Hong Kong just told every licensed crypto trading platform to drop SMS authentication within 12 months, and the reason behind that decision is anything but theoretical. Back in 2025, scammers ran large-scale SMS phishing campaigns impersonating brokers, and the damage was serious enough that the SFC ended up freezing about $11.7 million across four compromised accounts.
One regulatory shift has a way of reaching further than the jurisdiction where it lands. The SFC's move on authentication forces every platform to rethink its login flow, but that same logic applies further up the stack — in product design, privacy features, and even how support teams explain transaction delays. This digest follows that thread from the regulatory layer down to the user experience.
The SMS ban isn't just a compliance rule that sits in a drawer somewhere. It changes how founders think about jurisdiction from day one. Yana Mar, CBDO at ChangeNOW, made this point in her recent column on crypto hub decisions: getting the licence is only the beginning. What follows is a longer, messier process involving tax residency, corporate substance, and global minimum tax rules that keep shifting. The headline rates are one thing; the compliance burden that lands on your desk after you've set up shop is an entirely different story.
Now shift your focus from regulation to what happens inside product teams, because security looks completely different when you're the one building the infrastructure rather than just complying with a rule. Nikolas B., Technical Lead at ChangeNOW, breaks the company's approach into three interlocking layers — people, systems, and processes — and he's quick to point out that no amount of technical sophistication can fully protect you if the human element is neglected.
His team runs a "two-key" system where no single employee can act alone; that control evolved gradually from a small trusted circle to formal systems as the company grew. Rules that seemed like minor inconveniences at first — strict login policies, second-person sign-offs for large transfers — now separate near-misses from actual losses.
Once a business hypothesis is proven, building out real security systems and processes has to become an inseparable part of how the product develops.
— Nikolas B. , Technical Lead at ChangeNOW
What users see on the blockchain is the other side of security. This kind of data exposure has real consequences for specific user groups. Corporate businesses paying suppliers on-chain create a public record of who gets paid and how often. Journalists and human rights workers face direct exposure risks that can affect their safety. Everyday users often don't realize their spending habits are becoming part of a permanent public ledger.
When they realize what has been happening, that trust they had for your product is at stake.
Private transfers solve this by breaking the direct on-chain link between sender and recipient, and they do it without altering how public blockchains function. The technical details are covered in a recent piece on user anonymity in crypto products, but the core idea is simple: you can have privacy without sacrificing transparency.
Go further down the stack and you'll find privacy being built directly into the protocol architecture itself. Firo's Lelantus Spark uses a burn-and-redeem model that anonymizes coins during the burn process and redeems them as completely fresh coins with no transaction history attached. Sender, receiver, and amount stay hidden, and the protocol doesn't require a trusted setup at all. Firo's contributions have found their way into other privacy protocols. The project hasn't stood still either — development continues.
Ask a support specialist at ChangeNOW about the "Confirming" status, and they'll tell you it's a simplification. Behind the scenes, the team is monitoring manual reviews, payout signals, and failure flags as they happen.
Confirming means we've received the deposit, and the transaction is collecting the confirmations it needs. Think of it like this: during Confirming, the blockchain is essentially putting a stamp on the transaction.
— Support specialist at ChangeNOW
Different blockchain networks require different numbers of confirmations. Ethereum Classic needs about a dozen, while Avalanche can settle in just one or two. That variation is exactly why some swaps confirm in minutes while others take a bit longer. If a transaction's status doesn't update within 10 or 15 minutes, someone on the technical team is already looking into it.
Independent voices are starting to pick up on this shift, and one recent review of ChangeNOW's platform highlighted security, speed, and transparency as core pillars of the user experience, specifically calling out the platform's privacy features like Private Sends. More and more, trust is what distinguishes the platforms that had security baked in from the ones that scrambled to add it later.
A platform's success depends on getting each layer right — and getting any one wrong can ripple through the rest. The ones that last treat trust as a system, not a feature. It's not built in announcements; it's built in the details that add up over time.
That's the stack. Get the layers right, and trust takes care of itself.