EU requires crypto wallet makers to report hacks in 24 hours
Under the EU Cyber Resilience Act, hardware and software crypto wallet makers must report actively exploited bugs or severe vulnerabilities within 24 hours of becoming aware.
The European Union’s Cyber Resilience Act requires hardware and software crypto wallet makers to notify authorities of actively exploited bugs or severe security vulnerabilities within 24 hours of becoming aware. The requirement took effect on Friday, the European Commission announced.
Manufacturers must file an initial early warning within 24 hours, a full notification within 72 hours, and a final report 14 days after corrective or mitigating measures are available. For the most serious incidents, the final report must arrive within one month. These deadlines are set out in Articles 13 and 14 of the Act and apply to products with digital elements made available in the EU.
The European Commission said the timelines are intended to improve protection for consumers and businesses and to strengthen cybersecurity for connected products on the EU market. The law covers manufacturers and suppliers of devices and apps that contain or rely on digital components, which includes many wallet makers that sell or distribute in the EU.
Companies that breach the reporting obligations face administrative fines of up to 15 million euros or 2.5% of worldwide annual turnover, whichever is higher. Providing incorrect, incomplete or misleading information can trigger fines of up to 5 million euros.
Regulators set the accelerated notifications to reduce the time between discovery and a coordinated response by makers, national authorities and other stakeholders. The requirement applies to vulnerabilities that are actively exploited and to severe weaknesses that could lead to immediate loss for users.
Recent incidents informed the policy push. One hardware wallet provider disclosed that a breach at its shipping partner exposed tens of thousands of U.S. customers’ records, a figure that was later revised upward from initial estimates. Two wallet vendors warned users about phishing emails that mimicked urgent security notices after suspected compromises at third-party email services. A Layer-1 blockchain team reported a vulnerability in a Ledger app that could allow attackers to recover private keys from on-chain data.
Under the Act, manufacturers must create internal processes to detect and report severe incidents quickly and to prepare required documentation on the timelines set by law. The reporting framework is designed to support coordinated containment of active threats between vendors and authorities.
Companies operating in the EU should review vulnerability management and incident response procedures to ensure they can meet the 24-hour early-warning and 72-hour full-notification deadlines. Failure to provide timely and accurate reports exposes firms to enforcement actions and financial penalties under the new rules.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








