EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

EU requires cryptocurrency wallet companies to report major security breaches within 24 hours

2026-09-14 21:14:10
Bookmark

The EU has introduced new regulations on cybersecurity for cryptocurrency wallets: Major vulnerabilities must be reported within 24 hours

The EU has introduced strict cybersecurity reporting rules for cryptocurrency hardware and software wallet providers, requiring them to disclose proactively exploited vulnerabilities or critical security errors within 24 hours of discovering them. The new obligation is part of the Cyber Resilience Act (CRA), which took effect on Friday.

The Cyber Resilience Act focuses on digital product security

According to the European Commission's announcement, the Cyber Resilience Act aims to strengthen the cyber security of all products with digital elements sold within the EU, with special attention to equipment and software that handle sensitive assets such as cryptocurrency wallets. The new rules require manufacturers and service providers to issue early warnings within 24 hours of learning of a critical vulnerability, then submit detailed notices within 72 hours, and submit final reports within 14 days of fixing the vulnerability (within a month in the most serious case).

The European Commission said these fast-track reporting requirements are aimed at enhancing the protection of consumers and businesses in the digital economy. The scope of the Cyber Resilience Act is not limited to cryptocurrency wallets, but also covers any digital product sold in the market of EU member states.

Violators will face huge fines

Companies that fail to meet their reporting obligations under sections 13 and 14 of the Cyber Resilience Act may face serious financial consequences. The final draft text stipulates that violators will be fined up to 15 million euros (approximately US$17.3 million) or 2.5% of global annual turnover, whichever is higher. Companies that provide false, incomplete or misleading information related to security incidents may also face additional administrative fines of up to € 5 million.

Violation Maximum penalty No critical vulnerabilities reported 15 million euros or 2.5% of annual turnover Providing misleading/incomplete information 5 million euros

Industry background: Review of recent security incidents

The implementation of the Network Resilience Act follows several high-profile security incidents in the cryptocurrency hardware wallet space. In previous weeks, well-known providers disclosed major data breaches affecting user information, raising concerns about the threat of phishing and social engineering attacks.

  • Trezor Data Breach: On September 4, hardware wallet maker Trezor reported a data breach involving its logistics partner ShipMonk, putting 67,000 U.S. customers at risk, a figure much higher than the original estimate of 14,000 users.
  • Phishing attack warning: Both Trezor and BitBox have recently warned users about phishing attacks that impersonate emergency security notices, which may stem from data breaches by email service providers. These incidents highlight the growth risks faced by cryptocurrency wallet users.
  • Zilliqa vulnerability incident: In early June this year, Layer-1 blockchain platform Zilliqa publicly warned that its Ledger application contained a key vulnerability that could allow attackers to use data stored on the chain to recover users 'private keys.

Compliance Outlook and Regulatory Trends

The new EU regulations apply to any wallet provider operating or marketing its products within the EU. Industry participants, including Trezor and Ledger, are being asked to explain how they plan to comply with updated compliance standards. Manufacturers must issue early warnings of critical vulnerabilities within 24 hours, provide full notification within 72 hours, and submit final reports immediately after corrective actions are taken.

The European Commission's recent cybersecurity measures are part of its broader strategy to address growing digital threats, a trend that has become increasingly evident as more financial transactions and assets migrate to blockchain-based platforms.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP