EU cybersecurity rules require crypto wallet makers’ 24-hour reporting

The European Union has moved to tighten cybersecurity oversight for crypto wallet technology by requiring hardware and software wallet providers to report actively exploited bugs and severe vulnerabilities on very short timelines. The European Commission says the requirement takes effect under the EU’s Cyber Resilience Act (CRA), which entered into force on Friday. Under the framework, affected providers must issue an early warning within 24 hours after becoming aware of certain security problems, then submit broader notifications within set deadlines. The rules apply to digital products made available in the EU, aiming to reduce the window in which consumers and businesses can be exposed to real-world attacks. Key takeaways Wallet providers must report severe vulnerabilities that are actively exploited within 24 hours, with fuller updates due later. After corrective or mitigating measures are available, a final report is expected within 14 days; severe incidents may require updates within one month. The EU’s CRA introduces potential administrative penalties of up to €15 million (about $17.3 million) or 2.5% of worldwide annual turnover, whichever is higher. Supplying incorrect or misleading information to regulators can trigger additional fines of up to €5 million. The announcement arrives amid recent wallet-related incidents and vulnerability disclosures that highlight the speed at which threats can spread. What the CRA requires after a serious vulnerability is found According to an announcement from the European Commission, the CRA’s reporting obligations are designed for fast-moving threats—particularly those already in use by attackers. The measure requires manufacturers of in-scope products to notify authorities when they are aware of “actively exploited” security weaknesses or “severe security vulnerabilities” impacting their offerings. The timeline described by the Commission includes three main checkpoints: an early warning within 24 hours, a complete notification within 72 hours, and a final report after mitigations or corrections become available. The final reporting window is set at 14 days after corrective or mitigating measures are available. For severe incidents, the Commission also references a requirement to report within one month. While the CRA is broader than crypto alone, the practical impact for the market is significant because many wallet products involve tightly coupled components—secure elements, wallet software, update systems, and integrations with user interfaces. In such systems, vulnerabilities can quickly translate into phishing campaigns, social engineering, or compromise of signing workflows. How penalties could scale for non-compliance The Commission’s initiative is backed by enforcement measures. The penalties section of the CRA draft, referenced via the European Cyber Resilience Act article archive, states that companies failing to comply with requirements under Articles 13 and 14 may face an administrative fine of up to €15 million (approximately $17.3 million) or 2.5% of worldwide annual turnover, depending on which is higher. There is also a separate risk for poor quality reporting.
عنوان اصلی (انگلیسی): EU cybersecurity rules require crypto wallet makers’ 24-hour reporting
مشاهدهی خبر کامل در منبع ↗ بازگشت به Zilliqaاین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.