EU's New Cyber Rules Require Crypto Wallet Makers to Report Vulnerabilities Within 24 Hours
EU Mandates Quick Vulnerability Reporting for Crypto Wallets
The European Union has enacted new cyber rules that require crypto wallet makers to report actively exploited bugs or severe security vulnerabilities within 24 hours of awareness. This is part of the EU's Cyber Resilience Act, which took effect on September 14, 2026.
Timeline and Penalties for Non-Compliance
- An early warning for severe vulnerabilities must be submitted within 24 hours.
- A full notification is required within 72 hours.
- A final report is due 14 days after corrective measures are available, and within one month for severe incidents.
- Companies that fail to comply may face administrative fines of up to 15 million euros ($17.3 million) or 2.5% of worldwide annual turnover, whichever is higher.
- Supplying incorrect, incomplete, or misleading information can result in fines up to 5 million euros.
European Commission Announcement and Goals
The reporting requirements are announced by the European Commission, aiming to better protect consumers and businesses from cyber threats. The rules apply to all products with digital elements made available in the EU, building on the bloc's broader cybersecurity strategy.
Recent Security Incidents Provide Context
The measure comes after recent data breaches at hardware wallet providers. Trezor disclosed that an additional 67,000 US customers were at risk from a data breach, and both Trezor and BitBox warned users about phishing emails. In June, a vulnerability in the Zilliqa Ledger app was reported that could allow attackers to recover users' private keys.
Confirmed Reporting Requirements and Fines
The confirmed facts are that crypto wallet providers must adhere to the 24-hour and 72-hour reporting timelines, with specific fines for non-compliance. The European Commission has outlined these requirements in the Cyber Resilience Act.
Details Awaited from Wallet Providers
Cointelegraph has approached the European Commission, Trezor, and Ledger for more details on how wallet providers will comply with the new reporting requirements, but responses are not yet available. This means implementation specifics are still unclear.
Why These Rules Matter for Security
The rules are designed to enhance security by ensuring timely reporting of vulnerabilities, which can help prevent exploits and protect users' assets. This supports the EU's broader goal of improving cybersecurity for digital products.