NewsTradingSentimentCalendarCommunityBriefing
Markets

EU Mandates 24 Hour Breach Reporting for Crypto Wallets

By Markets Desk · 2026-09-13 · 2 min read
A digital padlock icon hovering over a stylized smartphone screen
Illustration: Tradingbird

Manufacturers of connected crypto wallets must now notify regulators within 24 hours of discovering an exploited flaw. The new rule under the Cyber Resilience Act applies to products already on the market.

Manufacturers of connected crypto wallets must now notify regulators within 24 hours of discovering an actively exploited vulnerability. This requirement took effect on September 11, 2026. It applies to hardware wallets and software available in the European Union. The rule targets products with digital elements connected to a network. According to GN markets/crypto (en-US), this covers commercially supplied wallet apps and devices.

The deadline for the initial warning is strict. It starts when the manufacturer becomes aware of the incident. The report must identify member states where the product is sold. It must also state if malicious acts are suspected. A more detailed notification is due within 72 hours. This filing includes details on the exploit and corrective measures. The final report deadline varies by the type of incident.

Reporting duties apply to existing products

The new reporting rule reaches products placed on the market before December 11, 2027. This means existing product lines are immediately subject to the 24 hour clock. The broader product security requirements of the law start later. The rapid reporting regime begins now. Manufacturers must file through the Single Reporting Platform. This portal is managed by the EU cybersecurity agency ENISA. The platform distributes information to national computer security incident response teams.

Manufacturers must also inform impacted users directly. They must provide guidance on necessary actions. This includes specific measures users can take to protect their assets. The obligation extends to all users when general action is needed. This ensures that the market remains informed during a security crisis.

Open source projects face new obligations

Open source licensing does not provide a blanket exemption. Commercially supplied free and open source products may face manufacturer duties. Non monetized software supplied by its manufacturer is treated differently. Individual contributors are not treated as manufacturers for software outside their responsibility. Open source software stewards are a separate legal category. Their specific reporting duties begin on December 11, 2027. This date aligns with the start of the main product security requirements.

Regulatory scope depends on product design

EU guidance does not name specific wallet brands. Coverage depends on the specific product and how it is supplied. The legal test requires a direct or indirect data connection. A downloadable wallet app can meet this test. A commercially supplied connected hardware wallet also qualifies. Manufacturers must assess their specific product against these criteria. They must determine if their item falls under the horizontal product law. This assessment is critical for compliance with the new timelines.

Based on reporting by CryptoSlate, compiled by the Tradingbird desk.

More from the Markets desk

All desk stories