SMS OTPs have long been a familiar security step for Filipino digital payment users, but e-wallets and payment providers are increasingly looking beyond text-message codes as fraud tactics become more sophisticated.
For years, the one-time password sent through SMS has served as a basic layer of protection for online banking and e-wallet transactions. Users enter a code sent to their registered mobile number before completing a login, payment, transfer, or other sensitive action.

IMAGE CREDOT: Banks and e-wallets will stop sending OTPs starting July 1.
The system is familiar, but it also depends heavily on the security of a mobile number.
If fraudsters gain access to a user’s SIM, intercept authentication messages, or convince consumers to disclose their OTPs through phishing and social engineering, the additional security layer can become vulnerable. SIM-swap
That is pushing the digital payments industry toward authentication methods that are more closely tied to the user’s device, identity, and behavior.
Why SMS OTPs are facing new pressure
SMS-based authentication was designed to add another barrier between an account and an unauthorized user. However, cybercriminals have developed increasingly sophisticated methods for bypassing that barrier.

Phishing scams can trick users into entering their credentials and OTPs into fake websites. Social engineering can convince users to reveal security codes. SIM-swap attacks can potentially allow criminals to take control of the phone number associated with an account.
The growing use of these techniques means that simply sending a code to a registered mobile number may no longer provide sufficient protection for every type of transaction.
This is especially important for digital wallets, where users can transfer money instantly and increasingly use their accounts for bills, purchases, remittances, and other financial transactions.
From something you know to something you have and are
The shift in authentication is partly about making security less dependent on information that can be stolen or shared.

Traditional passwords rely on something you know. SMS OTPs add something you have, theoretically using possession of the registered mobile number as another verification layer.
Newer authentication approaches can add stronger device and biometric signals, including something you are, such as a fingerprint or facial recognition.
With device-bound authentication, credentials can be linked to a particular device rather than simply being delivered through a potentially vulnerable communication channel.
This makes the authentication process less dependent on users manually receiving and entering codes.
FIDO brings passwordless authentication into payments
One technology gaining attention in this transition is FIDO, or Fast Identity Online authentication.
FIDO-based authentication is designed to reduce reliance on passwords and shared secrets. Instead of repeatedly sending credentials over the internet, authentication can use cryptographic credentials stored on a user’s device.

IMAGE CREDIT: FIDO (Fast Identity Online) – Identity Verification – Local Biometric Authentication – HUAWEI Developer
The user may verify their identity through a device’s biometric system, such as fingerprint recognition or facial authentication, or through another secure device-level method.
Importantly, biometric information itself does not have to be transmitted to the payment provider for authentication. The device can use the biometric check to unlock the cryptographic credential needed to authenticate the user.
For consumers, the experience can feel much simpler: instead of waiting for an SMS and typing a code, they may simply verify a transaction using Face ID, a fingerprint, or another device-based authentication method.
High-value transfers need more than one signal
The move away from SMS OTPs does not necessarily mean that biometrics will become the only security layer.
For high-value or unusual transactions, payment providers can combine multiple signals to determine whether an action appears legitimate.
This is where behavioral analytics can play an important role.
A payment provider may assess factors such as the user’s typical transaction patterns, device information, location-related signals, transaction amount, frequency of transfers, and other risk indicators.
A transaction that looks consistent with a user’s normal behavior may require less intervention, while an unusual transaction could trigger additional verification.
For example, a user who normally transfers small amounts to a few familiar recipients may generate a higher-risk signal if an unusually large transfer is suddenly initiated to a new recipient from an unfamiliar device.
Instead of treating every transaction exactly the same way, risk-based authentication can respond according to the circumstances surrounding the transaction.
Security can become less visible to users
One of the biggest changes in this model is that stronger security does not necessarily have to mean more steps for consumers.
With SMS OTPs, users actively participate in the security process by waiting for a message, finding the code, and entering it into the application.
Device-bound authentication and behavioral analytics can make more of the security process happen in the background.
The device can establish whether the correct credential is being used, while the payment provider’s systems assess whether the transaction resembles legitimate user behavior.
If everything looks normal, the payment may proceed with minimal friction. If multiple risk signals appear, the system can request additional authentication or prevent the transaction from continuing.
The shift does not eliminate fraud
Moving beyond SMS OTPs is not a guarantee that digital payment fraud will disappear.
Criminals can continue to target consumers through phishing, fake applications, social engineering, malware, and other techniques. Even sophisticated authentication systems can be undermined if users are tricked into approving transactions themselves.
This means consumer awareness remains important even as authentication technology improves.
Users should avoid sharing passwords, PINs, authentication codes, or other sensitive credentials, and should be cautious about unexpected messages asking them to click links or approve transactions.
Payment providers also need to ensure that new authentication systems are implemented alongside effective fraud monitoring, transaction controls, and consumer protection measures.
What the shift means for Filipino e-wallet users
The gradual move beyond SMS OTPs represents a broader change in how digital payments approach authentication.
Instead of relying primarily on a code delivered to a mobile number, providers can increasingly combine device-bound credentials, biometrics, FIDO-based authentication, and behavioral analytics to determine whether a user and transaction are legitimate.
For consumers, this could mean fewer SMS codes and a smoother payment experience without necessarily compromising security.
For payment providers, however, the challenge is more complex. They must balance convenience with increasingly sophisticated fraud detection while ensuring that stronger security does not make digital financial services difficult to access.
As more Filipinos rely on e-wallets for everyday payments and money transfers, authentication is becoming an increasingly important part of digital financial security.
The future of e-wallet security may therefore look far less like a six-digit text code and much more like a seamless, biometric verification embedded directly into the device. And that shift could make authentication faster for legitimate users while giving payment providers more signals to identify suspicious activity before money moves.
