Core Points
·The reporting obligation begins after the vulnerability is actually exploited.
·The first warning will be issued within 24 hours.
·Commercial wallet products may be covered by regulations.
·Most of the Internet Resilience Act (CRA) rules will take effect in December 2027.
The 24-hour reporting rule came into effect before broader CRA regulations
Starting from September 11, manufacturers must report to manufacturers mainly the CSIRT (Computer Security Incident Response Team) of the member states in which they establish, and usually to ENISA, actually exploited vulnerabilities and serious security incidents affecting products with digital elements available in the EU market through a single reporting platform operated by the European Cyber Security Agency (ENISA).
Most of the EU Cyberelasticity Act (CRA) will come into effect on December 11, 2027, including broader requirements for product design, documentation and compliance. However, Section 14 (provisions covering exploited loopholes and serious incidents) will take effect earlier. This means that wallet companies may not yet face a complete CRA compliance system, but if proactive exploitation occurs, their legal deadline has arrived. This requirement applies not only to new equipment and software releases after December 2027, but also to scope products already available on the EU market before then.
Hardware and software wallets may be regulated
CRA applies to hardware and software products commercially available in the EU when the intended or reasonably foreseeable use of these products includes direct or indirect logical or physical connection to equipment or networks. As a result, commercial hardware wallets as well as desktop or mobile wallet applications may be under regulation.
Legal liability lies with the "manufacturer": the individual or company that develops the product, commissions the development of the product, or markets the product under its own name or trademark. Companies selling hardware devices or distributing wallet software in the EU are a more typical example than individual contributors to unrelated open source projects. Since the CRA does not explicitly list the cryptocurrency wallet, whether specific products are regulated still needs to be subject to legal evaluation.
CRA reporting timeline after manufacturer becomes aware
Within 24 hours: Issue early warnings to authorities and relevant EU markets affected.
Within 72 hours: Provide product details, vulnerability nature, mitigation measures and user operation guidelines.
Within 14 days: Submit final exploited vulnerability report after corrective actions are taken.
Within 1 month: Submit final serious event report after 72 hours notice.
What wallet manufacturers must report within 24 hours
The first submission is an early warning, not a completed technical investigation. When a manufacturer learns of a vulnerability that has been actually exploited, it must notify the authorities without delay and no later than 24 hours. Early warnings should specify the member states in which the company knows that affected products are available, if applicable.
The same period applies to serious incidents that affect product safety. In this case, the early warning must at a minimum state whether the company suspects illegal or malicious activity caused the incident and the availability of the product in the relevant market.
More details should be provided within 72 hours. In accordance with the European Commission's reporting guidelines, this notification must include available information about the product and the general nature of the vulnerability/attack. It must also cover corrective or mitigation actions that have been taken, steps that users can take, and, where applicable, how sensitive the information is considered by the manufacturer.
"Actual exploitation" is a key legal trigger
The 24-hour countdown does not begin when researchers privately report vulnerabilities. It applies when the manufacturer learns of a vulnerability that is "actually exploited"(i.e., a defect is being used against the product) or a serious incident that affects product safety. A company can receive reports, conduct investigations, and prepare patches without automatically falling within the Article 14 deadline. Once it is learned that an attacker is exploiting the flaw before the fix is completed, a supervised reporting process begins.
Recent Coldcard cases demonstrate the importance of this threshold. In the July warning involving potentially weak seed generation, the actual risk went beyond identifying flaws: Affected users needed to determine whether their seeds were exposed and transfer funds if necessary.
Reports are directed to authorities, not automatic disclosure
The rapid reporting period sounds like a requirement for immediate disclosure of unfixed wallet flaws. However, the CRA does not stipulate this. The initial report is sent to the relevant CSIRT and ENISA through a single reporting platform; it is not an automatically issued public announcement, nor is it a mandatory blog post containing details of a technical attack.
Regulations require authorities and other parties involved to protect confidential information, including source code, trade secrets, and information that may undermine investigations. In cases involving coordinated vulnerability disclosures, CSIRT may delay the dissemination of notification to other CSIRTs that the vulnerability has been exploited if there are reasonable cybersecurity reasons.
Public disclosure is still possible when it is necessary to prevent or mitigate serious incidents, deal with ongoing incidents, or serve the public interest. In this case, CSIRT may inform the public or require the manufacturer to do so in consultation with the company. Wallet makers must provide authorities with enough information to assess risks while instructing users on how to protect themselves without disclosing details that may assist attackers.
Open source wallets are not automatically exempted
CRA does not apply to free and open source software that is not on the market during non-commercial activities. It also does not apply to individuals who only contribute code to non-owned open source software for which they are not responsible.
But this does not mean a comprehensive exemption for open source wallet projects. The European Commission's open source guidelines state that manufacturers who put free and open source products on the market still have manufacturer obligations. Just because a product is free does not necessarily mean that its supply is non-commercial.
CRA has also created a separate category for open source software maintainers: legal entities that provide ongoing support for specific open source products intended for commercial use. They are not subject to CRA administrative fines, but Section 14 may still require reporting when they are involved in product development or when serious incidents affect the development systems they provide.
Patches may still put wallet users at risk
For cryptocurrency wallets, the end of a technical event is not always the time when security updates are available. Updates can prevent new exposures, but there are still risks in using keys, mnemonics or wallet settings created by affected software.
This was very clear when Coldcard released security updates to address early seed generation issues. Updating the device does not make previously generated affected seeds safe; holders still need to create new keys and transfer funds. Under the new CRA rules, this operational response may now occur in parallel with mandatory authority notices when actual exploitation is discovered.
Wallet makers now need to establish a documented 24-hour process for determining whether a utilization is active, notifying authorities, preparing mitigation measures and warning affected users. The next breach will test whether companies can meet this legal deadline while the incident is still under investigation and a full remediation plan does not yet exist.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC