Loading market data...
Back to Feed
CRYPTO NEWS

EU cyber rules put crypto wallet makers on 24-hour reporting clock

Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

Published on CryptoNews: Source published: 2 min read
AI-generated editorial illustration for EU cyber rules put crypto wallet makers on 24-hour reporting clock
AI-generated editorial illustration.
Visit source

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.

$17.3 million2.5%Regulation

Summary

The European Union’s new Cyber Resilience Act requires cryptocurrency hardware and software wallet providers to report actively exploited bugs or severe security vulnerabilities within 24 hours of awareness. This rule took effect on Friday and mandates early warnings, full notifications, and follow-up reports within specified timeframes. The legislation aims to improve consumer and business protection against cyber threats in products with digital elements sold in the EU.

Why it matters

The European Commission states the reporting requirements enhance protection from cyber threats for consumers and businesses. The new rules impose strict timelines for vulnerability disclosures, potentially reducing the window of exposure to known exploits in crypto wallets. This could influence how wallet providers manage security incidents and communicate risks to users.

Key context

The Cyber Resilience Act extends to all products with digital components offered in the EU and is part of the bloc’s broader cybersecurity strategy. The regulation comes after recent data breaches affecting hardware wallet providers such as Trezor, which disclosed a significant customer data breach related to a shipping partner. Additionally, security vulnerabilities in apps like Zilliqa Ledger have raised concerns about cryptographic key exposure.

Key numbers and entities

The Cyber Resilience Act fines non-compliance with Articles 13 and 14 up to 15 million euros ($17.3 million) or 2.5% of global turnover, whichever is higher. Fines of up to 5 million euros apply for incomplete or misleading information submissions. Notable companies mentioned include wallet providers Trezor, BitBox, and Ledger, as well as blockchain project Zilliqa.

What remains unclear

The source does not specify how wallet providers will technically comply with the 24-hour reporting deadline or whether there are exceptions or support mechanisms. It also does not provide details on enforcement procedures or how the Commission will verify the accuracy and timeliness of incident reports. The responses from wallet makers to the new obligations remain unknown.

Read the original source

> JOIN THE ALPHA

Get a free crypto news briefing in your inbox. No fake subscriber counts — just the latest source-backed headlines we cache.

>
[ENCRYPTED][NO_SPAM][UNSUBSCRIBE_ANYTIME]