The EU Cyber Resilience Act now requires covered commercial crypto wallet makers to file an early warning within 24 hours of learning that a flaw in their product is being actively exploited. This is a reporting rule, not a demand to fix the bug in a single day, and it applies only to wallets that fall inside the law’s commercial scope.
The rule is part of the European Union’s Cyber Resilience Act, formally Regulation (EU) 2024/2847. It sets cybersecurity duties for products that connect to devices or networks. For crypto wallet makers, the headline change is a very short clock that starts the moment they become aware of an attack in progress. For related coverage, see ESMA Launches Crypto Custody Review for EU CASPs.
Key Takeaways
- The rule applies to covered commercial crypto wallet makers, not to every wallet or developer.
- Awareness of active exploitation starts the 24-hour reporting window.
- The deadline is a reporting deadline, not a deadline to patch the flaw.
What starts the 24-hour reporting clock?
The clock starts when a manufacturer becomes aware of an actively exploited vulnerability or a severe incident affecting its product. From that point, the maker has 24 hours to submit an early warning. For related coverage, see Sality Botnet Disruption: Crypto Address Swaps May Persist.
EU Cyber Resilience Act · Early warning after awareness
24 hours
The trigger is narrow. It covers flaws that attackers are actually using, not every bug a developer might discover during routine testing. Legal experts at Freshfields explain that active exploitation requires reliable evidence of exploitation by a malicious actor without the system owner’s permission.
This is important to understand clearly. The 24-hour window is a duty to warn regulators, not a duty to have a fix ready. A wallet maker can report an attack in progress while still investigating and building a patch.
The early warning is only the first stage. A full notification must follow within 72 hours of awareness, which is a separate step from the 24-hour warning.
EU Cyber Resilience Act · Full notification after awareness
72 hours
Later stages follow too. For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective measure is available. For a severe incident, the final report is due within one month of the 72-hour notification.
These reporting duties began on 11 September 2026. The wider set of Cyber Resilience Act obligations applies later, from 11 December 2027, after the regulation entered into force on 10 December 2024.
Which commercial crypto wallet makers are covered?
The rule reaches products with digital elements made available on the EU market. That means products whose intended or foreseeable use includes a data connection to a device or network, which describes most crypto wallet software and hardware.
The word “commercial” matters. Making a product available on the market means supply in the course of a commercial activity, whether the product is paid or free. Software given away at no cost can still fall inside the scope if it is supplied commercially.
Products that are not supplied in a commercial activity sit outside this scope. That is one reason the reporting rule sits alongside broader concerns about wallet security, which readers can see in cases like malware that targeted more than 50 crypto wallets.
Coverage of any single wallet is still a case-by-case question. The Commission material does not classify specific wallet products, so no fetched source confirms that a named hardware wallet, software wallet, or hosted service is covered or exempt.
Open-source projects sit in a separate lane. Open-source software stewards become subject to their own Article 24(3) reporting obligations from 11 December 2027, and stewards are not subject to Cyber Resilience Act infringement penalties.
There is also a size-based softening. The Commission summary says manufacturers that qualify as microenterprises or small enterprises may not be fined for missing the 24-hour deadline, though this does not remove their duty to report. The scope debate mirrors questions raised in the EU’s parallel resilience review of MiCA crypto custodians.
What the reporting window means for wallet makers
A one-day window leaves almost no time to build a process after an attack begins. Freshfields analysts noted that the short reporting windows leave little room to establish processes after an event occurs.
The clock also does not pause. Freshfields explains that weekends and public holidays do not stop the reporting deadline from running.
Practical preparation matters more than reaction. Wallet teams can decide in advance how to record the exact moment awareness arises, how to escalate to a responsible team, and how to assemble incident information quickly.
It helps to separate the jobs. Reporting to regulators is one task; investigating the attack and remediating the flaw is a different task that runs on its own timeline. The rise in targeted attacks, including North Korean crypto theft that has outpaced compliance, shows why fast internal escalation is worth planning now.
The reporting path is centralized. Manufacturers report once through the Cyber Resilience Act Single Reporting Platform, addressed to the relevant national CSIRT, with information made available to ENISA at the same time except in particularly exceptional circumstances. The rule also covers products already placed on the EU market before 11 December 2027.
One caution for wallet holders. Filing a report does not guarantee that a wallet is safe or that user funds are protected; it simply gives authorities early notice of an attack in progress. Required report fields, submission details, and any customer-notification duties should be confirmed against official guidance before anyone treats them as settled.
For a regular crypto holder, the practical takeaway is simple. If you use a wallet from a company operating in the EU, that maker may now owe regulators fast notice when attackers strike, which adds a layer of oversight that did not exist before 11 September 2026.
Additional source references: source document 1.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.