Cryptocurrency hardware and software wallet providers in the European Union are now required to report actively exploited bugs or severe security vulnerabilities within 24 hours after becoming aware of them, under new cyber rules that carry fines of as much as 15 million euros, or about $17.3 million.
The requirement is part of the EU’s Cyber Resilience Act, or CRA, which took effect on Friday, according to an announcement from the European Commission.
24-hour warning followed by a 72-hour notification
Under the new framework, manufacturers must send an early warning for severe vulnerabilities within 24 hours. A full notification is then due within 72 hours. Once corrective or mitigating measures are available, a final report must be submitted 14 days later, and severe incidents must be fully reported within one month.
The European Commission said the reporting rules are meant to better protect consumers and businesses from cyber threats. The measure applies to all products with digital elements made available in the EU and forms part of the bloc’s wider cybersecurity strategy.
Cointelegraph said it has approached the European Commission for more details on the measures.
Fines can climb to 15 million euros
According to the penalties section of the final draft, companies that fail to comply with cybersecurity obligations under Articles 13 and 14 may face administrative fines of up to 15 million euros ($17.3 million), or 2.5% of worldwide annual turnover, whichever amount is higher.
Providing incorrect, incomplete or misleading information can also lead to an administrative fine of up to 5 million euros.
The rules were disclosed weeks after two widely used hardware wallet providers reported user data breaches that could open the door to phishing or social engineering attempts.
Recent wallet-related security incidents drew attention
On Sept. 4, hardware wallet provider Trezor said an additional 67,000 US customers were at risk following a data breach at its shipping provider, ShipMonk. That figure exceeded the company’s initial estimate of 14,000 affected users.
On Wednesday, Trezor and BitBox also warned users about phishing emails disguised as urgent security notices after suspected compromises involving third-party email services.
In June, Layer-1 blockchain network Zilliqa said a vulnerability in the Zilliqa Ledger app could allow attackers to recover users’ private keys by using publicly available onchain data.
Cointelegraph said it has also approached wallet makers Trezor and Ledger for comment on how wallet providers would comply with the new reporting requirements.

