As of September 11, crypto wallet makers selling into the European Union are operating under a new clock. If a hardware device or wallet app suffers an actively exploited vulnerability, the manufacturer now has 24 hours to tell regulators — not weeks, not months, twenty-four hours.
The requirement comes from the EU's Cyber Resilience Act, a broad product-security law that until now was mostly discussed in the context of smart home gadgets and industrial software. It now explicitly covers network-connected wallets — both hardware devices and downloadable apps — sold on the EU market. The reporting works in three steps: an early warning within 24 hours flagging that a flaw is being actively exploited, a full notification within 72 hours detailing the product, the attack, and any mitigation, and a final report either 14 days after a fix ships or one month after a serious incident is confirmed. Everything routes through a single platform run by ENISA, the EU's cybersecurity agency.
Before this, wallet makers largely decided for themselves whether — and when — to admit publicly that something had been breached. In practice, that often meant weeks of quiet patching while users kept losing funds to a bug nobody outside the company knew about. The new timeline is aimed squarely at that gap between discovery and disclosure.
The rule didn't appear out of nowhere. Over the past year, wallet holders have run into bugs that sat unnoticed for years — from firmware flaws in hardware devices to app-level vulnerabilities that let attackers drain funds. For smaller wallet developers, the new obligation means building out incident-monitoring processes and legal readiness to respond in hours rather than weeks.
Penalties for non-compliance aren't yet spelled out in public reporting, and the bulk of the CRA's product-security requirements don't kick in until December 2027. But the direction is clear: in Europe, staying quiet about a wallet hack is no longer an option.



