EU Crypto Wallet Makers Face 24-Hour Reporting Deadline for Exploits
The European Union has introduced a new regulation for crypto wallet makers to report exploited vulnerabilities and severe security incidents within 24 hours. This rule applies to products sold in Europe, including commercial hardware wallets and desktop or mobile wallet applications.
The regulation, part of the EU's Cyber Resilience Act (CRA), requires manufacturers to submit an early warning to authorities and affected markets within 24 hours after becoming aware of an actively exploited vulnerability. This notification must indicate the Member States where the product has been made available.
A more detailed report is due within 72 hours, including information about the product, exploit, and corrective measures taken. The final report on exploited vulnerabilities is submitted within 14 days, while severe incident reports are required within one month.