Crypto news report · source clearly identified
EU Requires Crypto Wallet Makers to Notify Regulators Within 24 Hours of Exploited Flaws
Qualifying commercial wallet hardware and software now face a rapid three-stage reporting process for serious security events.

Effective September 11, 2026, the European Union’s Cyber Resilience Act (CRA) imposes a strict reporting timeline on manufacturers of connected hardware wallets and wallet software that are placed on the EU market.
Scope of the Requirement
The rule applies to commercial products that include digital elements and have a direct or indirect data connection to a device or network. Both hardware wallets and downloadable wallet applications can fall within this scope, though coverage depends on the specific product, its supply chain, and any applicable exclusions.
Reporting Timeline
- Initial warning: Must be submitted within 24 hours of becoming aware of an actively exploited vulnerability or a severe security incident.
- Follow‑up notification: Due within 72 hours, providing more detail about the product, the exploit, and any mitigation measures.
- Final report: For vulnerabilities, due within 14 days after a corrective measure is available; for severe incidents, due within one month after the 72‑hour notification.
Content of the Reports
The early warning must identify the EU member states where the product is available and, for severe incidents, indicate whether unlawful or malicious activity is suspected. Subsequent filings add technical details, initial assessments, and recommended mitigation steps. All reports are filed through the Single Reporting Platform operated by ENISA, which forwards the information to national Computer Security Incident Response Teams and makes it accessible to ENISA.
Obligations to Users
Manufacturers must also inform affected users directly and, when necessary, all users of the product about required actions and protective measures.
Applicability to Existing Products and Open‑Source Software
The reporting obligations cover products placed on the market before December 11, 2027, meaning many existing wallet lines are subject to the new timeline. Open‑source licensing does not automatically exempt commercial products; however, non‑monetized software provided by its developers is not considered a commercial activity, and individual contributors are not treated as manufacturers under the CRA.
Source & attribution
News Source
- Publisher
- CryptoSlate
- Original date
- September 13, 2026, 11:45 AM
- Original headline
- Crypto wallet creators now have just 24 hours to alert regulators when flaws are exploited