Key facts
- EU crypto wallet providers must report exploited bugs or severe security vulnerabilities within 24 hours of awareness.
- A full notification is required within 72 hours.
- Fines for non-compliance can reach 15 million euros ($17.3 million) or 2.5% of worldwide annual turnover.
- Supplying incorrect, incomplete, or misleading information can lead to fines of up to 5 million euros.
- The new rules are part of the EU's Cyber Resilience Act, which took effect on Friday.
- The measures apply to all products with digital elements made available in the EU.
The European Union has implemented new cybersecurity regulations under its Cyber Resilience Act (CRA), which became effective on Friday. This legislation mandates that cryptocurrency hardware and software wallet providers must report actively exploited bugs or severe security vulnerabilities within 24 hours of becoming aware of them. Following this initial warning, a comprehensive notification must be submitted within 72 hours. A final report is required within 14 days of implementing corrective or mitigating measures, and within one month for severe incidents.
The European Commission stated that these reporting requirements are designed to enhance the protection of consumers and businesses against cyber threats. The CRA's scope extends to all products with digital elements available in the EU, aligning with the bloc's broader cybersecurity strategy.
Companies that fail to comply with these new reporting obligations, as outlined in Articles 13 and 14 of the CRA, face significant administrative fines. Penalties can amount to up to 15 million euros ($17.3 million) or 2.5% of their worldwide annual turnover, whichever is greater. Furthermore, providing incorrect, incomplete, or misleading information could result in fines of up to 5 million euros.
These regulatory changes come shortly after several prominent hardware wallet providers reported data breaches. Trezor, for instance, disclosed that a breach at its shipping provider, ShipMonk, potentially exposed the data of an additional 67,000 US customers, surpassing an initial estimate of 14,000. Both Trezor and BitBox have since cautioned users about phishing attempts disguised as urgent security notices, following suspected compromises involving third-party email services. Previously, in June, Layer-1 blockchain network Zilliqa alerted users to a vulnerability in its Ledger app that could enable attackers to recover private keys using publicly available on-chain data.