digital security

Jul 17, 2026

OTPs Are No Longer Enough, Passwordless Authentication Emerges as the Answer

OTPs can now be intercepted by malware. VIDA CEO explains how device-based biometric authentication is replacing OTPs to prevent account takeover.

TL;DR: Passwordless authentication verifies users without relying on passwords or OTPs as the primary authentication method. Instead, it uses biometrics, passkeys, and trusted devices to better protect mobile banking.

---

Digital fraud has evolved. What was once centered on password theft and basic phishing attacks has become far more sophisticated. Today, cybercriminals use malware to compromise devices, intercept OTPs, and take over user accounts.

During his keynote at the AIBP Conference and Exhibition Malaysia 2026, VIDA Founder and Group CEO Niki Luhur illustrated how modern fraud has become a coordinated, cross-border operation.

A typical attack begins when a victim downloads a malicious application or clicks on a phishing link. Once the device is compromised, malware can intercept OTPs, hijack authenticated mobile banking sessions, or initiate transactions without the user's knowledge.

The stolen funds are then transferred to mule accounts, routed through multiple intermediary accounts, and eventually converted into cryptocurrency, making them significantly more difficult to trace and recover.

For decades, passwords and OTPs have been the foundation of account authentication. However, OTP is now a more than 30-year-old authentication method, while fraud techniques continue to evolve rapidly, especially with the rise of AI-powered attacks.

Here are three assumptions about OTPs and authentication that financial institutions should reconsider.

Assumption #1: Only the Account Owner Can Access an OTP

An OTP is essentially a shared secret, a code delivered through SMS or messaging apps that can be accessed by anyone who gains control of the user's device or communication channel.

That assumption no longer holds once malware infects the device.

Malware can read OTP messages, intercept notifications, or exploit compromised devices. Even when users enter the correct OTP themselves, attackers can still perform an account takeover if they have already compromised the user's device or authenticated session.

Assumption #2: Authentication Ends After Login

One of the biggest misconceptions in digital security is that a successful login proves the user is the legitimate account owner.

In reality, login only verifies who authenticated at a single point in time. It does not prove who is controlling the account afterward.

Authenticated sessions can be hijacked, redirected, or handed over to mule accounts, where stolen accounts are used to move illicit funds. Traditional KYC verifies identity only during onboarding. After that, there is no guarantee the same individual remains in control of the account.

To address this risk, financial institutions need continuous authentication, an approach that continuously verifies user identity throughout an active session rather than only at login. High-risk activities, such as high-value transactions or account recovery, should trigger additional biometric verification to confirm the user's identity.

Assumption #3: Authentication Ends Once Biometrics Are Verified

Biometric authentication plays a critical role in verifying legitimate users. However, today's threats do not necessarily stop once authentication is complete.

 

In some attack scenarios, malware can manipulate transaction details after the user has successfully authenticated.

 

To mitigate this risk, financial institutions should implement the What You See Is What You Sign (WYSIWYS) principle, ensuring users cryptographically sign the exact transaction they intend to authorize. If any transaction detail changes after approval, the digital signature becomes invalid, allowing the transaction to be rejected.

 

Biometric authentication should also include liveness detection and be combined with trusted device authentication. Together, these technologies form the foundation of passwordless authentication.

What Is Passwordless Authentication for Mobile Banking?

Passwordless authentication verifies a user's identity without relying on passwords or OTPs as the primary authentication mechanism. Instead, it uses biometrics, passkeys, and trusted devices, credentials that are significantly harder to steal, forge, or misuse.

 

1. VIDA PhoneToken

VIDA PhoneToken uses Public Key Infrastructure (PKI) technology to bind a user's digital identity to their trusted device. Authentication remains secure without relying on OTPs, as only the registered device can be used to access the account.

2. VIDA FaceToken

VIDA FaceToken combines liveness detection, face matching, and device authentication to ensure that only a genuine user can access an account. Together, these capabilities eliminate reliance on OTPs for login and transaction authentication, reducing the risk of fraud and account takeover.

 

This approach significantly reduces the risk of phishing, credential theft, and account takeover because it no longer depends on secrets that can be stolen or shared.

 

More importantly, passwordless authentication provides a far more resilient authentication framework against modern fraud while delivering a seamless user experience.

 

"Security and user experience don't have to be a trade-off. With the right authentication architecture, financial institutions can achieve both," said Niki Luhur.

VIDA - Verified Identity for All. VIDA provides a trusted digital identity platform.

Latest Articles

OTPs Are No Longer Enough, Passwordless Authentication Emerges as the Answer
digital security

OTPs Are No Longer Enough, Passwordless Authentication Emerges as the Answer

OTPs can now be intercepted by malware. VIDA CEO explains how device-based biometric authentication is replacing OTPs to prevent account ta...

July 17, 2026

Fraud Detection Using AI: How It Fights and Fuels The Digital Crime
cybersecurity

Fraud Detection Using AI: How It Fights and Fuels The Digital Crime

Fraud detection using artificial intelligence combines liveness checks, deepfake shielding, and device intelligence to stop attacks. Learn ...

July 14, 2026

Fraud Detection System for Banks: Why Multi-Layered Defense Is Non-Negotiable
bank

Fraud Detection System for Banks: Why Multi-Layered Defense Is Non-Negotiable

A fraud detection system for banks must address deepfakes, synthetic IDs, and account takeover. Learn why multi-layered AI defense is the n...

July 13, 2026