Commercial manufacturers whose connected hardware wallets or wallet software meet the European Union's product test must now warn cyber authorities within 24 hours of discovering an actively exploited vulnerability or severe security incident.
Crypto wallet creators now have just 24 hours to alert regulators when flaws are exploited
Commercial manufacturers whose connected hardware wallets or wallet software meet the European Union's product test must now warn cyber authorities within 24 hours of discovering an actively exploited vulnerability or severe security…
CryptoSlate
Publisher
Sep 13, 2026 at 11:45 AM UTC · 2 分钟阅读

The requirement took effect Sept. 11, 2026, under the EU's Cyber Resilience Act, or CRA. The European Commission's reporting guidance says the clock applies to manufacturers of products with digital elements.
The CRA is a horizontal product law. The Commission's implementation FAQ says it applies to hardware and software made available on the EU market. The legal test also requires the product's intended or reasonably foreseeable use to include a direct or indirect data connection to a device or network.
A commercially supplied connected hardware wallet or downloadable wallet app can meet that test. However, EU guidance does not name wallet brands or declare every wallet service or project covered. Coverage depends on the specific product, how it is supplied and any applicable exclusion.
What manufacturers must report
The first filing is an early warning due without undue delay and no later than 24 hours after a manufacturer becomes aware of the vulnerability or incident. It must indicate, where applicable, the member states where the product is known to have been made available. For a severe incident, the warning must also say whether unlawful or malicious acts are suspected.
Article Intelligence
Topics
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
