EU Cyber Resilience Act Requires 24-Hour Exploit Disclosure From Crypto Wallet Makers

Written by

in

EU Cyber Resilience Act Imposes 24-Hour Vulnerability Reporting on Crypto Wallet Makers

Crypto wallet manufacturers operating in Europe now face a strict 24-hour deadline to notify regulators when a vulnerability in their products is actively exploited. The requirement stems from Article 14 of the European Union’s Cyber Resilience Act (CRA), the bloc’s flagship cybersecurity legislation for connected hardware and software. The incident-reporting provisions took effect on September 11, 2026 — more than a year before the regulation’s broader security requirements become applicable in December 2027.

What the 24-Hour Reporting Window Requires

Article 14 of the Cyber Resilience Act covers manufacturers of “products with digital elements,” a category that encompasses hardware wallets and commercial wallet software because these products connect to devices and networks. When a manufacturer learns that a vulnerability is being actively exploited, it must submit an early warning notification to the EU’s cybersecurity agency ENISA and the designated computer security incident response team (CSIRT) through a single reporting platform within 24 hours.

A fuller vulnerability notification follows within 72 hours, and a final report is due within 14 days of a corrective or mitigating measure becoming available. The same accelerated reporting rules apply to severe incidents affecting product security.

Why the Deadline Matters for the Crypto Industry

The reporting obligation arrives amid a series of high-profile wallet security failures. Hardware wallet maker Coldcard has spent recent weeks responding to attacks that drained Bitcoin from its devices, and the wave three exploiter has since moved funds through CoinJoin. Trezor, meanwhile, disclosed a ShipMonk data breach affecting thousands of US customers.

Under the new EU regime, a manufacturer that discovers its firmware has been exploited must now alert regulators within a day rather than controlling the disclosure timeline itself. For an industry that has historically announced fixes on its own schedule, the requirement turns vulnerability disclosure from a discretionary choice into a legal duty.

Compliance Timeline and Key Exemptions

The September 11, 2026 date applies only to the CRA’s vulnerability and incident-reporting obligations. The regulation’s wider duties — including security-by-design requirements, conformity assessment, and CE marking — do not apply until December 11, 2027.

The regime also includes relief for smaller firms: administrative fines do not apply to microenterprises and small enterprises that miss the 24-hour early-warning deadline, although the reporting obligation itself remains in force. Once the broader framework takes effect, non-compliance can draw enforcement action from national market surveillance authorities.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *