EU Mandates Strict Twenty Four Hour Flaw Notice for Crypto Wallets

EU Mandates Strict Twenty Four Hour Flaw Notice for Crypto Wallets
Table of Contents

TL;DR

  • The EU activated Article 14 of the Cyber Resilience Act, requiring crypto wallet manufacturers to report active vulnerabilities within 24 hours.
  • The initial report is not public: it goes to the CSIRT of the manufacturer’s country of establishment and to ENISA through the Single Reporting Platform.
  • Hardware and software wallets marketed in Europe are already covered, even though the bulk of the CRA only takes effect in December 2027.

The European Union activated one of the most demanding obligations of the Cyber Resilience Act (CRA): manufacturers of products with digital elements available on the European market, including crypto wallets, must notify competent authorities within 24 hours of becoming aware of an actively exploited vulnerability or a serious security incident.

The EU brought forward this requirement —contained in Article 14 of the CRA— ahead of the rest of the regulatory framework, which will enter into force in December 2027.

The legal obligation falls on the manufacturer, understood as the person or company that develops a product and markets it under their name or brand. Hardware wallets and desktop or mobile applications distributed commercially in Europe fall within the scope of the regulation, given that they involve logical or physical connections with devices or networks. The law also covers products already available on the market before December 2027, not only future ones.

wallets cripto crypto

Deadlines Set by the EU

The tiered reporting scheme establishes four stages. Within the first 24 hours, an early warning must be sent indicating the member states where the affected product is available. Within 72 hours, the nature of the exploit, the mitigation measures adopted, and the recommended actions for users must be detailed. At 14 days, the final report on the exploited vulnerability is submitted, once a fix is available. At one month, the definitive report on the serious incident must be completed.

The 24-hour clock does not start upon the mere receipt of a report from a security researcher. The obligation begins when the manufacturer confirms that the flaw is being actively exploited. Until that point, the company may investigate and prepare a patch without incurring any regulatory obligation.

Coldcard

Crypto Wallets: The Coldcard Case

For crypto wallets, the availability of an update does not always bring the incident to a close. The case of Coldcard in July illustrated this distinction: a firmware fix did not protect seeds generated under the compromised software, forcing users to create new keys and move funds to secure wallets. Under the CRA, that operational process will now run in parallel with mandatory notification to the authorities.

The initial report is also not equivalent to public disclosure. The information sent to the CSIRT and ENISA is subject to confidentiality protection, including source code and trade secrets. Public disclosure only proceeds when necessary to prevent or mitigate a serious incident, and generally requires prior consultation with the manufacturer.

Open-source projects are not exempt either. If a free product is placed on the market in the context of a commercial activity, the manufacturer retains its obligations under the CRA.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews