EU Puts Crypto Wallet Makers on 24-Hour Breach Reporting Clock
Published October 6, 2026, 10:15 UTC. Based on a European Commission announcement on the Cyber Resilience Act and reporting by Cointelegraph.
Cryptocurrency hardware and software wallet providers now have 24 hours from becoming aware of an actively exploited vulnerability to warn European authorities, under reporting duties in the EU’s Cyber Resilience Act (CRA) that took effect on Friday, October 2. The rules cover all products “with digital elements made available in the EU,” according to a European Commission announcement reported by Cointelegraph.
The 24-hour clock
Manufacturers must file an early warning within 24 hours of discovering a severe or actively exploited vulnerability, followed by a full notification within 72 hours, according to the Commission’s announcement. A final report is due within 14 days after corrective or mitigating measures are available, and within one month for severe incidents. The Commission said the rules aim to better protect consumers and businesses from cyber threats as part of the EU’s broader cybersecurity strategy.
Fines up to 15 million euros
Companies that fail to meet the reporting obligations under Articles 13 and 14 of the Act face administrative fines of up to 15 million euros (about $17.3 million) or 2.5% of worldwide annual turnover, whichever is higher, according to the Act’s penalties text. Supplying incorrect, incomplete, or misleading information carries fines of up to 5 million euros. For wallet makers such as Ledger and Trezor, the rules mean running incident-response operations that can detect, assess, and report an actively exploited flaw to EU authorities within a single day.
The breaches behind the timing
The new duties arrive weeks after disclosures from two popular hardware wallet makers. On September 4, Trezor said an additional 67,000 U.S. customers were at risk from a data breach at its shipping provider, ShipMonk, well above the initially estimated 14,000 users, according to Cointelegraph. Trezor and BitBox later warned users about phishing emails disguised as urgent security notices after suspected compromises at third-party email services. In June, the Zilliqa network warned that a vulnerability in its Ledger app could have let attackers recover users’ private keys using publicly available onchain data. Cointelegraph said it has approached the Commission for more details, and has asked Trezor and Ledger for comment on how they plan to comply.
This article is news reporting and is not investment advice.
Sources
- European Commission, Cyber Resilience Act vulnerability reporting obligations (announced Oct. 2, 2026), primary source
- Cointelegraph, EU Cyber Rules Put Crypto Wallet Makers on 24-hour Reporting Clock (Oct. 6, 2026)
MABOnChain Daily Brief
The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.
Prefer chat? Join us on Telegram
Keep reading
FinCEN Scraps Plan to Track Crypto Sent to Personal Wallets
FinCEN withdrew a 2020 proposal requiring banks to report transfers to self-custodied wallets over $10,000 and a 2023 proposal targeting crypto mixers.
CFTC Seeks Comment on Federal Rules for Crypto Exchanges
The CFTC published an early notice on Regulation CTX and Regulation CAM, a possible federal license for crypto trading with leverage. Nothing is final yet.
NEAR Intents Says Full $3.8M Recovered After Exploit
The cross-chain swap service paused after a $3.8M exploit on Oct. 1. The attacker returned the funds after a 48-hour ultimatum, NEAR Intents says.


