EU cyber rules give crypto wallet makers 24 hours to report exploited flaws

EU cyber rules give crypto wallet makers 24 hours to report exploited flaws

N
News Editor
2026-09-14 11:38:44
Cryptocurrency wallet providers in the European Union now face a tight disclosure schedule under the bloc’s Cyber Resilience Act. The new rules require hardware and software wallet makers to file an early warning within 24 hours after becoming aware of an actively exploited bug or severe vulnerability affecting their products, then submit a full notification within 72 hours. A final report must follow 14 days after corrective or mitigating measures become available, while severe incidents must be fully reported within one month. The reporting regime applies to products with digital elements made available in the EU, not only crypto wallets, and sits within the European Commission’s broader cybersecurity strategy. Penalties are steep: companies that fail to comply with Articles 13 and 14 can face fines of up to 15 million euros, or 2.5% of worldwide annual turnover, whichever is higher. Supplying incorrect, incomplete or misleading information can trigger fines of up to 5 million euros. The move comes after recent security incidents involving wallet providers and related service vendors, including Trezor’s disclosure that 67,000 additional US customers were exposed in a breach tied to shipping provider ShipMonk, phishing warnings issued by Trezor and BitBox, and a June warning from Zilliqa about a flaw in the Zilliqa Ledger app that could expose private keys.

Cryptocurrency hardware and software wallet providers in the European Union are now required to report actively exploited bugs or severe security vulnerabilities within 24 hours after becoming aware of them, under new cyber rules that carry fines of as much as 15 million euros, or about $17.3 million.

The requirement is part of the EU’s Cyber Resilience Act, or CRA, which took effect on Friday, according to an announcement from the European Commission.

24-hour warning followed by a 72-hour notification

Under the new framework, manufacturers must send an early warning for severe vulnerabilities within 24 hours. A full notification is then due within 72 hours. Once corrective or mitigating measures are available, a final report must be submitted 14 days later, and severe incidents must be fully reported within one month.

The European Commission said the reporting rules are meant to better protect consumers and businesses from cyber threats. The measure applies to all products with digital elements made available in the EU and forms part of the bloc’s wider cybersecurity strategy.

Cointelegraph said it has approached the European Commission for more details on the measures.

Fines can climb to 15 million euros

According to the penalties section of the final draft, companies that fail to comply with cybersecurity obligations under Articles 13 and 14 may face administrative fines of up to 15 million euros ($17.3 million), or 2.5% of worldwide annual turnover, whichever amount is higher.

Providing incorrect, incomplete or misleading information can also lead to an administrative fine of up to 5 million euros.

The rules were disclosed weeks after two widely used hardware wallet providers reported user data breaches that could open the door to phishing or social engineering attempts.

Recent wallet-related security incidents drew attention

On Sept. 4, hardware wallet provider Trezor said an additional 67,000 US customers were at risk following a data breach at its shipping provider, ShipMonk. That figure exceeded the company’s initial estimate of 14,000 affected users.

On Wednesday, Trezor and BitBox also warned users about phishing emails disguised as urgent security notices after suspected compromises involving third-party email services.

In June, Layer-1 blockchain network Zilliqa said a vulnerability in the Zilliqa Ledger app could allow attackers to recover users’ private keys by using publicly available onchain data.

Cointelegraph said it has also approached wallet makers Trezor and Ledger for comment on how wallet providers would comply with the new reporting requirements.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
2000

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.