Crypto wallet manufacturers selling into the European Union are now legally required to alert regulators within 24 hours of learning that a vulnerability in one of their products is being actively exploited. The obligation comes from Article 14 of the Cyber Resilience Act, the bloc's flagship cybersecurity rule for connected hardware and software, whose vulnerability and incident reporting provisions took effect on September 11, 2026 — more than a year before the regulation's broader product requirements become applicable in December 2027.
The date has drawn wide coverage across crypto and compliance outlets this week, including CryptoSlate, Crowdfund Insider and law-firm analyses. The regulation itself — Regulation (EU) 2024/2847 — has been in force since December 2024, but its reporting duties were staged to begin 24 months later.
What the 24-Hour Deadline Requires
Article 14 covers manufacturers of "products with digital elements" — a category that sweeps in hardware wallets and commercial wallet software, because such products connect to devices and networks. When a manufacturer becomes aware that a vulnerability is being actively exploited, or that a severe incident has affected product security, it must:
- Submit an early warning notification to ENISA, the EU Agency for Cybersecurity, and the relevant national CSIRT within 24 hours
- Follow with a fuller vulnerability or incident notification within 72 hours
- File a final report within 14 days of a corrective or mitigating measure becoming available
Reports are filed once, through the CRA Single Reporting Platform operated by ENISA in cooperation with the CSIRT network — not separately to every member state.
Why the Timing Matters for Crypto
The deadline lands at the end of the worst stretch for wallet security in years. The Coldcard firmware flaw has drained more than $115 million from users, with the suspected wave-three exploiter still moving funds through THORChain and CoinJoin rounds, according to Galaxy Research's on-chain tracking. Trezor has spent two weeks disclosing a breach at its fulfillment partner that exposed tens of thousands of US customer records. And the Liquid Network — a federation used by exchanges — is running again after a proof-verification cache bug let attackers drain roughly 4,000 BTC, with peg-outs still frozen.
None of those disclosures ran on a 24-hour regulator-facing clock. Under the new regime, a wallet maker that discovers its firmware is being exploited in the wild must alert ENISA within a day — before it may fully understand root cause, scope or remediation — rather than controlling the disclosure timeline itself.
The Fine Print
The September 11 date applies only to the reporting obligations. The CRA's wider duties — security-by-design requirements, conformity assessment and CE marking — do not apply until December 11, 2027.
The regime also builds in relief for smaller firms: administrative fines for missing the 24-hour early-warning deadline do not apply to microenterprises and small enterprises, although the reporting obligation itself still stands. For larger manufacturers, non-compliance can draw enforcement action from national market surveillance authorities once the full framework is in force.
One boundary worth noting: the duty attaches to the manufacturer of a product with digital elements. It does not directly govern protocols, DAOs or open-source projects that ship no commercial product — a line that leaves much of the DeFi incident landscape outside this particular clock.
From Etiquette to Law
The change converts what has been a norms debate into a legal duty. Just last week, Ledger and Trezor executives were publicly arguing over responsible-disclosure etiquette in the AI era — Ledger's CTO criticizing researchers who publish before fixes exist, Trezor's security chief countering that 90-day timelines bind vendors, not researchers. The CRA answers part of that argument from the other direction: whatever researchers do, the vendor's clock starts when exploitation is confirmed.
For wallet makers, the practical work is internal: knowing who decides, who files and who signs off when a flaw goes from "reported" to "exploited" — because the first filing is now due before the investigation is comfortable, not after.
TrustGrade tracks the security posture of wallet vendors, protocols and exchanges. Security scans with verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.