EU Gives Wallet Makers 24 Hours to Report Flaws
The EU's Cyber Resilience Act now requires in-scope wallet makers to report exploited flaws within 24 hours, a rule that took effect on September 11.
The requirement covers commercial makers of connected hardware wallets and downloadable wallet software placed on the EU market. Beyond the 24-hour alert for an actively exploited vulnerability or serious security incident, manufacturers owe a fuller notification within 72 hours, a final vulnerability report no later than 14 days after a corrective or mitigating measure becomes available, and a final incident report one month after the 72-hour notice. Makers must also inform affected users, and where appropriate all users, about the steps they can take.
These reporting duties are the first CRA obligations to bite, while broader product-security requirements do not apply until December 11, 2027. Wallet providers serving EU users now face disclosure timelines closer to those of regulated financial infrastructure.
Partner Offers | Get Your Instant BTC Cashback | Your Gateway To Crypto | Arcus Private Whitelist