EU cyber rules put crypto wallet makers on 24-hour reporting clock

The European Commission says cryptocurrency hardware and software wallet providers must issue an early warning within 24 hours of becoming aware of actively exploited bugs or severe security flaws, under the Cyber Resilience Act which took effect on Friday. Firms must follow with a full notification within 72 hours and face administrative fines up to €15 million or 2.5% of global turnover for noncompliance.

By AI NewsroomPublished about 5 hours agoUpdated about 5 hours ago0 views
EU cyber rules put crypto wallet makers on 24-hour reporting clock

Why It Matters

The shorter reporting windows aim to reduce the time attackers can exploit vulnerabilities and strengthen consumer protection — a response that follows recent wallet-related data breaches and phishing incidents highlighted by several providers. The penalties create stronger incentives for rapid disclosure and remediation across products with digital elements sold in the EU.

Key Facts

  • Regulation: European Cyber Resilience Act (CRA) took effect on Friday (per the European Commission)
  • 24-hour requirement: Manufacturers must submit an early warning for severe vulnerabilities within 24 hours of awareness
  • 72-hour requirement: A full notification must follow within 72 hours
  • Final reporting timelines: A final report is required 14 days after corrective or mitigating measures are available and within one month for severe incidents
  • Scope: Applies to all products 'with digital elements made available in the EU'

The European Commission has told makers of cryptocurrency hardware and software wallets that they must provide an early warning within 24 hours after becoming aware of actively exploited bugs or other severe security vulnerabilities affecting their products. The requirement is part of the EU’s Cyber Resilience Act, which the Commission said took effect on Friday.

Under the CRA’s reporting regime, manufacturers must issue a preliminary notice within 24 hours and deliver a full notification within 72 hours. A final report is required 14 days after corrective or mitigating measures are available, and for particularly severe incidents a final report must arrive within one month. The Commission said the measures are intended to better protect consumers and businesses from cyber threats and extend to all products with digital elements made available in the EU.

The law carries substantial penalties for noncompliance. Companies that do not meet the reporting obligations under Articles 13 and 14 may face administrative fines of up to €15 million or 2.5% of worldwide annual turnover, whichever is higher; the European Commission’s draft text also sets fines of up to €5 million for supplying incorrect, incomplete or misleading information. The source material cites the €15 million figure as roughly $17.3 million.

The change comes amid recent security incidents affecting wallet users. Hardware wallet maker Trezor disclosed that a shipping-provider breach at ShipMonk put an additional 67,000 U.S. customers at risk, exceeding an earlier estimate of 14,000 affected users. Trezor and BitBox later warned customers about phishing emails posing as urgent security notices after suspected compromises of third-party email services. Separately, Zilliqa warned in June that a vulnerability in the Zilliqa Ledger app could let attackers recover private keys using publicly available onchain data. Cointelegraph said it has contacted the European Commission, as well as wallet makers Trezor and Ledger, for further comment on compliance with the new reporting requirements.

Keep Reading