Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

EU Crypto Wallet Makers Face 24-Hour Reporting Deadline for Security Flaws

Commercial hardware and software wallet manufacturers operating in the EU must now alert regulators within 24 hours of discovering actively exploited vulnerabilities, under the bloc's Cyber Resilience Act.
2 hours ago 9 views
EU Crypto Wallet Makers Face 24-Hour Reporting Deadline for Security Flaws

Commercial manufacturers of connected hardware wallets and wallet software sold in the European Union must now report actively exploited vulnerabilities or severe security incidents to cyber authorities within 24 hours of discovery, under requirements that took effect on September 11, 2026.

The obligation stems from the EU's Cyber Resilience Act, a horizontal product law that applies to hardware and software with digital elements made available on the EU market. A product qualifies for coverage if its intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network, which can encompass both connected hardware wallets and downloadable wallet applications.

Multi-Stage Reporting Process

The regulation establishes a three-stage reporting framework. Manufacturers must file an initial early warning notification without undue delay and no later than 24 hours after becoming aware of the vulnerability or incident. This filing must indicate which EU member states have received the product and, for severe incidents, note whether unlawful or malicious acts are suspected.

A fuller notification is due within 72 hours unless relevant information was already provided. For actively exploited vulnerabilities, this includes general information about the product, exploit, and vulnerability plus any corrective or mitigating measures. For severe incidents, it must detail the nature of the incident, an initial assessment, and available mitigation information.

Final reporting deadlines vary by event type. Vulnerability reports are due no later than 14 days after a corrective or mitigating measure becomes available. For severe incidents, the final report deadline is one month after the 72-hour notification.

Scope and Implementation

The reporting requirement applies to in-scope products already on the market before the broader law's main provisions take effect on December 11, 2027, extending the obligations to existing wallet product lines.

Manufacturers file through a single reporting platform operated by ENISA, the EU cybersecurity agency, which routes notifications to relevant national Computer Security Incident Response Teams. Manufacturers must also notify impacted users and, where appropriate, all users when action is needed.

Open-source software supplied commercially can face manufacturer obligations under the regulation, though non-monetized software and individual contributors outside their areas of responsibility receive different treatment. Separate reporting duties for open-source software stewards begin December 11, 2027, alongside the CRA's broader product-security requirements.

Market snapshot

Top cryptocurrency prices

Explore all prices
Market prices will appear after the next scheduled refresh.