The European Union has implemented new cybersecurity requirements for cryptocurrency wallet manufacturers under the Cyber Resilience Act (CRA), which took effect on Friday. The measure requires hardware and software wallet providers to report actively exploited bugs and severe security vulnerabilities affecting their products within strict timeframes.
Under the new rules, manufacturers must submit an early warning for severe vulnerabilities within 24 hours of awareness, followed by a full notification within 72 hours. A final report is required 14 days after corrective or mitigating measures become available, or within one month for severe incidents.
The reporting requirements apply to all products "with digital elements made available in the EU" and are designed to better protect consumers and businesses from cyber threats. The measure builds on the EU's broader cybersecurity strategy.
Enforcement and Penalties
Companies that fail to comply with the cybersecurity measures outlined in Articles 13 and 14 of the act face administrative fines of up to €15 million or 2.5% of worldwide annual turnover, whichever is higher. Providing incorrect, incomplete, or misleading information carries fines of up to €5 million.
Recent Security Incidents in Crypto Sector
The new reporting requirements come weeks after several prominent security breaches in the cryptocurrency industry. In September, hardware wallet provider Trezor disclosed that a data breach at its shipping provider ShipMonk affected approximately 67,000 US customers, exceeding initial estimates of 14,000 affected users.
Also in September, Trezor and BitBox warned users about phishing emails disguised as urgent security notices following suspected compromises of third-party email services. Earlier in June, Layer-1 blockchain network Zilliqa disclosed a vulnerability in its Ledger app that could potentially allow attackers to recover users' private keys using publicly available onchain data.


