EU Cyber Resilience Act Imposes 24-Hour Reporting Deadline for Crypto Wallet Vulnerabilities
The European Union's Cyber Resilience Act has taken effect, introducing new reporting duties for manufacturers of commercial connected hardware wallets and wallet software.
The law requires these manufacturers to alert European cybersecurity authorities within 24 hours of discovering an actively exploited vulnerability or a serious security incident. This includes sending an early warning with information about the affected product and member states where it has been received.
Within 72 hours, manufacturers must provide more detailed information, including product details, exploit information, and mitigation steps underway for vulnerabilities.
The EU Cyber Resilience Act does not specifically target digital assets but applies to products with data connections, making commercial connected hardware wallets and downloadable wallet apps within its scope.