EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

The Internet Resilience Act requires crypto wallets to report hacking attacks within 24 hours

2026-09-12 00:10:55
Bookmark

Cyber Resilience Act: EU crypto wallet manufacturers face a 24-hour vulnerability reporting time limit

With the EU Cyber Resilience Act (CRA) officially coming into effect this month, cryptocurrency wallet manufacturers facing the EU market are placed under a strict vulnerability reporting schedule. Once a product has a defect that is being exploited, it must be reported to the European Cyber Security Agency (ENISA) within 24 hours and a full report submitted within 14 days. Violators will face a maximum fine of 15 million euros.

However, ironically, 2026 data shows that only 11% of financial losses in audited projects resulted from smart contract code vulnerabilities. The vast majority of cryptographic assets are lost not due to code flaws targeted by regulations, but rather due to theft of private keys or infrastructure attacks.

24-hour warning, 14-day detailed report and tens of millions of euros fine

This regulatory framework is based on three fixed time nodes that will be triggered when a manufacturer discovers a vulnerability that is being actively exploited or a serious security incident occurs:

  • Early warnings (within 24 hours): sends an early alert to ENISA informing of discovered exploitative vulnerabilities or critical events.
  • Detailed notification (within 72 hours): provides detailed updates including mitigation steps and preliminary impact assessments.
  • Final report (within 14 days): Submit a post-hoc analysis report to clarify the root cause and its remediation plan.

Failure to comply with any of the above deadlines can result in a penalty amount of € 15 million or 2.5% of global annual turnover, whichever is higher. For a company with an annual turnover of 500 million euros, the percentage alone is as high as 12.5 million euros. While micro and small businesses are exempt from the strict 24-hour early warning period, most wallet companies backed by venture capital do not meet this requirement.

How hardware wallets fall under the jurisdiction of product security laws

Although the Network Resilience Act does not directly mention "cryptocurrency," its jurisdiction covers all products with digital symbols, that is, anything that carries software or firmware and connects to a device or network. Signature devices with firmware and accompanying applications undoubtedly fall into this category; browser extensions or mobile wallets are considered independent software with security features, and such products are subject to more stringent regulatory scrutiny.

Exchanges and custodians are mainly governed by the Cryptographic Asset Markets Regulations (MiCA), but tools that hold private keys must now comply with product liability laws, a line that directly leads the wallet team to ENISA regulation.

207 hacking attacks cost nearly US$1 billion, only 11% of which originated from code

There were more than 207 hacking attacks in the first half of 2026, more than double the number in the same period last year, although total losses remained below $1 billion in six months. The number of attempts increases, but the single profit decreases. A study released by CoinGecko in August 2026 further reveals this trend: Since 2025, 88.4% of stolen funds have come from platforms that have been independently audited, and of these audited projects, only 11% of attacks touched the smart contract code itself.

The remaining losses were mainly incurred through third-party dependencies, front-end supply chains, and stolen employee credentials. North Korea-affiliated Lazarus Group caused approximately 76% of global losses in early 2026.

Indicators All year of 2025 First half of 2026 2026 to date (estimate) Total amount stolen $2.38 billion-$3.4 billion $972 million-$1.31 billion About $1.5 billion and rising Number of Events Lower frequency More than 207 cases, a record There were 50 cases in August alone Main root causes Centralized entity failure Infrastructure and private keys (72 - 76%) Infrastructure and private keys (72 - 76%)

Regulations track vulnerabilities that thieves no longer use

This disconnect is obvious. The 24-hour reporting mechanism can still work when vulnerabilities in the wallet's own code are being actively attacked. But the mechanism becomes ineffective when attackers use phishing to gain rights to multi-signed devices or hijack developers 'sessions-which is how the largest theft of the year occurred.

The Cyber Resilience Act does require manufacturers to run a coordinated vulnerability handling process and maintain a software bill of materials (SBOM), so most third-party components that cause the majority of losses need to be registered at a minimum. However, it remains unknown whether reporting deadlines can change attacker behavior, and records for 2026 indicate that the speed of disclosure is not the only barrier between treasury funds and empty wallets.

Actual Fund Loss Path in 2026

January 2026· Ledger / Global-e
Customer names and contact information leaked through third-party payment processors. This was a data breach rather than a theft of funds, but it was this kind of external failure that caused the wallet manufacturer to record it in accordance with CRA requirements.

April 2026· KelpDAO -US$292 million
Bridge verification failed to cause attackers to cast unsupported rsETH, which subsequently extracts value from lenders. This is the second theft in the past 18 months.

April 2026· Drift Protocol -US$285 million
Private key was compromised, investigators linked it to a nationally backed hacking group.

June 2026· Humanity Protocol -US$30 million to US$32 million
It was emptied because a single private key was stolen, which visually demonstrates how the disclosure of a single certificate can lead to an empty treasury.

August 2026· Tectonic. cro-$120 million attack, net loss of approximately US$9 million
Vulnerability in the Cronos chain; the validator rolled back the blockchain and recovered most of the funds, leaving only approximately US$9 million in loss.

At the same time, the scale of retail phishing attacks has shrunk significantly, from US$494 million in 2024 to US$83.85 million in 2025. Instead of leaving, the attacker moved upstream, using language models to write bait specifically targeting administrators and signers with organization-level balances.

What the wallet team needs to complete before December 2027

The current priority is procedural. Wallet manufacturers need to establish a path from discovering the exploit to submitting a report to ENISA within one day, which means monitoring systems, duty rotation systems, and pre-written templates. Combined with the software bill of materials and coordinated disclosure policies, the dependencies behind the losses in 2026 will no longer be invisible. Large publishers can absorb this cost through compliance departments, and a streamlined wallet team for the EU market will either find the corresponding capabilities or geofence the EU market-the latter that some developers have chosen since MiCA was introduced.

Enforcement efforts will not appear the same everywhere at the same time. The national market supervisory authorities of each member state are responsible for enforcement, while uniform standards defining what constitutes "adequate safety" are still in the draft stage of the European Standardization Body. The reporting obligation that takes effect this month is only the first wave of impact from the Cyberelasticity Act; the "design is security" obligation will follow up in December 2027. The Wallet team has a short window of time to establish a reporting mechanism, and the first penalty case will show whether regulators are strictly enforcing the 24-hour deadline as literally stated.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP