EU cyber rules put crypto wallet makers on 24-hour reporting clock
Crypto wallet providers must submit an early vulnerability report within 24 hours and a full notification within 72 hours of exploits, or risk administrative fines of as much as $17.3 million.

Crypto wallet providers must submit an early vulnerability report within 24 hours and a full notification within 72 hours of exploits, or risk administrative fines of as much as $17.3 million.
The EU is telling cryptocurrency hardware and software wallet providers that they have 24 hours from awareness to report actively exploited bugs or severe security vulnerabilities affecting their products.
The measure is part of the EU’s Cyber Resilience Act (CRA), which took effect on Friday, according to an announcement from the European Commission.
Companies that fail to adhere to the cybersecurity measures under Articles 13 and 14 may face an administrative fine of up to 15 million euros ($17.3 million) or 2.5% of worldwide annual turnover, depending on which figure is higher, according to the penalties section of the final draft.