The European Union has introduced new cybersecurity rules for crypto wallet makers. Starting September 11, companies that sell hardware or software wallets in the EU must report actively exploited vulnerabilities to regulators within 24 hours of becoming aware of them. The rule affects millions of people who store private keys to their crypto holdings in these wallets.
What exactly changed?
The new requirement is part of the Cyber Resilience Act (CRA), which took effect on September 11. The law covers all products "with digital elements" sold in the EU, meaning it reaches far beyond crypto wallets into a wide range of electronics and software. For hardware and software wallet makers, it creates a new duty. Once a company learns of a severe vulnerability or an active exploit, it must notify the relevant authority.
Earlier cybersecurity rules mostly targeted classic electronics and industrial software, while crypto largely sat outside them. Specialized frameworks like MiCA focus on exchanges and token issuers, not wallet makers. The CRA closes that gap. If a product is sold in the EU and has any digital component, it falls under the general cybersecurity rules regardless of whether it's crypto or an ordinary smart gadget.
How much time do companies get to report?
The deadlines come in stages. Companies must submit an early warning about a severe vulnerability within 24 hours of becoming aware of it. A full notification with details follows within 72 hours. A final report is due 14 days after a fix or mitigation becomes available. Severe incidents get a separate one-month deadline.
The rules split into two cases. If attackers are already actively exploiting a vulnerability, the 24-hour clock starts immediately. If it's a severe but not yet exploited flaw, the same deadlines apply, but the clock starts when the maker learns the scale of the problem. Notifications go to the national cyber incident response team or to whichever authority a member state has designated.
What happens if a company breaks the rules?
Failing to comply with Articles 13 and 14 of the act can trigger an administrative fine of up to 15 million euros, about $17.3 million, or 2.5% of global annual turnover, whichever is higher. Submitting incomplete, incorrect, or misleading information carries a separate fine of up to 5 million euros. The European Commission says the goal is simply to protect consumers and businesses from cyber threats. The fine structure echoes GDPR, since the upper limit is tied to a company's turnover rather than a fixed sum, so penalties for large manufacturers could reach tens of millions of euros. National regulators can now inspect documentation and demand proof that a maker took reasonable steps to find vulnerabilities during development, not just after the fact.
Why does this matter right now?
Hardware wallets are usually marketed as the safest way to hold crypto because private keys never leave the physical device. But several incidents this year showed the weak point is often not the chip itself but the surrounding infrastructure. Think shipping providers, email services, third-party partners.
- The ShipMonk breach: On September 4, Trezor said a data breach at its shipping provider affected another 67,000 US customers, up from an initial estimate of 14,000.
- On Wednesday, Trezor and BitBox warned customers about phishing emails disguised as urgent security notices.
- In June, the Zilliqa network warned that a flaw in its Ledger app could theoretically let attackers recover private keys using public onchain data.
- In August, BitBox issued an emergency firmware update after researchers using AI tools found vulnerabilities in its hardware.
None of these cases was a direct mass wallet hack, but each showed how quickly incomplete communication turns into phishing material.
What this means for wallet owners
For everyday users, the change happens behind the scenes. They don't file reports or pay fines. But faster vulnerability disclosure means official security notices will show up more often and sooner.
If you use a hardware or software wallet, the safest habit is to verify security notices through the maker's official website rather than trusting email alone. The rule does not directly cover crypto exchanges or the hot wallets built into their mobile apps. Those fall under separate financial regulation, so the CRA is best read as an addition to existing rules, not a replacement for them.




Comments
Your email address will not be published. Required fields are marked *