The EU Cyber Resilience Act Takes Effect; Crypto Wallet Providers Must Report Vulnerabilities Within 24 Hours

icon MarsBit
Share
AI summary iconSummary
The EU Cyber Resilience Act (CRA) took effect on September 11, 2026, requiring crypto wallet providers to report critical vulnerabilities within 24 hours. Full reports must be submitted within 72 hours, with final details due within 14 days—or up to one month for severe issues. The European Commission stated that the rules aim to enhance protection for consumers and businesses under MiCA (EU Markets in Crypto-Assets Regulation). Non-compliance may result in fines of up to €15 million or 2.5% of global turnover, impacting liquidity and crypto markets. A recent Trezor data breach affecting 67,000 U.S. users has heightened the urgency surrounding the CRA’s implementation.

Huoxing Finance reports that the EU’s Cyber Resilience Act (CRA) officially took effect on September 11, requiring providers of crypto hardware and software wallets to submit an early warning report within 24 hours of discovering actively exploited vulnerabilities or serious security flaws, and a full notification within 72 hours. Manufacturers must also submit a final report within 14 days after implementing corrective or mitigating measures, with severe incidents requiring reporting within one month. The European Commission stated that the new reporting requirements aim to better protect consumers and businesses from cyber threats, applying to all “digital element products” sold on the EU market and building upon the EU’s broader cybersecurity strategy. Under the final draft’s penalty provisions, companies failing to comply with Articles 13 and 14 may face administrative fines of up to €15 million (approximately $17.3 million) or 2.5% of their global annual turnover, whichever is higher; providing incorrect, incomplete, or misleading information may also incur fines of up to €5 million. Prior to this measure’s implementation, several hardware wallet manufacturers recently disclosed user data breaches. On September 4, Trezor revealed that a data breach affecting its logistics provider ShipMonk impacted approximately 67,000 U.S. customers—exceeding the initial estimate of 14,000. This week, Trezor and BitBox also warned users to be cautious of phishing emails disguised as urgent security notices. In June, the Layer-1 blockchain network Zilliqa warned that a vulnerability existed in its Ledger application, allowing attackers to potentially recover user private keys using publicly available on-chain data.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.