EU Crypto Wallet Makers Now Have 24 Hours to Report Exploits

EU crypto-wallet makers may now face a 24-hour reporting clock when they discover an actively exploited flaw or severe incident affecting products sold in Europe.
Key Takeaways
- Reporting starts only after active exploitation.
- First warning arrives within 24 hours.
- Commercial wallet products are likely covered.
- Most CRA rules start December 2027.
The 24-hour reporting rule starts before the wider CRA
From September 11, manufacturers must report actively exploited vulnerabilities and severe security incidents affecting products with digital elements made available on the EU market. The report is submitted through the Single Reporting Platform operated by ENISA to the CSIRT in the Member State of the manufacturer’s main establishment and, in normal circumstances, to ENISA.
Most of the EU Cyber Resilience Act (CRA) applies from December 11, 2027, including its wider requirements around product design, documentation and conformity. Article 14, the provision covering exploited vulnerabilities and severe incidents, starts earlier.
That means a wallet company may not yet face the full CRA compliance regime, but it can already have a statutory deadline if an exploit is active. The requirement also applies to in-scope products made available in the EU before December 2027, not only to future devices and software releases.
Hardware and software wallets may be covered
The CRA applies to hardware and software products made available commercially in the EU when their intended or reasonably foreseeable use includes a direct or indirect logical or physical connection to a device or network. Commercial hardware wallets and desktop or mobile wallet applications could therefore fall within scope.
The legal obligation sits with the manufacturer: the person or company that develops a product, or has it developed, and markets it under its own name or trademark. A business selling a hardware device or distributing wallet software in the EU is a clearer example than an individual contributor to an unrelated open-source project.
Because crypto wallets are not named in the CRA, a specific product’s status may still require a legal assessment.
The CRA reporting timeline after a manufacturer becomes aware
Early warning to authorities and, where applicable, affected EU markets.
Product details, nature of the exploit, mitigation and user actions.
Final exploited-vulnerability report after a corrective measure is available.
Final severe-incident report after the 72-hour notification.
What wallet makers must report in 24 hours
The first submission is an early warning, not a completed technical investigation. When a manufacturer becomes aware of an actively exploited vulnerability, it must notify the authorities without undue delay and no later than 24 hours later. The early warning must indicate the Member States where the company knows the affected product has been made available, where applicable.
The same deadline applies to a severe incident affecting product security. In that case, the early warning must at least state whether the company suspects unlawful or malicious activity caused the incident, as well as the relevant markets where the product is available.
More detail is due within 72 hours. The European Commission’s reporting guidance says this notification must include available information about the product and the general nature of the exploit and vulnerability.
It must also cover corrective or mitigating measures already taken, steps users can take, and, where applicable, how sensitive the manufacturer considers the information to be.
Active exploitation is the key legal trigger
The 24-hour clock does not start whenever a researcher privately reports a bug. It applies when a manufacturer becomes aware of an actively exploited vulnerability, meaning the flaw is being used against the product, or of a severe incident affecting product security. A company can receive a report, investigate it and prepare a patch without automatically falling into the Article 14 deadline. Once it learns that attackers are exploiting the flaw before the fix is complete, the regulated reporting process begins.
Recent Coldcard coverage shows why this threshold matters. In a July warning involving potentially weak seed generation, the practical risk was not limited to identifying the flaw: affected users needed to determine whether their seed was exposed and move funds if necessary.
The report goes to authorities, not automatically to the public
A fast reporting deadline may sound like a requirement to reveal an unpatched wallet flaw immediately. That is not what the CRA says. The initial report goes to the relevant CSIRT and ENISA through the Single Reporting Platform; it is not an automatic public advisory or a mandatory blog post containing technical exploit details.
The regulation requires authorities and other parties involved in its application to protect confidential information, including source code, trade secrets and information that could undermine an investigation. In cases involving coordinated vulnerability disclosure, a CSIRT can delay dissemination of an exploited-vulnerability notification to other CSIRTs where justified cybersecurity grounds exist.
Public disclosure remains possible when it is needed to prevent or mitigate a severe incident, handle an ongoing incident or serve the public interest. A CSIRT may then inform the public or require the manufacturer to do so after consulting the company. Wallet makers must give authorities enough information to assess the risk while telling users how to protect themselves without disclosing details that could aid an attacker.
Open-source wallets are not automatically exempt
The CRA does not apply to free and open-source software that is not made available on the market in the course of commercial activity. It also does not apply to people who merely contribute code to open-source software that is not under their responsibility.
That is not a blanket exemption for open-source wallet projects. The Commission’s open-source guidance states that a manufacturer placing a free and open-source product on the market remains subject to manufacturer obligations. A product being free does not necessarily mean its supply is non-commercial.
The CRA also creates a separate category for open-source software stewards: legal entities that provide sustained support for a specific open-source product intended for commercial activity. They are not subject to CRA administrative fines, but Article 14 can still require reporting when they are involved in the product’s development or when severe incidents affect the development systems they provide.
A patch may still leave wallet users exposed
For crypto wallets, the end of a technical incident is not always the moment a security update becomes available. An update can prevent new exposure while leaving keys, seed phrases or wallet setups created under affected software at risk.
That distinction was clear when Coldcard released a security update for an earlier seed-generation issue. Updating the device did not make previously generated affected seeds safe; holders still needed to create fresh keys and move their funds. Under the new CRA rule, that operational response may now run alongside a mandatory authority notification when active exploitation is identified.
Wallet makers now need a documented 24-hour process for deciding whether exploitation is active, notifying authorities, preparing mitigation and warning affected users. The next exploit will show whether firms can meet that legal deadline while the incident is still being investigated and a full remediation plan may not yet exist.









