The BOSC requires virtual asset trading platforms to adopt certification methods that prevent fraud
On 9 July, the Hong Kong Securities Commission issued a circular to the Internet Brokers and Virtual Asset Exchange Platform operators (VAT Platform) to adopt certification methods to effectively prevent fraud in connection with the entry and installation of customers. As part of its ongoing efforts to combat fraudulent attacks on Internet brokers and virtual asset trading platforms and the theft of accounts, the Commission now requires Internet brokers and virtual asset trading platforms to cease the use of one-off passwords for the entry and installation of customers because of the risks associated with this practice, and because there are now more robust alternative certification options, such as key and binding devices, that can provide more robust and anti-fraud authentication methods. The CVM requires that these certification methods, which can prevent fraud, be implemented as soon as practicable, only within a 12-month period from the date of issuance of the communication, while large Internet brokers should immediately adopt the certification method. In addition to sound preventive controls, Internet brokers and virtual asset trading platforms should implement effective detection and surveillance measures in order to detect suspicious entries, transactions and extractions, to inform customers of important account activities in a timely manner and to respond in a timely manner to hacking incidents. They should also provide regular alerts and alerts to customers on emerging fraud and other cyber-security risks。
