Key Takeaways
Crypto wallet makers operating in the European Union now face a 24-hour clock to report actively exploited security vulnerabilities as a major part of the bloc’s Cyber Resilience Act (CRA) comes into force.
The reporting requirements became applicable on Sept. 11, 2026, extending the EU’s cybersecurity oversight across products containing digital elements.
That potentially brings hardware wallets, wallet applications and other crypto-related software products within the framework when they meet the CRA’s scope.
The rules arrive as cyber risk remains a growing concern for European regulators.
The European Securities and Markets Authority (ESMA) warned last week that operational risks across financial markets were at a “very high level and rising,” pointing partly to cyber threats and advances in artificial intelligence.
+245
Ethereum
Tether
Build'N'Build
USD Coin
Solana
Ripple
Dogecoin
Cardano
Toncoin
Shiba Inu
Avalanche
TRON
Chainlink
Polygon Matic
Polkadot
Wrapped Bitcoin
Litecoin
Dai
NEAR Protocol
Bitcoin Cash
Monero
Stellar
Cosmos
Filecoin
Ethereum Classic
Aptos
Hedera Hashgraph
Immutable
Optimism
Arbitrum
VeChain
The Sandbox
Decentraland
Axie Infinity
Injective Protocol
Render Token
The Graph
Maker
Aave
Chiliz
Helium
PAX Gold
Compound
Lido DAO Token
THORChain
Stacks
Arweave
Sui
Conflux Network
Lido Staked ETH
Bitget Token
Wrapped Ethereum
OKB
Uniswap
Pepe
Ondo
Mantle
First Digital USD
Bittensor
Kaspa
Celestia
XDC Network
Artificial Superintelligence Alliance
Jupiter
Quant
Worldcoin
PayPal USD
Bonk
Rocket Pool ETH
Flare
Tether Gold
Sei
JITO
JasmyCoin
PancakeSwap
Core
Floki Inu
Ethereum Name Service
SushiSwap
Kava.io
1inch Network
Tezos
Algorand
Flow
Trust Wallet Token
Curve DAO Token
KuCoin Token
MultiversX
GateToken
Zcash
IOTA
Basic Attention Token
Enjin Coin
Frax
Ethena
Ethena USDe
Ethena Staked USDe
BlackRock USD Institutional Digital Liquidity Fund
Fasttoken
Pi Network
SATS
Adventure Gold
Audius
Acala Token
Alchemy Pay
Arkham
API3
Bounce Token
Bitcoin
Altlayer
Aergo
Amp
Aevo
ARPA Chain
Astar
Ark
Ankr
AirSwap
Axelar
Alpaca Finance
SingularityNET
Blur
Beam
Badger DAO
Bancor
BakeryToken
Biconomy
Chromia
Tranchess
Celer Network
Celo
Shentu
Civic
Convex Finance
Cartesi
Cyber
COTI
DigiByte
DIA
Dymension
dYdX
ether.fi
FUNToken
FLUX
Firo
Ampleforth Governance Token
Golem
GMX
Gnosis
Gitcoin
Moonbeam
Holo
IoTex
ICON
Illuvium
JUST
Kadena
Kusama
Liquity
Livepeer
Lisk
Memecoin
Manta Network
Treasure
Mask Network
MetisDAO
NKN
Neutron
Ocean Protocol
Origin Protocol
ORDI
Ontology
Osmosis
Powerledger
Phala Network
Pendle
Portal
Pyth Network
ConstitutionDAO
Polkastarter
Qtum
iExec RLC
Rocket Pool
Reserve Rights
Ronin
Ravencoin
Starknet
Storj
Status
Spell Token
Sun (New)
Saga
SuperVerse
Toko Token
Theta Fuel
Tellor
Tensor
Unstoppable Ecosystem Token
Wrapped BNB
LayerZero
Scroll
Usual
Cetus Protocol
Eigenlayer
Hamster Kombat
Catizen
Berachain
KAITO
Pudgy Penguins
Vana
Solayer
Bio Protocol
ChainGPT
Cookie DAO
Solv Protocol
Alchemix
Bitcoin SV
Usual USD
Movement
DeXe
Kelp DAO Restaked ETH
Binance Staked SOL
Nexo
Solv Protocol BTC
Tokenize Xchange
Wrapped eETH
Hyperliquid
Casper
Zilliqa
Secret
Nervos Network
TrueUSD
EOS
BitTorrent
Mina
Dash
STEPN
Gemini Dollar
UNUS SED LEO
Synthetix
Neo
APEcoin
Gala
Theta Network
Fantom
Cronos
Internet Computer
Binance USD
+96
Bitcoin
Ethereum
Tether
Build'N'Build
USD Coin
Solana
Ripple
Dogecoin
Cardano
Toncoin
Shiba Inu
Avalanche
TRON
Chainlink
Polygon Ecosystem Token
Polkadot
Wrapped Bitcoin
Litecoin
Dai
NEAR Protocol
Bitcoin Cash
Monero
Stellar
Cosmos
Filecoin
Ethereum Classic
Aptos
Hedera Hashgraph
Immutable
Optimism
Arbitrum
VeChain
The Sandbox
Decentraland
Axie Infinity
Injective Protocol
Render Token
The Graph
Maker
Aave
Chiliz
Helium
PAX Gold
Compound
Lido DAO Token
THORChain
Stacks
Arweave
Sui
Conflux Network
Lido Staked ETH
Bitget Token
Wrapped Ethereum
OKB
Uniswap
Pepe
Ondo
Mantle
First Digital USD
Bittensor
Kaspa
Celestia
XDC Network
Artificial Superintelligence Alliance
Jupiter
Quant
Worldcoin
PayPal USD
Bonk
Rocket Pool ETH
Flare
Tether Gold
Sei
JITO
JasmyCoin
PancakeSwap
Core
Floki Inu
Ethereum Name Service
SushiSwap
Kava.io
1inch Network
Tezos
Algorand
Flow
Trust Wallet Token
Curve DAO Token
KuCoin Token
MultiversX
GateToken
Zcash
IOTA
Basic Attention Token
Enjin Coin
Frax
Ethena
Ethena USDe
Ethena Staked USDe
BlackRock USD Institutional Digital Liquidity Fund
Fasttoken
Pi Network
+95
Bitcoin
Ethereum
Tether
Build'N'Build
USD Coin
Solana
Ripple
Dogecoin
Cardano
Toncoin
Shiba Inu
Avalanche
TRON
Chainlink
Polygon Ecosystem Token
Polkadot
Wrapped Bitcoin
Litecoin
Dai
NEAR Protocol
Bitcoin Cash
Monero
Cosmos
Filecoin
Ethereum Classic
Aptos
Hedera Hashgraph
Immutable
Optimism
Arbitrum
VeChain
The Sandbox
Decentraland
Axie Infinity
Injective Protocol
Render Token
The Graph
Maker
Aave
Chiliz
Helium
PAX Gold
Compound
Lido DAO Token
THORChain
Stacks
Arweave
Sui
Conflux Network
Lido Staked ETH
Bitget Token
Wrapped Ethereum
OKB
Uniswap
Pepe
Ondo
Mantle
First Digital USD
Bittensor
Kaspa
Celestia
XDC Network
Artificial Superintelligence Alliance
Jupiter
Quant
Worldcoin
PayPal USD
Bonk
Rocket Pool ETH
Flare
Tether Gold
Sei
JITO
JasmyCoin
PancakeSwap
Core
Floki Inu
Ethereum Name Service
SushiSwap
Kava.io
1inch Network
Tezos
Algorand
Flow
Trust Wallet Token
Curve DAO Token
KuCoin Token
MultiversX
GateToken
Zcash
IOTA
Basic Attention Token
Enjin Coin
Frax
Ethena
Ethena USDe
Ethena Staked USDe
BlackRock USD Institutional Digital Liquidity Fund
Fasttoken
Pi Network
Under the CRA, manufacturers must submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe security incident affecting a covered product.
A more detailed notification is then required within 72 hours.
🇪🇺 EU Mandates 24-Hour Flaw Reporting for Crypto Wallets
Hardware and software walletmakers in the EU must now disclose actively exploited vulnerabilities within 24 hours.
– In Scope: Commercial hardware & downloadable software wallets
– Timeline: 24h initial alert / 72h… pic.twitter.com/pjLqSvOCPf
— Captain GM (@g13m) September 14, 2026
For exploited vulnerabilities, manufacturers must also provide a final report no later than 14 days after a corrective or mitigating measure becomes available. Severe incidents require a final report within one month of the 72-hour notification.
Reports are submitted through the CRA Single Reporting Platform established by the European Union Agency for Cybersecurity (ENISA), which became operational alongside the reporting rules on Sept. 11.
Importantly, the requirements can cover products already on the EU market, rather than applying only to products launched after the new rules took effect.
The financial consequences could be significant.
Violations of key CRA cybersecurity obligations can carry administrative fines of up to €15 million ($17.3 million) or 2.5% of a company’s total worldwide annual turnover from the preceding financial year, whichever is higher.
That makes the regime particularly relevant to major wallet manufacturers and software providers serving EU customers.
The EU CRA requires formal documentation built during the product lifecycle.
The EU CRA's December 2027 deadline requires a governed open source inventory, current SBOM coverage, and an audit trail for every remediation decision. You can't build that once a vulnerability is… pic.twitter.com/YyDdcTqsT2
— The Hacker News (@TheHackersNews) September 14, 2026
However, the CRA is broader than crypto regulation. It covers connected hardware and software products ranging from consumer applications and smart devices to security products.
The European Commission says its goal is to make manufacturers responsible for cybersecurity throughout a product’s lifecycle.
For crypto companies, the CRA adds another layer to an increasingly dense European regulatory framework.
Crypto-asset service providers are already subject to the EU’s Markets in Crypto-Assets Regulation (MiCA), while financial entities covered by the Digital Operational Resilience Act (DORA) face separate requirements for managing and reporting major ICT incidents.
Today, September 11, the EU’s Cyber Resilience Act (CRA) reporting obligations go live. If you place connected products on the EU market, you're now required to report actively exploited vulnerabilities and severe incidents.
This is the first hard CRA deadline. Full compliance… pic.twitter.com/MUWCFu0IJx
— Canonical (@Canonical) September 11, 2026
DORA’s reporting framework can similarly require an initial notification no later than 24 hours after an entity becomes aware of an incident.
The CRA changes the equation for wallet security by focusing directly on the products themselves.
For wallet providers, discovering an actively exploited vulnerability is therefore no longer simply a race to patch users’ software or firmware. In the EU, it can also start a regulatory countdown measured in hours.
Giuseppe Ciccomascolo began his career as an investigative journalist in Italy, where he contributed to both local and national newspapers, focusing on various financial sectors.
Upon relocating to London, he worked as an analyst for Fitch's CapitalStructure and later as a Senior Reporter for Alliance News. In 2017, Giuseppe transitioned to covering cryptocurrency-related news, producing documentaries and articles on Bitcoin and other emerging digital currencies. He also played a pivotal role in establishing the academy for a cryptocurrency exchange website. Crypto remained his primary area of interest throughout his tenure as a writer for ThirdFloor.
You’re All Set!
Thanks for signing up. We’ll be in touch soon with the latest insights.
