Cryptocurrency Wallet Companies Face Strict 24-Hour Deadline Under New EU Cybersecurity Regulations
Under new EU regulations, cryptocurrency wallet companies face mandatory reporting deadlines—24 hours for initial vulnerability alerts and 72 hours for comprehensive notifications following security breaches—with potential penalties reaching up to $17.3 million.

Cryptocurrency wallet manufacturers, including both hardware and software providers, now face a strict 24-hour window from the moment they become aware of actively exploited bugs or critical security flaws to notify authorities within the European Union.
This requirement forms a key component of the EU's Cyber Resilience Act (CRA), which officially came into force on Friday, as confirmed through a statement released by the European Commission.
Under the new framework, manufacturers are obligated to provide an early warning notification for critical vulnerabilities within a 24-hour timeframe, with a comprehensive notification required within 72 hours. Additionally, companies must deliver a final detailed report within 14 days once corrective actions or mitigation strategies become available, and no later than one month following severe security incidents.
According to the EC, these newly implemented reporting obligations are designed to enhance protection for both individual consumers and business entities against evolving cyber threats. The requirements apply universally to all products "with digital elements made available in the EU" and represent an expansion of the EU's comprehensive cybersecurity framework.
Cointelegraph has reached out to the European Commission seeking additional clarification and details regarding these cybersecurity regulations.
Fines could reach $17 million
Organizations that fail to comply with the cybersecurity requirements outlined in Articles 13 and 14 could be subject to administrative penalties reaching as high as 15 million euros ($17.3 million) or 2.5% of their total worldwide annual revenue, whichever amount proves to be greater, as specified in the penalties section outlined in the final legislative draft.
Additionally, companies that provide incorrect, incomplete or misleading information face administrative fines of up to 5 million euros.

These regulatory measures come to light just weeks following incidents where two widely-used hardware wallet manufacturers disclosed security breaches involving user data that could potentially expose customers to phishing attacks or social engineering schemes.
On Sept. 4, Trezor, a prominent hardware wallet manufacturer, disclosed that an additional 67,000 customers in the United States were potentially affected by a data breach that occurred at ShipMonk, its shipping service provider, significantly surpassing the original estimate of 14,000 affected users.
On Wednesday, both Trezor and BitBox issued warnings to their user bases regarding fraudulent phishing emails masquerading as critical security alerts following suspected security compromises involving third-party email service providers.
In June, Zilliqa, a Layer-1 blockchain network, issued an alert about a security flaw in the Zilliqa Ledger app that could potentially enable malicious actors to extract users' private keys by utilizing publicly accessible onchain data.
Cointelegraph has contacted wallet manufacturers Trezor and Ledger requesting their comments on how cryptocurrency wallet providers plan to meet compliance with these new mandatory reporting requirements.