The European Union has introduced strict cybersecurity reporting rules for cryptocurrency hardware and software wallet providers, requiring them to disclose actively exploited vulnerabilities
The European Union has introduced strict cybersecurity reporting rules for cryptocurrency hardware and software wallet providers, requiring them to disclose actively exploited vulnerabilities or critical security bugs within 24 hours of detection.
Cyber Resilience Act targets digital product security
The new reporting obligation is part of the Cyber Resilience Act (CRA), which came into force on Friday as announced by the European Commission. The CRA aims to strengthen cybersecurity across all products with digital elements available in the EU, with a particular focus on devices and software that handle sensitive assets such as cryptocurrency wallets.
Under the new rules, manufacturers and providers must issue an early warning for severe vulnerabilities within 24 hours of becoming aware of an incident. This must be followed by a detailed notification within 72 hours, and a final report is required either 14 days after fixing the vulnerability or within one month for the most serious incidents.
Mini dictionary: Cyber Resilience Act (CRA), a regulation adopted by the European Union to ensure better cybersecurity practices and incident reporting for companies providing digital products and services in the EU market, including those in the crypto industry.
The European Commission stated that these rapid reporting requirements are designed to enhance protection for consumers and businesses operating in the digital economy. The scope of the CRA extends beyond cryptocurrency wallets, covering any digital products marketed within EU member states.
Financial penalties for non-compliance
Companies that fail to meet the reporting obligations set out in Articles 13 and 14 of the CRA could face significant financial consequences. The final draft text specifies that violators may be fined up to 15 million euros ($17.3 million) or 2.5% of their worldwide annual turnover, whichever is higher.
In cases where companies provide incorrect, incomplete, or misleading information related to security incidents, they risk an additional administrative fine of up to 5 million euros.
ViolationMaximum PenaltyFailure to report severe vulnerabilities15 million euros or 2.5% of yearly turnoverSupplying misleading/incomplete info5 million euros
Industry context: Recent security breaches and response
The CRA’s implementation follows several high-profile security incidents within the crypto hardware wallet sector. Just weeks prior, prominent providers had disclosed significant data breaches affecting user information, raising concerns over phishing and social engineering threats.
On September 4, hardware wallet manufacturer Trezor reported that a data breach at its shipping partner, ShipMonk, placed 67,000 US customers at risk, a number far higher than the original estimate of 14,000 users.
Both Trezor and BitBox have recently warned their users about phishing attacks that impersonate urgent security notices, following possible leaks from email service providers. These incidents have underscored the growing risks facing crypto wallet users.
Manufacturers must issue an early warning about severe vulnerabilities within 24 hours, followed by a comprehensive notification within 72 hours, and deliver a final report as soon as corrective action is available.
Earlier in June, Layer-1 blockchain platform Zilliqa alerted the public about a critical vulnerability in the Zilliqa Ledger app that could enable attackers to recover users’ private keys using data stored onchain.
The new EU regulations apply to any wallet provider operating or marketing their products within EU borders. Industry participants, including firms like Trezor and Ledger, are being approached for details on how they plan to align with the updated compliance standards.
The European Commission’s recent cybersecurity measures form part of a broader strategy to address increasing digital threats as more financial transactions and assets migrate to blockchain-based platforms.
The post EU mandates crypto wallet firms to report major security flaws within 24 hours appeared first on COINTURK NEWS.