Regulation & Policy
Share
The EU's Cyber Resilience Act now requires crypto wallet providers to report actively exploited vulnerabilities within 24 hours, with fines up to €15 million for non-compliance, as incidents at Trezor, BitBox, and Revolut underscore the urgency of these obligations.
Crypto wallet providers operating in the European Union are facing tighter cybersecurity obligations under new rules that require companies to report actively exploited vulnerabilities within hours of becoming aware of them.
The requirements took effect Friday under the EU’s Cyber Resilience Act (CRA), bringing products with digital elements sold or made available in the bloc under a common cybersecurity framework.
For cryptocurrency hardware and software wallet providers, the rules introduce a compressed reporting timeline: companies must submit an initial warning about a severe vulnerability within 24 hours, followed by a more detailed notification within 72 hours.
The European Commission said the measures are designed to strengthen protection for consumers and businesses against cyber threats.
The CRA establishes several reporting stages for serious cybersecurity incidents.
Once a company becomes aware of an actively exploited vulnerability or severe security issue, it has 24 hours to submit an early warning. A fuller notification must follow within 72 hours.
A final report is then required 14 days after corrective or mitigating measures become available. For severe incidents, the final notification must be submitted within one month.
The requirements apply broadly to products with digital elements made available in the EU, meaning their impact extends beyond crypto wallets to a wide range of connected hardware and software.
For wallet manufacturers, however, the timing is particularly significant given the consequences that security vulnerabilities can have for users holding digital assets.
The financial consequences of failing to comply could be substantial.
Under the CRA's penalty provisions, companies that breach the relevant cybersecurity requirements can face administrative fines of up to €15 million ($17.3 million) or 2.5% of their total worldwide annual turnover, with the higher amount applying.
Providing information that is incorrect, incomplete or misleading can also result in fines of up to €5 million.
That raises the stakes for crypto wallet companies, which will need to identify serious vulnerabilities quickly, determine whether they meet the reporting threshold and provide regulators with information within tightly defined deadlines.
The new requirements also shift cybersecurity reporting closer to the front line of product operations. Instead of treating vulnerabilities solely as technical issues to be addressed internally, companies must account for regulatory reporting from the moment a serious incident comes to light.
The EU's new requirements arrive amid a series of cybersecurity incidents involving crypto wallet providers and their users.
Hardware wallet maker Trezor disclosed earlier this month that an additional 67,000 US customers could be exposed following a data breach at its shipping provider, ShipMonk. The figure was significantly higher than the company's initial estimate of 14,000 affected users.
Trezor and BitBox subsequently warned customers about phishing emails posing as urgent security communications after suspected compromises involving third-party email services.
In another incident, blockchain network Zilliqa disclosed in June that a vulnerability affecting its Ledger application could potentially allow attackers to recover users' private keys using publicly available onchain information.
The incidents illustrate the range of threats facing crypto users. Security failures do not necessarily have to originate within a wallet's core software to create risks; weaknesses at suppliers, communications systems or connected services can also expose customers to attacks.
The broader financial technology sector has also faced a recent data-security incident that underscores the risks surrounding sensitive customer information.
Revolut disclosed that an unauthorized party obtained access to sensitive customer data after submitting fraudulent information requests using an email address from a legitimate government agency domain.
The exposed information reportedly included passport copies, verification selfies and full transaction histories belonging to a limited number of customers.
According to the company, the fraudulent requests passed its authentication checks before the firm determined that they were not genuine.
Revolut said it subsequently blocked the address, alerted the government agency involved and notified law enforcement and financial regulators. The company also said that its systems and customer funds were not affected and that it contacted impacted customers directly.
Crypto investigator ZachXBT reportedly assessed the incident as limited in scope and suggested that high-net-worth individuals may have been targeted.
The Revolut incident highlights a different dimension of the cybersecurity challenge: even when core financial systems and customer funds remain secure, the exposure of identity and transaction data can create significant risks for users.
That concern is particularly relevant to crypto companies operating under increasingly comprehensive compliance and cybersecurity regimes.
The CRA does not specifically target cryptocurrencies. Instead, it establishes cybersecurity obligations across products with digital components. Crypto wallet providers fall within that broader framework because their products combine software, hardware and connectivity with systems that can directly affect users' access to digital assets.
The 24-hour reporting requirement could therefore become an important test of how quickly wallet companies can detect, assess and disclose serious vulnerabilities.
For the crypto industry, the regulation also reinforces a broader shift: cybersecurity is increasingly becoming a regulatory requirement rather than simply a product-development priority. Companies will need not only to secure wallets and digital infrastructure, but also to build the internal processes necessary to identify incidents and meet strict disclosure deadlines.
Disclaimer of Warranty
The information provided in this article is for general informational purposes only. We make no warranties about the completeness, reliability, and accuracy of this information. Read full disclaimer
Editor's Picks

Why Zondacrypto’s Collapse Would Unfold Differently in the UAE
Walid Abou Zaki
Aug 28, 2026
8 min

The Missing Orchestration Layer Holding Back Institutional Digital Assets
Julian Sawyer
Aug 18, 2026
5 min

Beyond Crypto Access: How ARP Digital Is Building the UAE’s Digital Capital Infrastructure
Anna K.
Aug 17, 2026
8 min
Read More Articles
In the Same Space

Kalshi's Bid for Non-Stop Stock Perpetuals Reignites CFTC-SEC Turf War
News Desk
Sep 11, 2026
8 min

Iran Turns to Crypto as Sanctions Bite, But USDT Has a Control Problem
Salma Naueihed
Sep 9, 2026
5 min

US and UK Launch Joint Effort to Tackle Crypto Investment Fraud
News Desk
Sep 4, 2026
5 min

CFTC Seeks Dismissal of CME Challenge to Kalshi Bitcoin Perpetuals
News Desk
Sep 3, 2026
4 min



