Crypto wallet makers selling in the EU must now alert cyber regulators within 24 hours if they discover an exploited security flaw, as the Cyber Resilience Act's rapid reporting regime takes effect for both hardware and software wallets.
Crypto wallet manufacturers selling in the European Union now face a strict deadline. Starting September 11, 2026, any company offering connected hardware wallets or wallet software in the EU must notify cyber authorities within 24 hours if they discover a vulnerability that has already been exploited or a serious security incident. This shifts wallet makers from voluntary disclosure to mandatory, rapid reporting.
Mandatory rapid disclosure
The new rules, part of the Cyber Resilience Act (CRA), apply to commercial manufacturers whose products-hardware devices or downloadable wallet apps-are available in the EU and connect to a network. The law covers a wide range of products, but not all: it depends on how the product is used, distributed, and whether it is a commercial offering. Open-source wallets are not automatically exempt, especially if supplied commercially, even for free. Individual open-source contributors are generally not considered manufacturers, but open-source project maintainers will have their own reporting duties starting December 11, 2027.
ENISA's Single Reporting Platform, launched on September 11, 2026, is now the mandatory EU intake point for all actively exploited wallet vulnerabilities and severe incidents.
ENISA
How the reporting process works
When a manufacturer learns of an exploited vulnerability or major incident, the first notification must be filed through ENISA's Single Reporting Platform, the EU's cybersecurity agency. This alert is due within 24 hours and must include the affected product, the nature of the vulnerability or incident, and the EU countries where the product is available. If the incident is severe, the report should also state whether unlawful or malicious activity is suspected. A more detailed follow-up is required within 72 hours, covering technical details, mitigation steps, and an initial assessment. Final reports are due within 14 days of a fix for vulnerabilities, or one month after the 72-hour notification for severe incidents.
Impact on wallet providers and users
The rules apply to products already on the market before December 11, 2027, not just new releases. Wallet manufacturers must address legacy devices and software still in use. Companies are also required to inform affected users directly, and all users if action is needed to protect their assets. The regulatory push comes as wallet security remains a concern: even after major botnet takedowns, malware and exploits continue to threaten user funds, as reported earlier.
Compliance and enforcement risks
Failing to meet the CRA's rapid reporting requirements can lead to regulatory penalties, product bans, or reputational harm. The law's broad approach means any product with digital elements and a network connection-regardless of brand or distribution channel-may be covered if supplied commercially in the EU. The Commission's guidance leaves some room for interpretation, but the message is clear: wallet providers in the European market can no longer rely on voluntary or delayed disclosure.
The CRA's reporting regime covers both hardware and software wallets, including those already on the market before December 2027. The law's scope extends to standalone apps and SaaS-connected devices, not just traditional hardware, making it one of the most comprehensive digital product regulations in the EU.
CoinDesk (source)
The European Commission says the Cyber Resilience Act's rapid reporting regime is now in force, while broader product-security requirements-including secure design and lifecycle management-will take effect on December 11, 2027. The new rules aim to close gaps in incident response and user notification, reducing the window of exposure for wallet users and limiting the spread of active exploits. For U.S. wallet makers and software developers, the regulation sets a new standard for incident transparency and may influence global practices, even if not directly enforceable outside the EU.
ENISA's Single Reporting Platform is now the main hub for incident notifications, automatically routing reports to national Computer Security Incident Response Teams and making information available to relevant authorities. The system is designed to streamline cross-border coordination and ensure that regulators and users get timely, actionable information about wallet vulnerabilities and attacks.
Wallet security remains a challenge for both users and manufacturers. Unlike custodial exchanges, self-custody wallets put the responsibility for key management and software updates on the user, making timely vulnerability disclosure essential. The new EU rules require wallet providers to prioritize transparency and quick response, but also raise the stakes for compliance failures. As regulatory expectations increase, wallet makers will need to invest in security monitoring, incident response, and user communication or risk losing access to one of the world's largest crypto markets.
Under the Cyber Resilience Act, the definition of "manufacturer" is key. Commercially supplied wallets-hardware or software-are covered if they are intended for use with a network connection and are available in the EU. Open-source projects are only exempt if they are non-commercial and not supplied by a manufacturer. This means many wallet projects previously outside product regulation may now face direct legal obligations, especially as the EU enforces stricter standards for digital products handling sensitive financial data.