Crypto wallet providers selling hardware or software products in the European Union must now alert authorities within 24 hours after identifying a serious security vulnerability or an instance of active exploitation.
The requirement comes under the EU’s Cyber Resilience Act and applies to products with digital elements sold in the bloc, including crypto wallets. Firms that miss the reporting deadlines or provide faulty information can face multimillion-euro penalties.
Early warning and formal report deadlines
Under the new rule, wallet makers must send an initial warning within 24 hours when they discover a vulnerability that is being actively exploited or another serious security issue. That first notice is followed by a formal report due within 72 hours.
The framework also requires additional updates after the initial filing. Providers must submit a final report within 14 days after a fix or mitigation has been implemented. In cases classified as serious security incidents, the deadline for that final report extends to one month.
Fines can reach 15 million euros
The Cyber Resilience Act allows for significant penalties when companies fail to comply. Violations can bring fines of up to 15 million euros or 2.5% of a company’s global annual revenue, whichever amount is higher.
Separate penalties apply when the information submitted to authorities is inaccurate or incomplete. In those cases, the maximum fine can reach 5 million euros.
Scope includes crypto wallets sold in the EU
The reporting obligation is not limited to one niche of the crypto market. It applies broadly to products with digital elements offered in the EU, a category that includes both hardware wallets and software wallets.
That means providers serving the European market are expected to build incident detection and disclosure processes that can meet the bloc’s compressed timelines once a serious issue is identified.
Broader aim of the rule
The EU’s stated purpose is to strengthen protection for consumers and businesses against cyber threats affecting digital products. For crypto wallet providers, the immediate effect is a stricter legal duty to disclose serious flaws and active exploitation quickly to authorities.
The next confirmed step after an early warning is the 72-hour formal report, followed by later updates once mitigation or a fix is in place. How providers handle those deadlines may determine whether they avoid the substantial fines set out in the law.
Source: en.bloomingbit.io