2026-09-14 CoinTelegraph

EU Cyber Resilience Act: Crypto Wallet Makers Must Report Exploits Within 24 Hours

Cryptocurrency hardware and software wallet providers operating in the EU must now report actively exploited vulnerabilities within 24 hours of discovery, under the European Union's Cyber Resilience Act (CRA), which took effect on Friday. The regulation requires manufacturers to submit an early warning for severe vulnerabilities within 24 hours, followed by a full notification within 72 hours. A final report must then be filed 14 days after corrective or mitigating measures are available, and within one month for severe incidents.

Companies that fail to comply with Articles 13 and 14 of the CRA face administrative fines of up to 15 million euros ($17.3 million) or 2.5% of worldwide annual turnover, whichever is higher. Supplying incorrect, incomplete, or misleading information carries a separate fine of up to 5 million euros. The measures extend to all products "with digital elements" made available in the EU market, reinforcing the bloc's broader cybersecurity strategy.

The new requirements come weeks after significant security incidents affected major hardware wallet providers. On September 4, Trezor disclosed that an additional 67,000 U.S. customers were exposed through a data breach involving shipping provider ShipMonk—far exceeding the initially estimated 14,000 affected users. Earlier this week, both Trezor and BitBox warned users about phishing emails disguised as urgent security notices following suspected compromises of third-party email services. In June, Zilliqa also alerted users that a vulnerability in the Zilliqa Ledger app could allow attackers to recover private keys from publicly available onchain data. The European Commission stated the rules aim to better protect consumers and businesses from escalating cyber threats targeting the crypto sector.

Read Full Article at CoinTelegraph →

Related Tool

Find Your ID

Try Now →
Check My ID