- The EU now requires wallet providers to file an early warning within 24 hours of awareness of severe exploited vulnerabilities.
- A full notification is due within 72 hours and fines can reach $17.3 million or 2.5% of annual turnover.
EU wallet rules are tightening reporting duties for cryptocurrency hardware and software wallet providers in the region. Under the European Union’s Cyber Resilience Act, companies must report actively exploited bugs or severe security vulnerabilities affecting their products within 24 hours of becoming aware of them. The framework, which the European Commission said took effect on Friday, also sets a 72-hour deadline for a full notification and later follow-up reports. The EU said the measures are meant to improve protection for consumers and businesses from cyber threats and apply to products with digital elements made available in the bloc.
EU wallet rules under the Cyber Resilience Act
The reporting timetable comes from the EU’s Cyber Resilience Act, referred to as the CRA in the announcement from the European Commission. The measure covers cryptocurrency wallet manufacturers as part of a broader set of obligations for products with digital elements made available in the EU.
According to the new requirements, firms must send an early warning within 24 hours for severe vulnerabilities. After that, a full notification must be filed within 72 hours. The reporting sequence does not end there, because a final report is also required 14 days after corrective or mitigating measures become available and within one month for severe incidents.
Reporting deadlines and penalties
The European Commission said the new framework is designed to better protect consumers and businesses from cyber threats. For wallet providers, that means a short clock starts once they become aware of a severe issue or an actively exploited bug affecting their products.
The penalties listed in the final draft are significant. Companies that fail to comply with the cybersecurity measures under Articles 13 and 14 may face an administrative fine of up to 15 million euros, equal to $17.3 million, or 2.5% of worldwide annual turnover, depending on which amount is higher. Providing incorrect, incomplete or misleading information can also bring an administrative fine of up to 5 million euros.
Recent incidents tied to EU wallet rules
The timing of the EU wallet rules comes weeks after security incidents involving well-known hardware wallet providers. The report said two popular hardware wallet companies disclosed user data breaches that could expose users to phishing or social engineering attempts.
On Sept. 4, Trezor said an additional 67,000 US customers were at risk from the data breach involving its shipping provider ShipMonk. That revised figure was above the initial estimate of 14,000 users. On Wednesday, Trezor and BitBox also warned users about phishing emails presented as urgent security notices after suspected compromises tied to third-party email services.
Wallet vulnerabilities beyond data breaches
The source also pointed to a separate issue disclosed earlier in the year. In June, Layer-1 blockchain network Zilliqa said a vulnerability in the Zilliqa Ledger app could let attackers recover users’ private keys using publicly available onchain data.
Cointelegraph said it approached the European Commission for more detail on the cybersecurity measures. It also said it contacted wallet makers Trezor and Ledger for comment on how wallet providers would comply with the new reporting requirements.
Conclusion
EU wallet rules set a strict sequence for reporting serious security issues affecting crypto wallet products in the bloc. Providers must submit an early warning within 24 hours of awareness, a full notification within 72 hours, and follow-up reporting after corrective or mitigating steps are available. The framework took effect on Friday as part of the Cyber Resilience Act and applies to products with digital elements made available in the EU. With fines reaching 15 million euros, or $17.3 million, and potentially 2.5% of worldwide annual turnover, the measure adds meaningful compliance pressure as wallet providers face continued scrutiny after recent breach and phishing incidents.
Disclaimer
The information provided in this article is for informational purposes only and should not be considered financial advice. The article does not offer sufficient information to make investment decisions, nor does it constitute an offer, recommendation, or solicitation to buy or sell any financial instrument. The content is opinion of the author and does not reflect any view or suggestion or any kind of advise from CryptoNewsBytes.com. The author declares he does not hold any of the above mentioned tokens or received any incentive from any company.
Featured image created by AI

