EU Cracks Down on Crypto Wallet Security with New Reporting Requirements
The European Union has introduced new cybersecurity regulations that require cryptocurrency hardware and software wallet providers to report actively exploited bugs or severe security vulnerabilities within 24 hours.
The measure, part of the EU's Cyber Resilience Act (CRA), aims to better protect consumers and businesses from cyber threats. Manufacturers must submit an early warning for severe vulnerabilities within 24 hours, followed by a full notification within 72 hours.
A final report will be required 14 days after corrective or mitigating measures are available and within one month for severe incidents. Companies that fail to adhere to the cybersecurity measures may face an administrative fine of up to €15 million ($17.3 million) or 2.5% of worldwide annual turnover, depending on which figure is higher.