EU Mandates 24-Hour Reporting of Severe Crypto Wallet Vulnerabilities

The European Union (EU) has mandated that virtual asset hardware and software wallet providers report severe security vulnerabilities or actual exploitation incidents to authorities within 24 hours.
According to CoinTelegraph, the EU Executive Commission (EC) began enforcing new reporting requirements under the Cyber Resilience Act (CRA) on November 11.
Wallet manufacturers operating in the EU must submit an early alert within 24 hours of discovering a vulnerability being actively exploited or a critical security issue. A formal report must follow within 72 hours.
Subsequent reporting obligations also apply. After implementing fixes for vulnerabilities, companies must submit a final report within 14 days. For severe security incidents, a final report is required within one month.
Non-compliance could result in significant fines. Companies failing to comply with CRA Articles 13 and 14 may face penalties of up to €15 million (approximately $17.3 million) or 2.5% of global annual revenue, whichever is higher. Fines of up to €5 million also apply for submitting inaccurate or incomplete information.
The regulation comes amid a series of recent security incidents involving virtual asset hardware wallets. Trezor reported on November 4 that a data breach at shipping company ShipMonk exposed an additional 67,000 U.S. customers to potential risk—significantly more than the initial estimate of 14,000.
Trezor and BitBox have also warned users about phishing emails masquerading as urgent security notices following concerns over third-party email service vulnerabilities.
Earlier this June, Layer-1 blockchain Zilliqa had cautioned that attackers could potentially recover user private keys using a vulnerability in the Zilliqa Ledger application to access publicly available on-chain data.
The EU Executive Commission stated that these reporting requirements apply to all digital products containing 'digital elements' sold in the EU market, aiming to protect both consumers and businesses from cyber threats.
Korean Source
This article is an English localization of a Korean-language crypto news report. Original headline: EU, 가상자산 지갑 보안 취약점 '24시간 내' 신고 의무화…위반 시 최대 240억원 과징금