MABOnChain
Educational content only. Nothing on this site is financial advice.
Home / Regulation / EU Puts Crypto Wallet Makers on 24-Hour Breach Reporting Clock
Regulation

EU Puts Crypto Wallet Makers on 24-Hour Breach Reporting Clock

By MABOnChain Desk · Published · Updated · 3 min read

Editorial digital-art illustration of a hardware wallet and a smartphone under a translucent blue cybersecurity shield with EU stars, beneath a golden countdown clock over a European cityscape

Published October 6, 2026, 10:15 UTC. Based on a European Commission announcement on the Cyber Resilience Act and reporting by Cointelegraph.

Cryptocurrency hardware and software wallet providers now have 24 hours from becoming aware of an actively exploited vulnerability to warn European authorities, under reporting duties in the EU’s Cyber Resilience Act (CRA) that took effect on Friday, October 2. The rules cover all products “with digital elements made available in the EU,” according to a European Commission announcement reported by Cointelegraph.

The 24-hour clock

Manufacturers must file an early warning within 24 hours of discovering a severe or actively exploited vulnerability, followed by a full notification within 72 hours, according to the Commission’s announcement. A final report is due within 14 days after corrective or mitigating measures are available, and within one month for severe incidents. The Commission said the rules aim to better protect consumers and businesses from cyber threats as part of the EU’s broader cybersecurity strategy.

Fines up to 15 million euros

Companies that fail to meet the reporting obligations under Articles 13 and 14 of the Act face administrative fines of up to 15 million euros (about $17.3 million) or 2.5% of worldwide annual turnover, whichever is higher, according to the Act’s penalties text. Supplying incorrect, incomplete, or misleading information carries fines of up to 5 million euros. For wallet makers such as Ledger and Trezor, the rules mean running incident-response operations that can detect, assess, and report an actively exploited flaw to EU authorities within a single day.

The breaches behind the timing

The new duties arrive weeks after disclosures from two popular hardware wallet makers. On September 4, Trezor said an additional 67,000 U.S. customers were at risk from a data breach at its shipping provider, ShipMonk, well above the initially estimated 14,000 users, according to Cointelegraph. Trezor and BitBox later warned users about phishing emails disguised as urgent security notices after suspected compromises at third-party email services. In June, the Zilliqa network warned that a vulnerability in its Ledger app could have let attackers recover users’ private keys using publicly available onchain data. Cointelegraph said it has approached the Commission for more details, and has asked Trezor and Ledger for comment on how they plan to comply.

This article is news reporting and is not investment advice.

Sources

Not financial advice. This content is for information and education only. See our disclaimer, editorial policy and disclosures.

MABOnChain Daily Brief

The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.

Loading the signup form…

Prefer chat? Join us on Telegram

Keep reading