Newsroom

EU Imposes 24-Hour Security Flaw Reporting Rules on Crypto Wallet Providers

14 September, 2026   /   News   /  AI   /   Tags:  manufacturers, european, cyber, reporting, severe

EU Imposes 24-Hour Security Flaw Reporting Rules on Crypto Wallet Providers

The Cyber Resilience Act now requires manufacturers of hardware and software wallets sold in the European Union to notify authorities of severe vulnerabilities within 24 hours of detection, with penalties reaching $17.3 million for non-compliance

New Obligations Under the Cyber Resilience Act

The European Union has activated strict cybersecurity reporting requirements for companies that develop and supply cryptocurrency hardware and software wallets. The rules form part of the Cyber Resilience Act, which took effect on September 11, 2026, according to the European Commission. The legislation applies to products with digital elements placed on the EU market, including connected hardware wallets and downloadable wallet applications whose intended use involves data connections.

Manufacturers must submit an early warning to authorities as soon as they become aware of an actively exploited vulnerability or a serious security incident. The initial alert is due no later than 24 hours after detection. A more detailed notification must follow within 72 hours. A final report is required within 14 days after corrective or mitigating measures become available, or within one month for the most severe incidents.

Reports are filed through a Single Reporting Platform operated by the EU Agency for Cybersecurity. The platform distributes the information to relevant national incident response teams. The early warning must identify the member states where the affected product has been made available and, in serious cases, note any suspicion of foul play. The 72-hour filing requires additional product details, exploit information, and descriptions of ongoing fixes or mitigations. Where necessary, manufacturers must also inform affected users directly.

Manufacturers must issue an early warning about severe vulnerabilities within 24 hours, followed by a comprehensive notification within 72 hours, and deliver a final report as soon as corrective action is available.
European Commission guidance on the Cyber Resilience Act

Penalties for Non-Compliance

Failure to meet the reporting duties set out in Articles 13 and 14 of the act can result in administrative fines of up to 15 million euros, equivalent to $17.3 million, or 2.5 percent of the company’s worldwide annual turnover, whichever amount is higher. Providing incorrect, incomplete, or misleading information about security incidents carries an additional fine of up to 5 million euros, or approximately $5.8 million.

ViolationMaximum Penalty
Failure to report severe vulnerabilities$17.3 million or 2.5% of worldwide annual turnover
Supplying incorrect, incomplete, or misleading informationApproximately $5.8 million

Recent Security Incidents in the Wallet Sector

The timing of the new rules follows several high-profile incidents involving hardware wallet providers. On September 4, 2026, Trezor disclosed that a data breach at its shipping partner ShipMonk had placed 67,000 United States customers at risk, a figure substantially higher than the earlier estimate of 14,000 users. Shortly afterward, both Trezor and BitBox issued warnings to customers about phishing emails that impersonated urgent security notices, linked to suspected compromises of third-party email services.

In June 2026, the Layer-1 blockchain network Zilliqa publicly alerted users to a critical vulnerability in its Ledger application. The flaw could have allowed attackers to recover private keys by using publicly available on-chain data. These events have raised concerns about phishing, social engineering, and the exposure of sensitive user information.

Scope and Timeline of Full Implementation

The reporting obligations already apply to qualifying products that were sold in the European Union before the broader framework becomes mandatory. Commercially distributed open-source wallet software can fall within scope, although non-monetized projects and individual contributors outside direct commercial responsibility receive different treatment. Dedicated reporting duties for open-source stewards begin in December 2027.

The full set of Cyber Resilience Act requirements, including secure-by-design obligations, product lifecycle duties, and CE marking, will become mandatory on December 11, 2027. Technical standards supporting the law are expected in October and December 2026. The European Commission has stated that the rapid notification rules are intended to strengthen protection for consumers and businesses against cyber threats across all products with digital elements marketed in the EU.

Wallet providers operating or selling products within the European Union are now subject to these accelerated disclosure timelines. Industry participants such as Trezor and Ledger have been contacted for information on their compliance plans.

Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.