EU Slams Cryptocurrency Wallet Providers with 24-Hour Security Reporting Deadline
The European Union has introduced new cyber rules that require cryptocurrency hardware and software wallet providers to report actively exploited bugs or severe security vulnerabilities within 24 hours. This measure is part of the EU's Cyber Resilience Act (CRA), which took effect on Friday, according to an announcement from the European Commission.
Manufacturers must submit an early warning for severe vulnerabilities within 24 hours, followed by a full notification within 72 hours. A final report will be required 14 days after corrective or mitigating measures are available and within one month for severe incidents.
The new reporting requirements aim to better protect consumers and businesses from cyber threats. Companies that fail to adhere to the cybersecurity measures under Articles 13 and 14 may face an administrative fine of up to €15 million (approximately $17.3 million) or 2.5% of worldwide annual turnover, depending on which figure is higher.