EU Cracks Down on Crypto Wallet Security with 24-Hour Vulnerability Reporting
The European Union is set to introduce new regulations for crypto wallet makers, mandating that they report actively exploited vulnerabilities within 24 hours of becoming aware of them. This requirement comes from the EU's Cyber Resilience Act (CRA), which treats crypto wallets as any other product with digital elements.
Under Article 14 of the CRA, manufacturers must file an early warning through ENISA's Single Reporting Platform within 24 hours of discovering a vulnerability that has been actively exploited. This notification must include information about the scope and severity of the exploit. A more detailed report is required within 72 hours, including technical details and any available mitigations.
The regulation applies to all companies selling crypto wallets in the EU, regardless of their headquarters location. Fines for non-compliance can reach as high as €15 million or 2.5% of annual global turnover, whichever is larger. The requirement is set to come into effect on September 11, 2026.
The timing of this regulation is significant, following a major incident in July 2026 that resulted in losses exceeding 1,778.84 BTC (valued at around $112.7 million at the time). The CRA's broader requirements, including security-by-design mandates and certification processes, are scheduled to take effect on December 11, 2027.