EU Cyber Resilience Act Puts a 24-Hour Deadline on Crypto Wallet Security Disclosures
For years, cryptocurrency wallet makers have treated security disclosures as a matter of corporate discretion. A firmware flaw could be quietly patched, a blog post published when the time felt right, and customers informed only after an internal investigation had run its course. That era ended on September 11, 2026, when a key provision of the European Union’s Cyber Resilience Act went into force. From that day forward, any crypto wallet manufacturer doing business in the EU has just 24 hours to notify European regulators when a vulnerability in one of its products is actively exploited. The requirement, embedded in Article 14 of the CRA, is part of the bloc’s ambitious effort to build a stronger cybersecurity baseline for connected hardware and software. And while the regulation’s broader obligations—including security-by-design, conformity assessment, and CE marking—will not become fully applicable until December 11, 2027, the incident-reporting provisions have already created a dramatic shift in how wallet makers must think about vulnerabilities. The old model, in which a company could control the narrative and timeline around a security crisis, has been replaced by a legal duty to report fast, report clearly, and report to regulators first. For an industry that has historically been defined by independence and self-regulation, that is a profound change.
The scope of the new rule is broader than many in the crypto industry may realize. The Cyber Resilience Act applies to manufacturers of “products with digital elements,” a category that explicitly includes hardware wallets and commercial wallet software because such products connect to devices and networks. That means the 24-hour obligation is not limited to a few major players. It applies to established hardware wallet companies, software wallet developers, and even startups that sell directly to EU consumers. When a manufacturer becomes aware that a vulnerability is being actively exploited, it must file an early warning notification with ENISA, the European Union Agency for Cybersecurity, and with the designated computer security incident response team, or CSIRT, through a single reporting platform. This is not a suggestion or a best practice. It is a legal requirement. The notification must happen within one day of the manufacturer learning about the active exploitation, not within one day of confirming every technical detail. This is a deliberate design choice: regulators want to know about the threat immediately, even if the full picture is still incomplete. The goal is to give the EU a real-time view of emerging attacks and to enable swift coordination across member states before a single vulnerability spirals into a widespread incident.
Article 14 does not stop at the 24-hour early warning. The reporting framework is built on a three-stage timeline that ensures regulators receive increasingly detailed information as a crisis unfolds. After the initial early warning, manufacturers have 72 hours to submit a more complete vulnerability notification. This follow-up must include technical details about the vulnerability, its impact, and any indicators of compromise that have been identified. Then, once a corrective or mitigating measure is available—a patched firmware update, a software hotfix, or another remediation—the manufacturer has 14 days to deliver a final report. That final report is meant to close the loop, explaining what happened, how the issue was addressed, and what steps are being taken to prevent a recurrence. The same fast-track reporting obligations apply to severe incidents that affect the security of a product, even if a specific vulnerability has not yet been pinpointed. In other words, if a wallet maker sees unusual activity that suggests a product is under attack, the clock starts ticking immediately. This structure represents a significant departure from the traditional “responsible disclosure” model that has long dominated the cybersecurity world. Under that model, companies often spent weeks or months quietly developing fixes before revealing a vulnerability. The CRA compresses that timeline dramatically, forcing transparency to happen in near real-time.
The timing of this new regulatory regime is particularly significant for the cryptocurrency wallet sector, which has been rattled by a string of high-profile security failures. Hardware wallet maker Coldcard, for instance, spent weeks responding to a series of attacks that drained Bitcoin from its devices. The situation escalated to the point where the company’s “wave three” exploiter moved stolen funds through CoinJoin, a privacy-enhancing tool that makes transaction tracing significantly harder. The attack highlighted the uncomfortable reality that even purpose-built hardware wallets can be compromised, and it underscored the difficulty of responding to an active threat while protecting users. Around the same period, Trezor, another leading name in the hardware wallet space, disclosed a data breach at ShipMonk, a third-party logistics provider, that affected thousands of customers in the United States. Although that breach involved customer data rather than digital assets, it illustrated the breadth of security risks facing wallet manufacturers. Under the previous, more discretionary approach, both companies had room to control the timing and framing of their disclosures. They could wait for law enforcement involvement, legal review, or a carefully crafted public relations strategy. Under the CRA, that flexibility evaporates. A manufacturer that discovers its firmware has been exploited must notify EU regulators within 24 hours, whether or not it is ready to go public. The disclosure timeline is no longer a matter of brand management; it is a matter of legal compliance.
This transition from voluntary disclosure to mandatory reporting marks a cultural shift for the entire crypto ecosystem. Historically, wallet manufacturers operated in a space where trust was earned through transparency, but transparency was largely self-regulated. Companies decided when to announce a fix, how much technical detail to share, and whether regulators needed to be involved at all. That approach had some advantages, including the ability to protect users by withholding information until a patch was ready. But it also allowed vulnerabilities to remain hidden for long stretches, leaving users in the dark and giving attackers a head start. The CRA fundamentally changes that calculation. It prioritizes speed and regulatory awareness over corporate discretion. Manufacturers must now bring European authorities into the loop before a vulnerability becomes a public story. For an industry built on decentralized principles, the idea of reporting to a central cybersecurity agency may feel uncomfortable. But for many security experts, it is a necessary evolution. Cryptocurrency users have grown increasingly wary of security failures, exchange collapses, and phishing attacks. The promise of self-custody is only meaningful if the tools used to protect digital assets are held to a high and auditable standard. The CRA provides exactly that: a concrete, enforceable process that cannot be gamed with vague language or silent patches. Over time, this may actually help rebuild user trust. More frequent advisories might seem alarming at first, but they signal that manufacturers are being held accountable by an external authority.
The rollout of the CRA is deliberately staggered, and it includes important nuances for smaller businesses. The September 11, 2026, effective date applies only to the regulation’s vulnerability and incident-reporting obligations. The broader requirements—security-by-design mandates, conformity assessment procedures, CE marking, and the full compliance infrastructure—do not become applicable until December 11, 2027. This gives manufacturers more than a year to prepare for the heavier regulatory burden. In the meantime, the reporting rules are a standalone obligation, and they apply immediately to any product with digital elements sold or made available in the EU. There is also a measure of relief for smaller firms. Administrative fines for missing the 24-hour early-warning deadline do not apply to microenterprises and small enterprises, as defined under EU law. However, the reporting obligation itself still applies. In other words, a small wallet startup that fails to file on time may avoid a fine, but it is still in violation of the law. For larger manufacturers, the stakes are higher. Once the full framework is in force, national market surveillance authorities will have the power to take enforcement action against non-compliant companies. That could include financial penalties, product recalls, or even bans on selling certain products within the EU market. For companies that rely on European customers, the message is unmistakable: cybersecurity compliance is now a market access issue.
Looking ahead, the CRA’s 24-hour reporting requirement is likely to reshape the entire security lifecycle of crypto wallet products. Manufacturers will need to invest in continuous monitoring and threat detection systems capable of identifying active exploitation quickly enough to meet the deadline. Manual review alone will no longer suffice, because a vulnerability could be exploited overnight, and a company that discovers it at 9 a.m. must have its notification ready by the next morning. This may also change how manufacturers interact with security researchers. In the past, researchers often hesitated to report vulnerabilities directly to companies for fear of being ignored or silenced. Under the CRA, manufacturers have a strong incentive to respond quickly and cooperatively, because any delay in fixing a flaw could lead to an active exploitation event and a regulatory notification. For users, the practical effect should be more timely alerts and more transparent communication about the risks affecting their devices. That may feel unsettling, especially for those who prefer to believe their hardware wallets are invulnerable. But it is a sign that the industry is growing up. The EU’s Cyber Resilience Act is part of a broader global push toward stronger cybersecurity standards, and its impact will be felt far beyond Europe. Crypto wallet makers, wherever they are based, will have to adapt to a new reality in which the clock starts ticking the moment a vulnerability is exploited—and 24 hours is all they get to tell the world. The era of quiet patches and delayed disclosures is over. In its place is a new era of mandatory transparency, and for an industry whose entire value proposition rests on trust, that may ultimately be a very good thing.











