EU Gives Crypto Wallet Providers 24-Hour Window to Report Exploits
The European Union has introduced new regulations requiring cryptocurrency wallet providers to report actively exploited vulnerabilities within 24 hours. This is part of the Cyber Resilience Act (CRA), which came into effect on September 11, 2026.
Under the CRA, manufacturers must submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe security incident affecting a covered product. A more detailed notification is then required within 72 hours.
The financial consequences for non-compliance can be significant, with administrative fines of up to €15 million ($17.3 million) or 2.5% of a company's total worldwide annual turnover from the preceding financial year.