Newsroom
14 September, 2026 / News / AI / Tags: manufacturers, european, cyber, reporting, severe

The Cyber Resilience Act now requires manufacturers of hardware and software wallets sold in the European Union to notify authorities of severe vulnerabilities within 24 hours of detection, with penalties reaching $17.3 million for non-compliance
The European Union has activated strict cybersecurity reporting requirements for companies that develop and supply cryptocurrency hardware and software wallets. The rules form part of the Cyber Resilience Act, which took effect on September 11, 2026, according to the European Commission. The legislation applies to products with digital elements placed on the EU market, including connected hardware wallets and downloadable wallet applications whose intended use involves data connections.
Manufacturers must submit an early warning to authorities as soon as they become aware of an actively exploited vulnerability or a serious security incident. The initial alert is due no later than 24 hours after detection. A more detailed notification must follow within 72 hours. A final report is required within 14 days after corrective or mitigating measures become available, or within one month for the most severe incidents.
Reports are filed through a Single Reporting Platform operated by the EU Agency for Cybersecurity. The platform distributes the information to relevant national incident response teams. The early warning must identify the member states where the affected product has been made available and, in serious cases, note any suspicion of foul play. The 72-hour filing requires additional product details, exploit information, and descriptions of ongoing fixes or mitigations. Where necessary, manufacturers must also inform affected users directly.
Failure to meet the reporting duties set out in Articles 13 and 14 of the act can result in administrative fines of up to 15 million euros, equivalent to $17.3 million, or 2.5 percent of the company’s worldwide annual turnover, whichever amount is higher. Providing incorrect, incomplete, or misleading information about security incidents carries an additional fine of up to 5 million euros, or approximately $5.8 million.
| Violation | Maximum Penalty |
|---|---|
| Failure to report severe vulnerabilities | $17.3 million or 2.5% of worldwide annual turnover |
| Supplying incorrect, incomplete, or misleading information | Approximately $5.8 million |
The timing of the new rules follows several high-profile incidents involving hardware wallet providers. On September 4, 2026, Trezor disclosed that a data breach at its shipping partner ShipMonk had placed 67,000 United States customers at risk, a figure substantially higher than the earlier estimate of 14,000 users. Shortly afterward, both Trezor and BitBox issued warnings to customers about phishing emails that impersonated urgent security notices, linked to suspected compromises of third-party email services.
In June 2026, the Layer-1 blockchain network Zilliqa publicly alerted users to a critical vulnerability in its Ledger application. The flaw could have allowed attackers to recover private keys by using publicly available on-chain data. These events have raised concerns about phishing, social engineering, and the exposure of sensitive user information.
The reporting obligations already apply to qualifying products that were sold in the European Union before the broader framework becomes mandatory. Commercially distributed open-source wallet software can fall within scope, although non-monetized projects and individual contributors outside direct commercial responsibility receive different treatment. Dedicated reporting duties for open-source stewards begin in December 2027.
The full set of Cyber Resilience Act requirements, including secure-by-design obligations, product lifecycle duties, and CE marking, will become mandatory on December 11, 2027. Technical standards supporting the law are expected in October and December 2026. The European Commission has stated that the rapid notification rules are intended to strengthen protection for consumers and businesses against cyber threats across all products with digital elements marketed in the EU.
Wallet providers operating or selling products within the European Union are now subject to these accelerated disclosure timelines. Industry participants such as Trezor and Ledger have been contacted for information on their compliance plans.









