Cyber Resilience Act Gives Crypto Wallets 24 Hours to Report Hacks

The Cyber Resilience Act puts EU-facing crypto wallet makers on a fixed vulnerability-reporting clock. An exploited flaw must reach ENISA in 24 hours, with a full report in 14 days and fines up to €15 million. In 2026 only 11% of losses at audited projects came from smart-contract code. Most crypto money left through stolen keys and infrastructure, not the flaws the CRA targets. The European Union switched on the reporting duties of its Cyber Resilience Act this month, and for crypto the timing is almost ironic. Wallet makers now have 24 hours to tell Brussels when a vulnerability in their product is under active exploitation, yet the 2026 data shows that product vulnerabilities are not where the money leaves. The Act drags hardware and software wallet developers into a fixed disclosure schedule backed by fines reaching €15 million, and it does so in the same year crypto logged its highest-ever hack count while the thefts themselves walked around the code the regulation is built to police. 24 hours to ENISA, 14 days to explain, €15 million if you are late The regime hangs on three fixed points, each triggered when a manufacturer discovers an actively exploited vulnerability or a severe incident. An early warning goes to ENISA, the European Union Agency for Cybersecurity, within 24 hours. A detailed notification carrying mitigation steps follows at 72 hours. The full post-mortem, naming the root flaw and its fix, is due 14 days after discovery. Miss any of them and the penalty runs up to €15 million or 2.5% of global annual turnover, whichever is larger, which for a firm with €500 million in annual turnover reaches €12.5 million on the percentage alone. Micro and small enterprises get relief from the strict 24-hour early-warning deadline, but most venture-backed wallet firms will not qualify. WindowWhat must be filedDeadlineEarly warningNotice to ENISA that an exploited flaw or severe incident exists24 hoursNotificationDetailed update with mitigation steps and initial impact72 hoursFinal reportRoot-cause post-mortem and resolution14 days How a hardware wallet ended up under product-safety law The Act never names crypto. It governs any product with digital elements, meaning anything that ships with software or firmware and connects to a device or a network. A signing device with firmware and a companion app fits the definition without argument, and a browser-extension or mobile wallet counts as standalone software with a security function, a category the regulation watches more closely. Exchanges and custodians stay largely with MiCA, but the tools that hold private keys now answer to product law, and that line is what routes wallet teams to ENISA.
عنوان اصلی (انگلیسی): Cyber Resilience Act Gives Crypto Wallets 24 Hours to Report Hacks
مشاهدهی خبر کامل در منبع ↗ بازگشت به Driftاین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.