mt logoMyToken
ETH Gas
EN

EU Cyber Resilience Act Imposes 24-Hour Exploit Disclosure on Crypto Wallet Makers

europe main2

Crypto wallet manufacturers now have just 24 hours to alert European regulators when a vulnerability in one of their products is actively exploited. The obligation comes from Article 14 of the European Union’s Cyber Resilience Act (CRA), the bloc’s flagship cybersecurity rule for connected hardware and software, whose incident-reporting provisions took effect on September 11, 2026 — more than a year before the regulation’s broader security requirements become applicable in December 2027.

What the 24-Hour Deadline Requires

Article 14 of the Cyber Resilience Act covers manufacturers of “products with digital elements” — a category that sweeps in hardware wallets and commercial wallet software because such products connect to devices and networks. When a maker learns that a vulnerability is being actively exploited, it must submit an early warning notification to the EU’s cybersecurity agency ENISA and the designated computer security incident response team (CSIRT) through a single reporting platform within 24 hours. A fuller vulnerability notification follows within 72 hours, and a final report is due within 14 days of a corrective or mitigating measure becoming available. The same fast-track rules apply to severe incidents affecting product security.

Why the Timing Matters for Crypto

The deadline lands amid a series of high-profile wallet security failures. Hardware wallet maker Coldcard has spent recent weeks responding to attacks that drained Bitcoin from its devices, and its wave three exploiter has since moved funds through CoinJoin . Trezor, meanwhile, disclosed a ShipMonk data breach affecting thousands of US customers. Under the new EU regime, a manufacturer that discovers its firmware has been exploited must now alert regulators within a day rather than controlling the disclosure timeline itself. For an industry that has historically announced fixes on its own schedule, the requirement turns disclosure from a discretionary choice into a legal duty.

Compliance Timeline and the Fine Print

The September 11 date applies only to the CRA’s vulnerability and incident-reporting obligations. The regulation’s wider duties — security-by-design, conformity assessment and CE marking — do not apply until December 11, 2027. The regime also builds in relief for smaller firms: administrative fines do not apply to microenterprises and small enterprises that miss the 24-hour early-warning deadline, although the reporting obligation itself still stands. Once the broader framework is in force, non-compliance can draw enforcement action from national market surveillance authorities.

Disclaimer: This article is copyrighted by the original author and does not represent MyToken’s views and positions. If you have any questions regarding content or copyright, please contact us.(www.mytokencap.com)contact
More exciting content is available on
X(https://x.com/MyTokencap)
or join the community to learn more:MyToken-English Telegram Group
https://t.me/mytokenGroup