EU Gives Crypto Wallet Makers Just 24 Hours to Report Hacks

iEXExchanger
EU Gives Crypto Wallet Makers Just 24 Hours to Report Hacks

A new EU rule took effect this week: makers of crypto wallets must now alert regulators within 24 hours of an actively exploited flaw, ending weeks of silent patching while users lose funds.

As of September 11, crypto wallet makers selling into the European Union are operating under a new clock. If a hardware device or wallet app suffers an actively exploited vulnerability, the manufacturer now has 24 hours to tell regulators — not weeks, not months, twenty-four hours.

The requirement comes from the EU's Cyber Resilience Act, a broad product-security law that until now was mostly discussed in the context of smart home gadgets and industrial software. It now explicitly covers network-connected wallets — both hardware devices and downloadable apps — sold on the EU market. The reporting works in three steps: an early warning within 24 hours flagging that a flaw is being actively exploited, a full notification within 72 hours detailing the product, the attack, and any mitigation, and a final report either 14 days after a fix ships or one month after a serious incident is confirmed. Everything routes through a single platform run by ENISA, the EU's cybersecurity agency.

Before this, wallet makers largely decided for themselves whether — and when — to admit publicly that something had been breached. In practice, that often meant weeks of quiet patching while users kept losing funds to a bug nobody outside the company knew about. The new timeline is aimed squarely at that gap between discovery and disclosure.

The rule didn't appear out of nowhere. Over the past year, wallet holders have run into bugs that sat unnoticed for years — from firmware flaws in hardware devices to app-level vulnerabilities that let attackers drain funds. For smaller wallet developers, the new obligation means building out incident-monitoring processes and legal readiness to respond in hours rather than weeks.

Penalties for non-compliance aren't yet spelled out in public reporting, and the bulk of the CRA's product-security requirements don't kick in until December 2027. But the direction is clear: in Europe, staying quiet about a wallet hack is no longer an option.

Questions and answers

Frequently asked questions about this article

What is this law and when did it take effect?

It's the EU's Cyber Resilience Act, a broad law on digital product security. The 24-hour rule for reporting actively exploited wallet vulnerabilities took effect on September 11, 2026.

Who exactly does the new rule apply to?

Commercial makers of network-connected wallets sold in the EU — both hardware devices and downloadable wallet apps.

What has to happen within the first 24 hours?

The manufacturer must send an early warning to ENISA through the single reporting platform, flagging that a vulnerability is being actively exploited and in which EU countries.

What happens after that first notification?

Within 72 hours, the maker must submit full details on the vulnerability and mitigation steps. A final report follows 14 days after a patch ships, or one month after a serious incident is confirmed.

Why did regulators set these specific deadlines?

To close the gap between discovering a flaw and attackers exploiting it — previously, makers decided on their own whether and when to admit a breach publicly.