EU mandates 24-hour reporting for crypto wallet vulnerabilities under Cyber Resilience Act

1 week ago 47

Starting September 11, 2026, any company selling a crypto wallet in the European Union will have exactly 24 hours to flag an actively exploited vulnerability to regulators. Miss that window, and fines can climb as high as €15 million or 2.5% of annual global turnover, whichever is larger.

The requirement comes from the EU’s Cyber Resilience Act (CRA), a sweeping piece of legislation that treats crypto wallets, both hardware and software, the same way it treats any product with digital elements.

How the reporting timeline works

Article 14 of the CRA lays out a two-stage notification process. Within 24 hours of becoming aware of an actively exploited vulnerability or severe security incident, manufacturers must file an early warning through ENISA’s Single Reporting Platform. ENISA is the EU’s cybersecurity agency, and the platform routes alerts to relevant national Computer Security Incident Response Teams (CSIRTs).

Within 72 hours, a more thorough notification is required, documenting the scope, severity, and technical details of the exploit. Manufacturers are also obligated to inform affected users about the security issue and share any mitigations that can be deployed.

One important nuance: the clock starts ticking only when a manufacturer becomes aware of active exploitation, not when an independent security researcher files a theoretical bug report.

The penalty structure has some flexibility built in. Micro and small enterprises are exempt from fines tied specifically to the initial 24-hour early warning requirement. Larger firms get no such cushion.

Why this matters for crypto wallet makers

The timing is not coincidental. A significant incident in July 2026 resulted in losses exceeding 1,778.84 BTC, valued at roughly $112.7 million at the time.

The broader CRA requirements, which include security-by-design mandates and proper certification processes, are scheduled to come into force on December 11, 2027. That gives manufacturers roughly 15 months after the reporting obligations begin to overhaul their entire product development lifecycle.

Companies that sell wallets in the EU but are headquartered elsewhere still fall under the regulation if their products are available on the European market.

What this means for the market

The requirement to notify affected users about exploits and available mitigations could fundamentally change how the industry communicates about security incidents. Under the CRA, delaying disclosure or downplaying severity becomes a finable offense.

Because reporting is triggered by awareness of active exploitation rather than theoretical risk, manufacturers have an incentive to invest heavily in threat intelligence.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article