TL;DR, The Reserve Bank of India (RBI) is steering a shift from traditional OTP-based authentication in response to the rising incidents of online fraud, including over 95,000 cases of UPI fraud reported in the fiscal year 2022-23. This article explores vulnerabilities inherent in OTP systems, such as susceptibility to social engineering and phishing attacks, and discusses the potential of Verifiable Credentials as an alternative to OTPs.
RBI Governor Shaktikanta Das, during a monetary policy statement address, said, "With innovations in technology, alternative authentication mechanisms have emerged in recent years. To facilitate the use of such mechanisms for digital security, it is proposed to adopt a principle-based “Framework for authentication of digital payment transactions”. Instructions in this regard will be issued separately."