NewsLayer.com
NewsLayer PulseLIVEBTC$78,931+2.11%ETH$2,533+1.13%SOL$103.07+2.07%XRP$1.44+5.99%DOGE$0.0849+0.49%ADA$0.212+1.66%Total Cap$2.60T+2.11%Layer Index53 Neutral

CryptoDeFi

breaking

EU Imposes 24-Hour Exploit Disclosure Deadline on Crypto Wallet Makers

The EU has reportedly imposed a 24-hour deadline for crypto wallet makers to disclose exploits. The requirement would increase the urgency of incident reporting for wallet providers operating in the region.

finance.biggo.com

Publisher

Sep 11, 2026 at 6:26 PM UTC · Updated há 3 dias · 6 min de leitura

EU Imposes 24-Hour Exploit Disclosure Deadline on Crypto Wallet Makers
NewsLayer editorial artwork
Traduzindo…

Pontos-Chave

  • Crypto wallet makers would be required to disclose exploits within 24 hours.
  • The measure reportedly applies in the European Union.
  • The rule could raise operational and compliance pressure on wallet providers during security incidents.

Crypto wallet manufacturers selling products in the European Union now have just 24 hours to alert authorities after discovering that a security flaw in their software or hardware is being actively exploited by attackers.

The clock started on September 11, when Article 14 of the EU's Cyber Resilience Act (CRA) became applicable. The provision covers any "product with digital elements" made available on the EU market, a category that legal experts say likely includes commercial hardware wallets and desktop or mobile wallet applications. The obligation applies to manufacturers regardless of where they are based.

Under the new rules, a company that becomes aware of an actively exploited vulnerability must file an early warning through the Single Reporting Platform operated by ENISA, the EU's cybersecurity agency, within 24 hours. A more detailed notification is due within 72 hours, followed by a final report within 14 days of a corrective measure becoming available. Severe security incidents follow the same initial deadlines, with the final report due one month after the first filing.

The reporting requirement is not triggered by a private bug report from a researcher. A manufacturer can receive a report, investigate it, and prepare a patch without automatically falling under the Article 14 deadline. The clock starts only once the company learns that attackers are exploiting the flaw before a fix is complete.

Article Intelligence

Topics

Sponsored

Ad
House — Advertise on NewsLayer
NewsLayerLearn more

NewsLayer Premium

Unlock deeper intelligence.

Ad-free reading, exclusive research, and real-time onchain insights.

Go Premium