This event focused on security building, compliance boundaries, and business implementation under the trend toward institutionalization. It attracted around 50 decision-makers and business leads from exchanges, wallets, payment and stablecoin institutions, licensed traditional financial institutions, public chain teams, and professional service organizations to attend.
Author and source: BlockSec
On September 16, the closed-door symposium “Harbouring Trust” Hong Kong, hosted by BlockSec and jointly supported by East Asia, Jumio, and TiDB, concluded successfully in Hong Kong.
This event focused on security building, compliance boundaries, and business implementation under the trend toward institutionalization. It attracted around 50 decision-makers and business leads from exchanges, wallets, payment and stablecoin institutions, licensed traditional financial institutions, public chain teams, and professional service organizations to attend.
Opening: Building a foundation of trust for Web3 requires multi-party co-construction
Michele Fung, a council member of the Hong Kong Fintech Association (Fintech Association of Hong Kong) and Head of Unlimit for Asia Pacific, delivered opening remarks for this event.
She said that security and compliance are no longer static code audits and management procedures, but dynamic engineering deeply integrated with law, technology, and responsibility—forming the underlying foundation to support the steady progress of the next generation of the crypto economy. She also said that the association has always been committed to connecting the industry, promoting policy dialogue, and fostering technological innovation. She is also very pleased to see security technology organizations like BlockSec deeply participating in the development of Hong Kong’s crypto industry.
"People who stand alone are hard to lift up; those who go together are easy to move forward." At the end of her speech, she said that building a safe, trustworthy, and sustainable Web3 environment cannot be accomplished independently by any single organization. It requires close collaboration among regulatory bodies, security service providers, fintech companies, industry experts, and a wide community of developers.

Michele Fung delivers the opening remarks for Trust to Spark · Hong Kong
Keynote speech: As crypto moves toward institutionalization, the nature of risk changes

Zhou Yajin, Co-founder of BlockSec and associate professor at the Chinese University of Hong Kong, delivers a thematic keynote speech
As the host, Zhou Yajin, Co-founder of BlockSec and an associate professor at the Chinese University of Hong Kong, delivered a keynote speech titled (Security and Compliance for the Institutionalization of Crypto).
He broke down institutionalization into four layers of meaning: blockchain has become a factual underlying infrastructure for fast settlement across financial institutions; the trading scale of new assets such as stablecoins and on-chain stocks has been growing rapidly; market participants have expanded from crypto-native players to traditional financial institutions; and the industry has moved on from “savage growth,” while regulatory rules have gradually become clearer. With that shift, the nature of risk changes as well: attackers use AI to significantly increase attack efficiency; grey-and-black industries have formed a crime-as-a-service ecosystem that includes customer acquisition, chat, website building, and money laundering; stablecoins are used as a foundation infrastructure for money laundering; and criminals generally evade risk controls by making two to four hops of transfers, meaning that traditional anti–money laundering systems that only do one-hop screening are easy to bypass.
On-site interaction
Guests also took part in on-site compliance knowledge Q&A and took group photos.

Guests participate in compliance knowledge Q&A on site

Group photo of the full event for Trust to Spark · Hong Kong
41 pre-event questionnaires—sketching out today’s room
Before the event, we distributed a questionnaire of no more than 10 questions to each invited guest, and received 41 responses. The results showed that the top three concerns were tied for first place: funding security and continuous monitoring, stablecoins and cross-border payment channels across multiple countries, and regulatory policies and licenses. Overall, 78% of the guests hoped to learn about payment and stablecoin institutions on site. The questionnaire also collected 23 questions that guests most wanted to ask. After categorizing them by theme, they were presented anonymously, forming all the materials for that day’s Hot Seat segment.

The topics guests care about most (41 pre-event questionnaires)
Roundtable One: Compliance Boundaries, Operational Practice, and Growth
Roundtable One was conducted in Cantonese. Real-time subtitle translation was provided on site. It was moderated by Yanyee He, BlockSec’s Head of Compliance Strategy. The dialogue guests were Corey Tang, Head of Compliance at PingPong; Winnie Cheung, Director of Consulting Business at Deloitte Hong Kong; and Kelvin Lo, Business Head of Web3.0 Payments at LianLian LDC.

Roundtable One: Compliance Boundaries, Operational Practice, and Growth
How to draw the boundaries for compliance compromises—guests proposed a three-dimensional framework: the hard requirements of local regulators, the company’s own risk appetite, and whether the收益 from a single project can cover the compliance cost. If any one of the three does not hold, the business should not be pursued. On timing of intervention, there was consensus that compliance must be addressed early—during business planning, expanding to new markets, and early client engagement. Waiting until the business is actually launched to “fill in” the processes wastes the resources of the entire backend team. As for whether compliance is a cost center, the audience received a clear rebuttal on site: compliance can be converted into a marketing advantage. Industry trust itself creates business opportunities, and it can also form competitive barriers—providing a differentiated advantage when engaging with traditional financial institutions. The guest also noted that there is still a clear talent gap in Hong Kong’s Web3 compliance field. General job seekers lack sufficient understanding of SFC regulatory rules, and crypto-native practitioners often have weak compliance and risk-control awareness.
Roundtable Two: Risk Frontlines and Industry Collaboration
The second-roundtable was moderated by Ruby Xu, COO of BlockSec. The panelists were Karry, CEO of Bitget Wallet; Alan Xin, Head of On-chain Risk Control at Bybit; Toya Zhang, Deputy Chief Executive Officer of EX.IO GROUP; and Paolo Chen, Chief Strategy Officer of VDX.

Roundtable Two: Risk Frontlines and Industry Collaboration
A guest who personally experienced the $1.5 billion theft event reconstructed the entire process on site: North Korean hackers compromised the multi-signature service provider’s developers’ computers and cloud environment, tampering with the transaction pages to carry out the theft. Looking back, it was a security incident caused by supply-chain risk. Bybit’s own systems were never breached, and after the incident, the platform withstood the pressure instead of shutting down withdrawals. Through live streaming, it publicly disclosed all relevant information to the community, quickly earning user and industry confidence and enabling the business to recover rapidly. The case has now been filed and initiated in the United States, and the recovery of funds is also proceeding in an orderly manner. This incident has also pushed the industry to take seriously the “what you sign is what you see” problem of multi-signatures and to strengthen risk prevention and control across external supply chains.
Balancing product iteration and security, the event dispelled a common misconception on site: long-unupdated legacy systems are not more secure—they are more likely to have vulnerabilities spotted and scanned by AI. A practical approach is to keep the security team independent and empowered to halt any product release, have them participate in product design and review in advance, and set up an AI-supported red team for proactive offense-and-defense. In terms of implementation pathways: for wallet payments, the service provider handles on-chain security and KYT risk control, while the fiat currency stage and KYC are completed in cooperation with locally licensed institutions. For RWA, it continues to extend from U.S. stock tokenized assets toward private equity. This year in May, Hong Kong licensed virtual asset trading platform (VATP) EX.IO announced that it has successfully completed the listing and distribution of an Asian-first tokenized product—SpaceX equity-linked depositary receipts (DR). As for the core demand from traditional financial institutions entering the market, it is to retain existing customers. By leveraging third-party service providers to fill gaps in systems, compliance, and liquidity capabilities, they do not need to build end-to-end infrastructure themselves.

On-site Roundtable Two
Closing remarks
Thank you to East Asia, Jumio, and TiDB for their support of this event, and thank you to every guest who attended. BlockSec will continue to deepen and strengthen security audits, attack detection, fund tracing, and compliance capabilities—working with regulators, financial institutions, and industry partners to lay a solid foundation for security and compliance in the process of crypto’s institutionalization.
For the background and agenda setting of this event, you can review our earlier release (Event preview|Trust to Spark · Hong Kong: Closed-door exchange on September 16).
