EU Cyber Resilience Act Puts Crypto Wallet Makers on 24-Hour Vulnerability Reporting Clock
Cryptocurrency hardware and software wallet providers operating in the European Union now face a 24-hour deadline to report actively exploited bugs or severe security vulnerabilities affecting their products, under new rules that took effect on Friday.
The measure is part of the EU’s Cyber Resilience Act (CRA), according to an announcement from the European Commission. Manufacturers must submit an early warning for severe vulnerabilities within 24 hours of becoming aware of them, followed by a full notification within 72 hours. A final report is required 14 days after corrective or mitigating measures are available, and within one month for severe incidents.
Fines Up to 15 Million Euros
Companies that fail to adhere to the cybersecurity measures under Articles 13 and 14 of the act may face administrative fines of up to 15 million euros or 2.5% of worldwide annual turnover, whichever is higher, according to the penalties section of the final draft. Supplying incorrect, incomplete or misleading information is separately subject to fines of up to 5 million euros.
The reporting requirements extend to all products “with digital elements made available in the EU,” making crypto wallet makers explicitly part of a framework that covers connected devices and software more broadly. The EC said the new rules aim to better protect consumers and businesses from cyber threats and build on the EU’s broader cybersecurity strategy.
Why Wallet Makers Are Watching Closely
The rules arrive weeks after two popular hardware wallet providers disclosed user data breaches that could lead to phishing or social engineering attempts. On Sept. 4, hardware wallet provider Trezor revealed that an additional 67,000 US customers were at risk from the data breach suffered by its shipping provider, ShipMonk, exceeding the initially estimated 14,000 users.
Last Wednesday, Trezor and BitBox warned users about phishing emails disguised as urgent security notices after suspected compromises involving third-party email services. In June, Layer-1 blockchain Zilliqa warned that a vulnerability in the Zilliqa Ledger app could allow attackers to recover users’ private keys using publicly available onchain data.
Those incidents involved data leaks rather than flaws in wallet firmware itself, but they illustrate the attack surface the CRA now forces manufacturers to monitor and disclose. For an industry whose value proposition rests on self-custody, the reputational cost of a delayed disclosure could exceed the statutory fine.
Compliance Questions Remain
Cointelegraph said it approached the European Commission for more details on the measures and contacted wallet makers Trezor and Ledger for comment on how they would comply with the new reporting requirements.
Open questions include how the 24-hour clock applies to vulnerabilities discovered by third-party researchers, whether software wallet developers distributing through app stores count as manufacturers, and how the rules interact with the EU’s existing disclosure framework under the Digital Operational Resilience Act (DORA), which applies to financial entities.
Larger wallet companies with established security teams and bug bounty programs are likely to absorb the requirement as an extension of existing practice. Smaller developers, particularly open-source projects with distributed maintainers and no legal entity in the EU, face a harder calculation: staff up for compliance, restrict distribution to the bloc, or risk the fines.
Global Context
The EU framework also lands amid intensifying global scrutiny of crypto security practices. Regulators in the United States and Asia have tightened expectations around incident disclosure over the past two years, and the CRA is among the first regimes to hard-code explicit hourly deadlines for product-level vulnerabilities rather than data breaches alone. How wallet makers adapt here could become a reference point for similar rules elsewhere, since most major wallet brands distribute globally and tend to build compliance to the strictest applicable standard.
For European users, the practical upside is faster public disclosure when the tools guarding their keys are found wanting. For manufacturers, the trade-off is a compliance burden that rewards companies with round-the-clock security operations and punishes those without a formal vulnerability response process. In an industry where a single firmware flaw can empty thousands of accounts, forced transparency may ultimately serve the same goal the wallets themselves were built for: making self-custody safer to hold.
Part of a Broader EU Push
The CRA reporting clock is the latest in a series of EU measures tightening obligations around digital assets, following the Markets in Crypto-Assets regulation and the traceability requirements of the Transfer of Funds regulation. Together they signal that Brussels intends to regulate crypto infrastructure with the same toolkit it applies to connected products and financial services generally.
Bitcoin was trading around 77,709 USD at press time as markets look ahead to a Federal Reserve rate decision this week. For wallet makers serving European customers, however, the more consequential deadline is already here: from Friday, the clock on severe vulnerabilities starts at 24 hours.
24 hours for an early warning is tight when half these wallet firms run on 3 devs and a hardware signer
^ incident response at 2am against a 24h clock sounds miserable. expect a flood of vague boilerplate early warnings just to tick the box
The 72h full notification is where the real detail lands. early warnings will be noise, full reports the signal. anyone monitoring these feeds should tune accordingly
24 hours to disclose a vulnerability you might not have even fully diagnosed yet, backed by 15 million euro fines. Security teams at wallet firms are in for a rough year.
its 24h from awareness not from discovery, but yeah the clock is brutal either way
15 million euros or 2.5% of worldwide turnover, whichever is higher. That is a heavy stick for a reporting delay, and it will get corporate lawyers involved fast.
which is sort of the point. fine driven compliance is ugly but it moves faster than goodwill ever did
mostly agree until you remember the Trezor situation. ShipMonk numbers went from 14k to 67k affected users and that came out in dribs. goodwill had its chance
2.5% of worldwide turnover for a missed disclosure will finally make the big hardware wallet brands staff their security teams properly. Long overdue.
nobody is talking about the 5 million euro fine for incomplete or misleading info. legal will review every disclosure twice before anything ships, which kind of defeats the 24h clock