EU Cracks Down on Crypto Wallet Security with Tight Reporting Rules
The European Union has introduced new cybersecurity rules that require crypto wallet makers to report actively exploited bugs and severe vulnerabilities within a tight timeline. According to the EU's Cyber Resilience Act, which took effect on Friday, affected providers must issue an early warning within 24 hours after becoming aware of certain security problems, then submit broader notifications within set deadlines.
The rules apply to digital products made available in the EU and aim to reduce the window in which consumers and businesses can be exposed to real-world attacks. The CRA introduces potential administrative penalties of up to €15 million or 2.5% of worldwide annual turnover, whichever is higher, for non-compliance.
The Commission's initiative is backed by enforcement measures, including a separate risk for poor quality reporting, with an administrative fine of up to €5 million for companies that submit 'incorrect, incomplete or misleading information.'