EU Cyber Resilience Act Imposes Immediate Reporting Duty on Cryptocurrency Wallet Manufacturers
The European Union's Cyber Resilience Act has introduced a new duty for manufacturers of digital products, including cryptocurrency wallets. Since September 11, 2026, any product with digital elements made available commercially on the EU market must report actively exploited vulnerabilities to competent bodies within 24 hours and inform affected users.
The regulation applies to products whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. This includes hardware wallets, which are physical devices with firmware that communicate with companion software over USB, Bluetooth, or QR code.
Article 14 of the EU Cyber Resilience Act requires manufacturers to report vulnerabilities and severe security incidents to designated Computer Security Incident Response Teams (CSIRT) and the European Union Agency for Cybersecurity (ENISA). The regulation defines an actively exploited vulnerability as a known security flaw used by attackers, not just theoretical gaps discovered in laboratories.
The reporting duty is immediate, with deadlines of 24 hours for early warning, 72 hours for vulnerability notification, and 14 days for the final report. For severe security incidents, the final report is due one month after the 72-hour notification. The regulation does not name specific wallet brands or products but applies to any product meeting the defined criteria.