Pakistan's fintech ecosystem is expanding fast, but its next growth leap depends on one thing more than features, funding, or even infrastructure: trust. The P@SHA policy roundtable paper on "Boom of Fintech in Pakistan and the Role of Raast" makes it clear that Pakistan now has the rails—Raast as an instant, interoperable payments backbone—but the ecosystem still struggles to convert infrastructure into mass everyday commerce, especially person-to-merchant (P2M) payments.
And here's the hard truth: P2M cannot scale if users and merchants fear account takeovers, scams, and digital fraud. That's why the report explicitly calls out security baselines and recommends device binding (FIDO2) to prevent account takeovers.
Raast is Scaling — But Trust Must Scale With It
Raast has already proven its value as a national utility: it has facilitated more than PKR 40 trillion in transaction value since launch and forms the backbone of Pakistan's digital payments architecture. At the same time, the report highlights a critical imbalance: adoption is still skewed toward transfers rather than commerce, and merchant enablement remains limited.
Mid-2025 snapshots in the paper show both progress and the challenge ahead:
- Total Raast transactions exceed 260 million
- Cumulative value surpasses PKR 9.5 trillion
- Registered users stand above 42 million
- Active merchant endpoints are fewer than 850,000
- Merchant payments total under PKR 200 billion annually
This is exactly where security becomes strategic: merchant payments are not just "more transactions." They're higher-frequency, higher-touch, and more exposed to social engineering, fraud rings, and compromised devices.
The Root Cause of Digital Fraud: Credentials and Recovery
Most large-scale digital fraud in payments ultimately comes down to one of these:
- Stolen or phished credentials (passwords, PINs)
- OTP interception (SIM swap, call forwarding, malware, social engineering)
- Account takeover (ATO) via weak recovery flows (OTP-based reset, "call the helpline" manipulation)
- Session hijacking / device cloning and man-in-the-middle attacks
The industry's legacy controls—especially SMS OTP—were built for a simpler era. In today's fraud landscape, OTP is often a comfort blanket, not real security.
So if Pakistan wants Raast to power everyday commerce, the question becomes:
How do we stop ATO at the root, not just detect it after damage?
What FIDO2 Actually Changes (and Why It's Different)
FIDO2 (commonly implemented as passkeys/WebAuthn) replaces shared secrets (passwords/OTPs) with public-key cryptography tied to the user's device.
Instead of "something you know" (password) or "something you receive" (OTP), FIDO2 proves:
- You are present
- On your trusted device
- Using local biometrics or device PIN
- Without sending a reusable secret over the network
The "Device Binding" Advantage
The report's wording is important: device binding (FIDO2) to prevent account takeovers. That's the heart of FIDO2: even if an attacker knows your username, or tricks you into sharing details, they still can't log in because the private key never leaves the device.
Why It's Phishing-Resistant by Design
With OTP/password flows, a fake page can capture what the user types. With FIDO2, authentication is bound to the real domain and the real device key—so phishing becomes dramatically less effective.
A Practical Implementation: FortAuth
- FIDO2-based, bank-grade authentication: FortAuth enables financial institutions and fintechs to move beyond passwords and vulnerable OTP flows.
- Stops account takeovers at the source: Prevents credential phishing and OTP-based takeover patterns by using phishing-resistant authentication.
- Cryptographic device binding: Strongly ties user access to a trusted device so attackers can't log in from cloned or unfamiliar devices.
- Secure biometric / PIN verification: Uses on-device biometrics or PIN for user presence verification without exposing reusable secrets.
- Faster, frictionless customer experience: Quick login and transaction approvals improve usability while raising security.
- Enables safer Raast-enabled commerce: Strengthens trust for high-frequency payments—especially merchant and wallet transactions.
- Reduces fraud where it starts: Cuts risk at the earliest point in the attack chain—authentication.
- Explore FortAuth: See the overview/architecture and learn how to deploy phishing-resistant FIDO2 authentication: https://fortauth.fortanixor.com/
Website: Fortanixor
Why Pakistan Needs FIDO2 Now (Not Later)
The paper repeatedly emphasizes that adoption depends on "trust/cybersecurity" and strong operational baselines. In a cash-dominant economy, any spike in fraud stories (even if statistically small) can cause a large behavioral rollback to cash.
FIDO2 is a Growth Enabler, Not Only a Security Feature
If Pakistan wants merchants to accept Raast payments at scale, users must feel:
- "My account can't be taken over."
- "My money can't be moved by someone who stole an OTP."
- "If my phone is lost, recovery won't be abused."
That confidence is exactly what FIDO2 delivers best.
"Eliminate Digital Frauds Completely" — What's Realistic?
It's important to be precise:
- FIDO2 can virtually eliminate entire categories of fraud, especially credential theft, phishing-based login fraud, OTP interception-based ATO, and replay attacks when implemented correctly.
- But no single control eliminates 100% of all fraud—because fraud also includes scams (authorized push payments), mule accounts, insider abuse, and social manipulation where the user willingly approves a transaction.
So the honest promise is:
FIDO2 doesn't stop every scam — but it shuts down the biggest technical doors criminals use to take over accounts at scale.
That alone is a massive "step change" for Pakistan's digital economy.
How FIDO2 Fits Perfectly Into Raast's Next Phase
The report calls for aligning participants with cybersecurity baselines and strengthening trust as a prerequisite for sustained growth. A practical national approach could look like this:
1) Make FIDO2 the default for high-risk moments
- First-time login on a new device
- Adding/Changing beneficiary
- Increasing transaction limits
- Profile changes (phone/email)
- Account recovery and reactivation
2) Transaction signing for "non-repudiation"
Use FIDO2 keys not only to login, but to cryptographically approve high-value payments—so disputes reduce and forensic confidence increases.
3) Strong recovery without OTP dependency
Account recovery is where many "secure" apps fail. FIDO2 enables recovery models that don't collapse back to SMS OTP as the master key.
A National Trust Blueprint: What to Do Next
If Raast is the national payment utility (as the paper frames it), then FIDO2 should be treated as a national trust utility layer—a consistent standard banks and fintechs can adopt quickly.
Recommended actions:
- Regulator (SBP): Include "phishing-resistant authentication (FIDO2/passkeys)" in baseline security requirements for Raast participants, alongside device-binding guidance.
- Banks: Embed FIDO2 in mobile apps as the primary login + step-up control, not as an optional "extra setting."
- Fintechs: Build merchant tools and onboarding flows on top of Raast rails, but make trust "built-in," not bolted-on later.
- Ecosystem: Pair security with transparency and user education (fees, fraud, protections) because trust is both technical and behavioral.
The Bottom Line
Pakistan has already built the payment highway. Now it must build the trust engine that keeps users, merchants, and institutions safe at scale.
FIDO2 is the fastest, most proven way to dramatically reduce digital fraud in authentication and prevent account takeovers—especially the OTP-driven fraud patterns that plague modern digital finance. It is not just "another security upgrade." In Pakistan's next fintech phase, it's a foundational requirement.







