EU Crypto Wallet Makers Face 24-Hour Deadline to Report Exploited Flaws
New mandates under the Cyber Resilience Act require manufacturers to notify authorities of active security incidents almost immediately.
Commercial crypto wallet manufacturers selling products in the European Union must now report actively exploited vulnerabilities or severe security incidents within 24 hours. This mandate, which took effect on September 11, 2026, marks the first phase of the EU's Cyber Resilience Act (CRA) to enter into force.
Under Article 14 of the CRA, manufacturers of products with digital elements must provide an "early warning" to authorities within 24 hours of becoming aware of an active exploit or severe incident. This initial notification must be submitted via the Single Reporting Platform managed by the European Union Agency for Cybersecurity (ENISA) and directed to both ENISA and the relevant national Computer Security Incident Response Team (CSIRT). Following this early warning, a comprehensive report detailing the nature of the exploit, specific product details, and mitigation steps must be filed within 72 hours.
A Phased Approach to Security
The fast-tracking of these reporting requirements is part of a broader strategy to improve the security of digital products across the EU. While the reporting obligations are now live, the majority of the CRA's requirements—including strict rules regarding product design, documentation, and conformity assessments—will not be fully implemented until December 11, 2027. By decoupling the reporting mandate from the design rules, EU regulators aim to ensure a rapid, coordinated response to active threats while giving manufacturers more time to overhaul their development lifecycles.
Implications for Digital Assets
For the crypto wallet industry, these deadlines create a high-pressure legal environment where the clock starts the moment a flaw is exploited, regardless of whether a technical patch is available. In the digital asset ecosystem, where security breaches often result in the irreversible loss of funds, the speed of communication is critical. Rapid reporting to authorities is intended to mitigate systemic risk, potentially allowing for faster warnings to users who may need to move their assets before a vulnerability is widely weaponized.
This 24-hour window is specifically triggered when a manufacturer becomes aware of an actively exploited vulnerability, rather than when a security researcher privately reports a bug.
Looking Ahead
Industry participants now face a transition period leading up to December 2027, when the full weight of the CRA's design and documentation standards will apply. Until then, the primary focus for wallet makers will be the operationalization of their incident response plans to meet the strict 24-hour and 72-hour windows. Market observers will be watching how ENISA manages the influx of reports through the Single Reporting Platform and whether these early warnings successfully reduce the window of exposure for EU consumers.