Crypto wallet creators now have just 24 hours to alert regulators when flaws are exploited
Commercial manufacturers whose connected hardware wallets or wallet software meet the European Union's product test must now warn cyber authorities within 24 hours of discovering an actively exploited vulnerability or se...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Commercial manufacturers whose connected hardware wallets or wallet software meet the European Union's product test must now warn cyber authorities within 24 hours of discovering an actively exploited vulnerability or severe security incident.
The requirement took effect Sept. 11, 2026, under the EU's Cyber Resilience Act, or CRA. The European Commission's reporting guidance says the clock applies to manufacturers of products with digital elements.
The CRA is a horizontal product law. The Commission's implementation FAQ says it applies to hardware and software made available on the EU market. The legal test also requires the product's intended or reasonably foreseeable use to include a direct or indirect data connection to a device or network.
A commercially supplied connected hardware wallet or downloadable wallet app can meet that test. However, EU guidance does not name wallet brands or declare every wallet service or project covered. Coverage depends on the specific product, how it is supplied and any applicable exclusion.
Related Reading SafePal breach exposes 40,000 customers as hardware wallet attacks escalate from data leaks to $100 million theft What manufacturers must reportThe first filing is an early warning due without undue delay and no later than 24 hours after a manufacturer becomes aware of the vulnerability or incident. It must indicate, where applicable, the member states where the product is known to have been made available. For a severe incident, the warning must also say whether unlawful or malicious acts are suspected.
A fuller notification is due within 72 hours unless the relevant information was already provided. For an actively exploited vulnerability, that filing adds general information about the product, exploit and vulnerability, plus corrective or mitigating measures. For a severe incident, it adds the nature of the incident, an initial assessment and available mitigation information.
Related Reading Zilliqa points to hardware wallet flaw discarding entropy to expose crypto keys, enabling 683M ZIL theftThe final deadline differs by event. A vulnerability report is due no later than 14 days after a corrective or mitigating measure becomes available. The CRA sets the severe-incident final report deadline at one month after the 72-hour notification, as detailed in the regulation.
Manufacturers file once through the Single Reporting Platform launched by ENISA, the EU cybersecurity agency. The portal sends the notification to the designated coordinating Computer Security Incident Response Team and makes the information available to ENISA, then supports distribution to other relevant national teams. Manufacturers must also inform impacted users and, where appropriate, all users when action is needed, including measures they can take.
Related Reading No dice? Your Bitcoin hardware wallet is probably not as secure as you thought it wasThe reporting rule reaches in-scope products placed on the market before Dec. 11, 2027. That makes the new clock relevant to existing product lines, not only wallets first sold after the broader law takes effect.
Open-source licensing does not create a blanket exemption. The Commission's open-source guidance says commercially supplied free and open-source products can face manufacturer obligations. Non-monetized software supplied by its manufacturer should not count as commercial activity, while individual contributors are not treated as manufacturers for software outside their responsibility.
Open-source software stewards are a separate legal category, and their reporting duties begin Dec. 11, 2027. That is also when the CRA's main product-security requirements take effect. The Sept. 11 change starts the rapid reporting regime, not the law's broader secure-design and product-lifecycle framework.
The post Crypto wallet creators now have just 24 hours to alert regulators when flaws are exploited appeared first on CryptoSlate.
Why this matters
Bitcoin is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on CryptoSlateRelated market context
S&P brings ratings-style scrutiny to $10 billion crypto vault market as $6 million Base incident exposes risks
S&P Global is bringing ratings-style risk assessments to crypto lending vaults as the fast-growing market confronts fresh security...
OKX Eyes 63 U.S. Stocks in Major Tokenized Trading Expansion
Key Takeaways: OKXICE informed the SEC about its plan to establish an online platform called “Tokenized Securities Venue” that wou...
Abstract to Shut Down Dec. 15 After Consumer Crypto Model Fails to Scale
Key Takeaways: Abstract will close on 15th December, 2026, and users will have to move assets off the network before the time. The...
Europol warns crypto wallets are the weak spot for future quantum attacks
The crypto industry must urgently adopt quantum-resistant cryptography to prevent future vulnerabilities and secure digital assets...
Bitcoin Drops Under $84,000 as $487 Million in Leveraged Longs Get Liquidated in 24 Hours
Bitcoin fell below $84,000 late Tuesday as traders holding leveraged long positions were forced out of their trades. Coinbase exch...
Cardano News: CIP-0113 Upgrade Could Change ADA Future
Good news coming from The Cardano Foundation as it launched CIP-0113 on mainnet, giving issuers of regulated stablecoins, funds, a...