Attackers Have Industrialized the Moment of Urgency: The Hidden Cost of OTP Nobody Talks About
Discover the hidden costs of SMS OTPs, from fraud and failed delivery to customer abandonment, and how passkeys and persistent authentication reduce risk.



Key takeaways
Key Takeaways
- SMS OTPs create hidden costs beyond message fees. Delayed delivery, failed authentication, customer abandonment, support requests, account recovery, and repeated challenges can make SMS-based authentication far more expensive than it appears.
- One-time passcodes remain vulnerable to phishing and social engineering. An OTP can confirm that the correct code was entered, but it cannot prove that the legitimate customer entered it or was not manipulated into sharing it.
- Phishing-resistant authentication can improve security and customer experience. Passkeys, silent authentication, and device-bound cryptographic credentials reduce reliance on reusable codes while enabling faster, lower-friction authentication.
- Persistent authentication can reduce SMS costs and unnecessary challenges. Prove securely persists authentication so trusted customers remain recognized across interactions without repeatedly receiving and entering one-time passcodes.
- Strong authentication must begin with strong identity proofing. Organizations need high-assurance identity verification during credential enrollment and account recovery to prevent fraudsters from registering phishing-resistant credentials in another person’s name.
In a recent Prove webinar, “Layering Trust in the Real World,” Chris Nygard of KeyBank and Michael Di Marco of BetMGM shared a candid, real-world perspective on the limitations of SMS one-time passcodes. They explored how fraudsters exploit OTPs, the operational and customer-experience costs businesses often overlook, the challenges of moving millions of customers toward passkeys and silent authentication, and why phishing-resistant credentials must be paired with equally strong identity proofing.
Their conversation revealed an important truth: the cost of OTP extends far beyond the price of sending a text message.
OTP’s biggest cost is not the text message
For years, SMS one-time passcodes have been treated as a practical compromise: familiar to customers, easy to deploy, and seemingly inexpensive one transaction at a time. But that view misses the real economics.
Every OTP creates a new paid event. Every delayed or failed message adds friction. Every prompt gives an attacker another chance to impersonate a trusted organization and persuade a customer to surrender a code. And every time a legitimate customer is challenged again, the business spends money to re-establish trust it may already have earned.
The hidden cost of OTP is the compounding tax it places across security, operations, customer experience, and growth.
A low-cost message can become an expensive operating model
The direct expense is straightforward: organizations pay to send SMS messages, often at enormous scale. The indirect expenses are harder to isolate, and usually much larger.
- Delivery friction. Messages may arrive late or not at all, interrupting high-intent moments such as account opening, login, payments, withdrawals, and profile changes.
- Customer abandonment. A customer who has to leave the experience, find a code, return, and retry has more opportunities to give up.
- Support and recovery. Failed delivery, changed phone numbers, lost devices, and locked accounts create service contacts and manual recovery work.
- Fraud losses. A passcode can be relayed, intercepted, or willingly handed over to a convincing fraudster.
- Repeat-challenge fatigue. Treating every interaction as a fresh authentication event forces known customers through the same friction again and again.
That lack of visibility matters. An OTP can confirm that the correct code was entered; it cannot prove that the legitimate customer entered it, understood the request, or was not manipulated into sharing it.
Attackers have industrialized the moment of urgency
OTP fraud rarely begins with a technical exploit. It often begins with pressure: a message about a suspicious transaction, an urgent account problem, or an immediate security threat. The attacker presents themselves as the helper, and turns the customer into the mechanism that defeats the control.
This has ceased to be an edge case. Fraud kits, generative AI, spoofed communications, and highly polished social engineering have lowered the barrier to launching convincing campaigns.
The answer is not simply a different challenge
Moving beyond OTP should not mean swapping one isolated factor for another. The stronger model is layered: establish the customer’s identity with appropriate assurance, bind authentication to the customer and device with cryptographic credentials, and use trusted signals and orchestration to decide when an interaction can proceed silently and when more assurance is warranted.
Passkeys and other phishing-resistant, device-bound methods change the economics because the credential is not a reusable secret a customer can read to a fraudster. When the experience works as intended, stronger security can also mean less customer effort.
Persistence changes the OTP cost equation
The most important shift is from repeated proof to persistent trust. Prove persists authentication so a trusted customer can remain recognized across interactions with less friction. Instead of buying another SMS message every time the business needs confidence, organizations can use phishing-resistant, device-bound authentication and reserve step-up experiences for situations that genuinely require them.
That can reduce SMS volume and associated delivery costs while improving the experience for legitimate customers. It also makes the authentication event harder to phish because there is no code for the customer to disclose.
The strategic shift: Stop paying to re-challenge every known customer. Persist strong authentication for trusted users, then apply additional assurance when the context calls for it.
Strong credentials still need strong identity proofing
A phishing-resistant credential is only as trustworthy as the enrollment behind it. If an attacker can register a strong credential in someone else’s name, the organization has made the attacker’s access more durable, not the customer’s.
For identity and risk leaders, this is the design principle that prevents a modernization program from becoming a credential-only project: high-assurance identity proofing, secure credential enrollment, and persistent recognition have to work together.
A practical path beyond OTP
Most organizations cannot replace every OTP in one move, and they do not need to. OTP may remain useful as a fallback or in selected journeys while teams modernize the highest-volume, highest-friction, or highest-risk interactions first.
- Quantify the full cost of OTP through SMS spend, retries, abandonment, support contacts, recovery work, and fraud exposure.
- Identify journeys where trusted users are repeatedly challenged and where persistent authentication can remove unnecessary friction.
- Match identity-proofing assurance to credential assurance, especially during enrollment and recovery.
- Introduce phishing-resistant, device-bound authentication while preserving accessible paths for customers who are not yet ready to adopt new methods.
- Measure the outcome across security, cost, conversion, authentication success, and customer effort, and not SMS volume alone.
The hidden cost becomes a visible opportunity
OTP made digital authentication possible at enormous scale. But its familiar interface can obscure what organizations now pay to maintain it: recurring message fees, avoidable abandonment, operational overhead, and a credential that can be socially engineered.
Phishing-resistant authentication changes that tradeoff. With Prove Key, organizations can securely persist authentication so trusted customers stay authenticated with less friction, helping reduce SMS costs while making the authentication experience more resistant to fraud.
For trust and safety, risk, and identity leaders, the key issue is whether continuing to pay (in dollars, fraud exposure, and customer patience) to prove the same trusted customer again and again still makes sense.
The modern
way of proving identity
Trusted by 2500+ leading companies to reduce fraud and improve consumer



Keep reading
Read the article: How to Achieve More B2B Customer Growth With Prove Pre-Fill® for BusinessProve Pre-Fill® for Business provides a comprehensive solution for organizations that want to onboard businesses by delivering faster onboarding, a decrease in abandonment, and a reduction in fraud (relative to attack rate).
Read the article: Account Takeovers: The Silent Revenue KillerAccount takeover (ATO) fraud is rapidly becoming one of the biggest threats facing digital marketplaces and gig platforms. Learn how ATO attacks work, why they are accelerating, the latest fraud trends and statistics, and how continuous identity verification helps organizations prevent account takeovers while protecting revenue, customer trust, and user experience.
Read the article: The Silent Drain: How SMS Pumping Is Bleeding Digital Marketplaces DrySMS pumping fraud is silently increasing verification costs for digital marketplaces by exploiting OTP workflows. Explore how these attacks operate, why traditional SMS authentication is failing, and how proactive phone intelligence can prevent fraud before an SMS is sent.