Crypto wallet manufacturers must report security exploits to EU regulators within 24 hours
Under the European Union's Cyber Resilience Act (CRA), which took effect on September 11, 2026, commercial manufacturers of connected hardware wallets and wallet software are now required to notify cyber authorities within 24 hours of discovering an actively exploited vulnerability or severe security incident. This regulation applies to products with digital elements that connect to devices or networks. Manufacturers must provide an initial warning within 24 hours, followed by a more detailed notification within 72 hours, including information on the nature of the incident, the exploit, and any corrective measures taken.
Summaries are written by AI from the original article. Not investment advice.