started · updated
European Union mandates 24-hour security breach reporting for crypto wallets
The European Union has implemented new cybersecurity obligations for companies developing crypto hardware and software wallets under the Cyber Resilience Act. Effective as of Friday, the regulation mandates that manufacturers provide an early warning within 24 hours if an actively exploited vulnerability or critical security flaw is detected.
The reporting timeline requires an initial notification within 24 hours, followed by a detailed report within 72 hours. Once corrective or risk-mitigating measures are ready, a final report must be submitted within 14 days, with additional reporting required for serious incidents within one month. These rules apply to all digital products offered within the EU market.
Non-compliance carries significant financial penalties. Companies failing to meet these obligations may face administrative fines of up to 15 million euros or 2.5% of their total global annual turnover, whichever is higher. Providing false, incomplete, or misleading information can result in additional fines of up to 5 million euros.
This regulatory move follows recent security concerns in the sector, including data breaches reported by hardware wallet providers such as Trezor, which recently updated its estimate of affected users following a breach involving a shipping partner.
Entities
European Commission · European Union · Mark Warner · Trezor · United States Senate