login. The code was valid. The problem was that nothing tied it to the genuine website.

Passkeys solve that with public-key cryptography. A private key lives on the client’s device, hardware security key or passkey manager, and it is registered to your domain specifically, so it simply will not produce a valid response to a lookalike site. The client unlocks it with biometrics or a PIN. There is nothing shared and nothing to phish. Device binding is the alternative route, where the device is linked to the account using robust verification. The Appendix is blunt that binding conducted with “weak verification methods, such as user login credentials and OTP-based authentication,” leaves firms exposed to unauthorised device registration, precisely the flow phishing defeats.

The single hardest requirement in the document is in the Appendix, and it is a procurement gate: whether you buy a passkey solution or build one, it “should be subject to appropriate certification, ie, FIDO certification”. Firms should request evidence of certification directly, rather than relying on marketing materials.

The practical checklist

Identify the owners. The circular names the Manager-in-Charge of Overall Management and Oversight and the Manager-in-Charge of Information Technology specifically, and both should be included in the board paper.

Scope every channel. Desktop application, mobile application and trading website each need an answer, and the web is the hardest case.

Design the enrolment journey around four client scenarios, because the Appendix does:

  1. New clients: create a passkey during onboarding after identity verification.
  2. Existing clients with a bound device: prompted to create a passkey after their next login.
  3. Existing clients without a bound device, before the deadline: may still log in with ID, password and SMS OTP, then be prompted both to create a passkey and to bind the device.
  4. Existing clients without a bound device, after 8 July 2027: must use one of the Appendix’s robust verification methods to create a passkey, an existing passkey via cross-device authentication, a live selfie checked against your own records, an identity document scan with a selfie match, or a visit to your office in person.

Use the carve-out. Clients whose devices are already bound do not have to rebind. For most active books, that turns a migration into an enrolment prompt.

Front-load it anyway. Every client you fail to migrate before July 2027 becomes a client who can only enrol through document verification or an office visit. If you have no retail premises, work out your answer to that now.

Then the housekeeping: cap enrolment at three passkeys and three devices with an assessment gate for exceptions; limit idle session timeout, the circular’s example is 30 minutes, and do not let clients switch it off; notify clients on successful login, new-device logins, device binding and passkey creation or revocation, across more than one channel; keep device ID logs and review them; control synchronisation risk, since the Appendix separately requires firms to mitigate the risk that software-based passkeys synced across a client’s device ecosystem (iCloud Keychain, Google Password Manager and similar) could be abused to extend unauthorised access; build the loss and recovery path before you need it.

The sentence about client losses

This is the paragraph compliance teams keep asking us about. The relevant paragraph is reproduced below. If a firm “fails to implement adequate measures to prevent, detect and stop large-scale unauthorised transactions conducted through client accounts following hacking incidents, the SFC will hold the relevant firm accountable for the losses suffered by its clients.”

Read it carefully. The words compensate, reimburse, indemnify and liable appear nowhere in the circular. This is a statement of supervisory posture, not a new compensation right, and it creates no private cause of action. It is also conditional and narrow: the trigger is large-scale unauthorised transactions following a hack, not any loss on any account.

While the SFC does not need a compensation rule, it has section 194 of the SFO (suspension, revocation, public reprimand, and a fine of up to HK$10 million or three times the profit gained or loss avoided), section 53ZSP of the AMLO for licensed platforms (which at section 53ZSP(3)(b) adds a power to order remedial action by a date the SFC fixes), the power to amend or impose licensing conditions at any time under section 116(6) of the SFO and section 53ZRK(4) of the AMLO, and restriction notices under sections 204 and 205. In November 2024 it used those last powers to freeze up to HK$91 million across four brokers after unauthorised trades through hacked accounts. The toolkit is not theoretical.

What your clients will notice

Codes disappear from the login screen, replaced by Face ID, a fingerprint, a PIN or a physical key. Registering a new phone becomes harder on purpose. Notifications increase. Sessions time out and cannot be disabled. Accounts get suspended faster when something looks wrong, because during the transition that is the one thing the circular says firms must do.

What does not change: clients still carry responsibility for not handing over credentials, and the circular gives them no new legal remedy. If a client loses money, the answer still runs through the client agreement, the general law, and the Financial Dispute Resolution Centre or the courts.

How TITUS helps

We work with licensed platforms and brokers on exactly this: reading the circular against your actual licence and business, deciding the grey-area questions (are you a “large internet broker”, are you an in-scope VASP), drafting the board paper and the implementation plan, reviewing vendor contracts and the certification position, updating client agreements and terms for the new authentication regime, and handling the conversation with your case officer if the timeline is tight.

If your implementation plan is not yet written, that is the piece to start with. It is also the first document the SFC will ask for.

Book a compliance review with our virtual assets and fintech team. We will map the circular against your current authentication stack and give you a dated plan you can put in front of your board. Book a consultation or contact us to get started.

Frequently asked questions

Does the SFC circular ban SMS one-time passwords entirely?

No. The restriction covers client login and device binding. OTPs can still be used elsewhere, and the circular itself contemplates SMS as a notification channel.

When is the deadline?

8 July 2027 for robust authentication, being twelve months from the circular’s date. Surveillance, incident response and client education are expected immediately or as soon as practicable, without the twelve-month runway.

Does the circular apply to banks?

It is addressed to licensed corporations and SFC-licensed VASPs. Registered institutions are regulated for e-banking security by the HKMA under a separate and differently shaped programme. If your group has both a bank and a licensed corporation, take advice rather than assuming one answer covers both.

Do existing clients have to re-register their devices?

No. The circular expressly says firms are not required to ask existing clients to rebind devices that are already bound.

If a client is hacked, does the platform have to repay them?

Not automatically. The circular says the SFC will hold a firm accountable for client losses where it failed to prevent, detect and stop large-scale unauthorised transactions after a hack. That is regulatory accountability. Whether a particular client recovers a particular loss is a separate question that turns on the client agreement and the general law.


Disclaimer: This article reflects our understanding of the position under Hong Kong law and applicable regulatory guidance as at 28 July 2026. The regulatory framework for virtual assets and licensed intermediaries continues to develop. It is subject to change, and the application of an SFC circular to a particular licensed business depends on its licence, its systems and its client base. Nothing in this article is, or should be taken as, legal advice or a recommendation on any specific matter or product.

TITUS Solicitors is a firm of solicitors qualified to practise in the Hong Kong Special Administrative Region of the People’s Republic of China. We do not solicit business in any jurisdiction in which we are not authorised to practise. This article is provided for information purposes only and is not directed at, or intended for distribution to or use by, any person in a jurisdiction where to do so would be contrary to applicable law or regulation.