EU Imposes 24-Hour Exploit Disclosure on Crypto Wallet Makers
The European Union's Cyber Resilience Act has imposed a new requirement on crypto wallet manufacturers to disclose exploited vulnerabilities within 24 hours. Article 14 of the regulation, which took effect on September 11, 2026, requires makers of products with digital elements, including hardware wallets and commercial wallet software, to submit an early warning notification to ENISA and the designated CSIRT through a single reporting platform.
The obligation is part of a broader cybersecurity rule for connected hardware and software, which will become fully applicable in December 2027. The fast-track rules also apply to severe incidents affecting product security, with a fuller vulnerability notification due within 72 hours and a final report required within 14 days of a corrective or mitigating measure becoming available.
The new deadline has been triggered by recent high-profile wallet security failures, including attacks on hardware wallet maker Coldcard and a data breach at Trezor. Under the EU regime, manufacturers now have a legal duty to disclose exploited vulnerabilities within a day, rather than controlling the disclosure timeline itself.