EU Imposes 24-Hour Exploit Disclosure Rule for Crypto Wallet Makers
The European Union's Cyber Resilience Act has introduced new requirements for crypto wallet manufacturers to alert regulators within 24 hours when a vulnerability in their products is actively exploited. This obligation applies to all 'products with digital elements' that connect to devices and networks, including hardware wallets and commercial wallet software.
Article 14 of the Cyber Resilience Act, which took effect on September 11, 2026, requires manufacturers to submit an early warning notification to the EU's cybersecurity agency ENISA and the designated computer security incident response team (CSIRT) through a single reporting platform within 24 hours. A fuller vulnerability notification follows within 72 hours, and a final report is due within 14 days of a corrective or mitigating measure becoming available.
The new requirement comes amid recent high-profile wallet security failures, including attacks on hardware wallet maker Coldcard and a data breach affecting thousands of US customers of Trezor. The EU regime now turns disclosure from a discretionary choice into a legal duty for manufacturers, who must alert regulators within a day rather than controlling the disclosure timeline themselves.