EU Imposes 24-Hour Security Warning Rule on Crypto Wallet Firms
The European Union has introduced new regulations requiring crypto wallet companies to report serious security vulnerabilities within 24 hours of becoming aware of them. The rules, which took effect on September 11, impose fines of up to 15 million euros for noncompliance.
The move comes after a series of security incidents and vulnerability warnings involving Trezor, BitBox, and Zilliqa. These incidents included a data breach at shipping contractor ShipMonk that left 67,000 U.S. customers exposed to additional risk.
Under the Cyber Resilience Act (CRA), crypto wallet makers offering products in the EU must submit an early warning within 24 hours if they discover a vulnerability being actively exploited or another serious security issue. They must then file a formal report within 72 hours, and follow-up reports are required after fixing the issue.
Violations of these rules can trigger steep penalties, including fines of as much as 15 million euros ($17.3 million) or 2.5% of global annual revenue, whichever is higher.