EU Mandates 24-Hour Reporting of Crypto Wallet Vulnerabilities
Developers of crypto wallets in Europe are required to report vulnerabilities in their software within 24 hours of discovery. This mandate is part of the updated Cyber Resilience Act.
ForkLog
Publisher
Sep 14, 2026 at 7:26 AM UTC · Updated a few seconds ago · 2 min read

EU mandates 24-hour reporting of crypto wallet vulnerabilities.
Developers of crypto wallets in Europe are required to report vulnerabilities in their software within 24 hours of discovery. This mandate is part of the updated Cyber Resilience Act.
The rules took effect on September 11. The requirements apply to providers of both hardware and software crypto wallets registered in the EU.
According to the document, an initial notification of a vulnerability or serious security incident must be sent within 24 hours of the manufacturer becoming aware of the issue. A full statement is required within 72 hours.
A final incident report must be submitted no later than 14 days after implementing fixes. For serious incidents, the report is due within a month after the 72-hour notification.
Manufacturers are also obligated to inform all affected or potentially vulnerable users.
Reports are submitted through the Single Reporting platform created by ENISA. Notifications are sent to CSIRT, which must promptly forward them to relevant teams in other EU countries where the product is available.
Background
Concerns about security in the sector intensified following an incident involving the hack of Coldcard hardware wallets. In July, hackers began exploiting a flaw in seed phrase generation that had been present in the firmware for several years.
Market Context
Bitcoin
BTC
$77,969
+1.56% (24H)
Market Cap
$1.56T
24H Volume
$15.7B
24H High
$77,988
Article Intelligence
Related Coverage
View all relatedSponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
