TL;DR: Passwordless authentication verifies users without relying on passwords or OTPs as the primary authentication method. Instead, it uses biometrics, passkeys, and trusted devices to better protect mobile banking.
---
Digital fraud has evolved. What was once centered on password theft and basic phishing attacks has become far more sophisticated. Today, cybercriminals use malware to compromise devices, intercept OTPs, and take over user accounts.
During his keynote at the AIBP Conference and Exhibition Malaysia 2026, VIDA Founder and Group CEO Niki Luhur illustrated how modern fraud has become a coordinated, cross-border operation.
A typical attack begins when a victim downloads a malicious application or clicks on a phishing link. Once the device is compromised, malware can intercept OTPs, hijack authenticated mobile banking sessions, or initiate transactions without the user's knowledge.
The stolen funds are then transferred to mule accounts, routed through multiple intermediary accounts, and eventually converted into cryptocurrency, making them significantly more difficult to trace and recover.
For decades, passwords and OTPs have been the foundation of account authentication. However, OTP is now a more than 30-year-old authentication method, while fraud techniques continue to evolve rapidly, especially with the rise of AI-powered attacks.
Here are three assumptions about OTPs and authentication that financial institutions should reconsider.
Assumption #1: Only the Account Owner Can Access an OTP
An OTP is essentially a shared secret, a code delivered through SMS or messaging apps that can be accessed by anyone who gains control of the user's device or communication channel.
That assumption no longer holds once malware infects the device.
Malware can read OTP messages, intercept notifications, or exploit compromised devices. Even when users enter the correct OTP themselves, attackers can still perform an account takeover if they have already compromised the user's device or authenticated session.
Assumption #2: Authentication Ends After Login
One of the biggest misconceptions in digital security is that a successful login proves the user is the legitimate account owner.
In reality, login only verifies who authenticated at a single point in time. It does not prove who is controlling the account afterward.
Authenticated sessions can be hijacked, redirected, or handed over to mule accounts, where stolen accounts are used to move illicit funds. Traditional KYC verifies identity only during onboarding. After that, there is no guarantee the same individual remains in control of the account.
To address this risk, financial institutions need continuous authentication, an approach that continuously verifies user identity throughout an active session rather than only at login. High-risk activities, such as high-value transactions or account recovery, should trigger additional biometric verification to confirm the user's identity.
Assumption #3: Authentication Ends Once Biometrics Are Verified
Biometric authentication plays a critical role in verifying legitimate users. However, today's threats do not necessarily stop once authentication is complete.
In some attack scenarios, malware can manipulate transaction details after the user has successfully authenticated.
To mitigate this risk, financial institutions should implement the What You See Is What You Sign (WYSIWYS) principle, ensuring users cryptographically sign the exact transaction they intend to authorize. If any transaction detail changes after approval, the digital signature becomes invalid, allowing the transaction to be rejected.
Biometric authentication should also include liveness detection and be combined with trusted device authentication. Together, these technologies form the foundation of passwordless authentication.
What Is Passwordless Authentication for Mobile Banking?
Passwordless authentication verifies a user's identity without relying on passwords or OTPs as the primary authentication mechanism. Instead, it uses biometrics, passkeys, and trusted devices, credentials that are significantly harder to steal, forge, or misuse.
1. VIDA PhoneToken
VIDA PhoneToken uses Public Key Infrastructure (PKI) technology to bind a user's digital identity to their trusted device. Authentication remains secure without relying on OTPs, as only the registered device can be used to access the account.
2. VIDA FaceToken
VIDA FaceToken combines liveness detection, face matching, and device authentication to ensure that only a genuine user can access an account. Together, these capabilities eliminate reliance on OTPs for login and transaction authentication, reducing the risk of fraud and account takeover.
This approach significantly reduces the risk of phishing, credential theft, and account takeover because it no longer depends on secrets that can be stolen or shared.
More importantly, passwordless authentication provides a far more resilient authentication framework against modern fraud while delivering a seamless user experience.
"Security and user experience don't have to be a trade-off. With the right authentication architecture, financial institutions can achieve both," said Niki Luhur.