Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
EU mandates 24-hour reporting for crypto wallet security flaws under Cyber Resilience Act
00

EU mandates 24-hour reporting for crypto wallet security flaws under Cyber Resilience Act

Sep 13, 2026

The European Union has begun enforcing strict incident-reporting rules under the Cyber Resilience Act as of September 11, 2026. Crypto hardware and software wallet providers must report actively exploited vulnerabilities within 24 hours or face administrative fines of up to 15 million euros or 2.5% of global annual revenue. The rules follow recent security incidents at Trezor, BitBox, and Zilliqa, aiming to protect consumers from escalating cyber threats.

CRA 24-hour vulnerability reporting requirement

  • ▪The Cyber Resilience Act reporting obligation applies to in-scope products placed on the market before December 11, 2027, making the rules relevant to existing product lines.
  • ▪The European Union began enforcing incident-reporting rules under the Cyber Resilience Act on September 11, 2026, requiring crypto hardware and software wallet providers to notify authorities within 24 hours of identifying an actively exploited vulnerability or severe security incident.
  • ▪The Cyber Resilience Act reporting requirement applies to all products with digital elements made available on the European Union market, including commercially supplied connected hardware wallets and downloadable wallet applications.

Three-stage notification process

  • ▪Under the Cyber Resilience Act, manufacturers must submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe security incident, followed by a detailed notification within 72 hours.
  • ▪Manufacturers must submit Cyber Resilience Act notifications through the Single Reporting Platform launched by ENISA, which routes the alerts to designated coordinating Computer Security Incident Response Teams.
  • ▪Under the Cyber Resilience Act, manufacturers are obligated to inform affected users about security issues and share any available mitigations or actions they can take.

Reporting deadlines by event type

  • ▪For actively exploited vulnerabilities, Cyber Resilience Act rules require a final report to be submitted within 14 days after a corrective or mitigating measure becomes available.
  • ▪For severe security incidents, Cyber Resilience Act rules require a final report to be submitted within one month after the initial 72-hour notification.

CRA penalties up to €15M

  • ▪Micro and small enterprises are exempt from the administrative fines specifically tied to the initial 24-hour early warning requirement under the Cyber Resilience Act.
  • ▪Companies that fail to comply with Articles 13 and 14 of the Cyber Resilience Act face administrative fines of up to 15 million euros, or 2.5% of global annual revenue, whichever is higher.
  • ▪Submitting incorrect, incomplete, or misleading information under the Cyber Resilience Act can subject companies to administrative fines of up to 5 million euros.

Recent Trezor data breaches

  • ▪Trezor and BitBox warned users to watch for phishing emails disguised as urgent security notices following suspected compromises involving a third-party email service.
  • ▪Hardware wallet provider Trezor disclosed on September 4, 2026, that a data breach at its shipping contractor, ShipMonk, exposed 67,000 United States customers, which was higher than the initial estimate of 14,000.

Zilliqa Ledger vulnerability disclosure

  • ▪In June 2026, the layer-1 blockchain network Zilliqa warned that a vulnerability in the Zilliqa Ledger application could allow attackers to recover users' private keys using public on-chain data.
  • ▪A security incident in July 2026 resulted in cryptocurrency losses exceeding 1,778.84 BTC, which was valued at approximately $112.7 million at the time.

Debatable claims

  • ▪The EU should not regulate crypto wallets under general digital product frameworks
  • ▪The EU's 24-hour reporting mandate for crypto security flaws is overly burdensome
  • ▪Commercially supplied open-source crypto wallets should be exempt from the Cyber Resilience Act

4 sources

Cointelegraph
EU Cyber Rules Put Crypto Wallet Makers on 24-hour Reporting Clock
View source article
En
EU Orders Crypto Wallet Firms to Report Serious Security Flaws Within 24 Hours or Face Fines of Up to 15 Million Euros
View source article
Cryptoslate
Crypto wallet creators now have just 24 hours to alert regulators when flaws are exploited
View source article
Cryptobriefing
EU mandates 24-hour reporting for crypto wallet vulnerabilities under Cyber Resilience Act
View source article

Story comments

Loading comments…

Related entities

Cybersecurity

Topics

EU digital regulationCrypto securityCrypto regulation