Skip to content

Crypto Wallet Makers Face 24-Hour Reporting Deadline

EU Enforces 24-Hour Reporting for Crypto Wallet Security Vulnerabilities

  • The EU’s Cyber Resilience Act mandates that cryptocurrency hardware and software wallet providers report severe vulnerabilities within 24 hours of discovery.
  • A full notification must follow within 72 hours, with a final report due 14 days after corrective measures are available.
  • Non-compliance could result in fines up to €15 million (approximately $17 million) or 2.5% of global annual turnover, whichever is higher.
  • This regulation applies to all products with digital elements sold in the EU, enhancing consumer protection against cyber threats.
  • The announcement follows recent data breaches affecting popular wallet providers like Trezor, which exposed data of over 67,000 US customers.

The new reporting requirements aim to strengthen cybersecurity for digital products in the EU, responding to increasing threats faced by consumers and businesses alike. This initiative builds on existing cybersecurity strategies to ensure better protection against vulnerabilities.

With fines potentially reaching €15 million for non-compliance, wallet providers must act swiftly to adhere to these new regulations following recent security incidents affecting over 67,000 users. (Source)

Share