EU cyber rules put crypto wallet makers on 24-hour reporting clock

Summary

The EU’s Cyber Resilience Act now requires crypto wallet providers and other products with digital elements sold in the EU to report actively exploited bugs or severe vulnerabilities quickly: an early warning within 24 hours of awareness, a full notification within 72 hours, then follow-up reports 14 days after fixes or mitigations are available and within one month for severe incidents. The goal is to improve consumer and business protection against cyber threats. Noncompliance can trigger fines of up to 15 million euros or 2.5% of global annual turnover, whichever is higher; misleading reporting can bring fines up to 5 million euros. The rule comes amid recent breaches and phishing warnings affecting hardware wallet users.