Crypto wallet manufacturers now face a mandatory 24-hour deadline to alert European regulators when a vulnerability in one of their products is actively exploited. The requirement stems from Article 14 of the European Union’s Cyber Resilience Act (CRA), whose incident-reporting provisions took effect on September 11, 2026.
Article 14 applies to manufacturers of “products with digital elements,” a category that includes hardware wallets and commercial wallet software. Once a maker learns that a vulnerability is being actively exploited, it must submit an early warning notification to the EU cybersecurity agency ENISA and the designated computer security incident response team (CSIRT) through a single reporting platform within 24 hours. A fuller vulnerability notification is due within 72 hours, and a final report must follow within 14 days after a corrective or mitigating measure becomes available. Severe incidents affecting product security are subject to the same fast-track rules.
The timing is significant for the crypto sector amid recent wallet security failures. Hardware wallet maker Coldcard has been responding to attacks that drained Bitcoin from its devices, and its wave three exploiter has since moved funds through CoinJoin. Trezor separately disclosed a ShipMonk data breach affecting thousands of US customers. Under the new EU regime, a manufacturer that discovers its firmware has been exploited must notify regulators within a day, turning disclosure from a discretionary choice into a legal duty.
The broader CRA security duties — including security-by-design, conformity assessment and CE marking — do not apply until December 11, 2027. The rules also include relief for smaller firms: administrative fines do not apply to microenterprises and small enterprises that miss the 24-hour early-warning deadline, although the reporting obligation itself remains. Once the wider framework is in force, national market surveillance authorities can pursue enforcement action for non-compliance.