EU Cyber Resilience Act Requires 24-Hour Exploit Disclosure for Crypto Wallet Makers
Crypto wallet manufacturers now have just 24 hours to alert European regulators when a vulnerability in one of their products is actively exploited. The obligation comes from Article 14 of the European Union’s Cyber Resilience Act…
KuCoin
Publisher
Sep 14, 2026 at 5:46 AM UTC · 2 分钟阅读

Crypto wallet manufacturers now have just 24 hours to alert European regulators when a vulnerability in one of their products is actively exploited. The obligation comes from Article 14 of the European Union’s Cyber Resilience Act (CRA), the bloc’s flagship cybersecurity rule for connected hardware and software, whose incident-reporting provisions took effect on September 11, 2026 — more than a year before the regulation’s broader security requirements become applicable in December 2027.
What the 24-Hour Deadline Requires
Article 14 of the Cyber Resilience Act covers manufacturers of “products with digital elements” — a category that sweeps in hardware wallets and commercial wallet software because such products connect to devices and networks. When a maker learns that a vulnerability is being actively exploited, it must submit an early warning notification to the EU’s cybersecurity agency ENISA and the designated computer security incident response team (CSIRT) through a single reporting platform within 24 hours. A fuller vulnerability notification follows within 72 hours, and a final report is due within 14 days of a corrective or mitigating measure becoming available. The same fast-track rules apply to severe incidents affecting product security.
Market Context
Bitcoin
BTC
$77,652
+0.71% (24H)
Market Cap
$1.56T
24H Volume
$15.5B
24H High
$77,830
Article Intelligence
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
