LOOK CRYPTO · DATA PIPELINE

Data collection status

Checking collection status…

← All news
CRYPTO NEWS

EU Cyber Rules Impose 24-Hour Reporting Deadline on Crypto Wallet Makers for Critical Vulnerabilities

Cointelegraph · Zoltan Vardai

With the enactment of the EU Cyber Resilience Act (CRA), providers of cryptocurrency hardware and software wallets are now required to report severe security vulnerabilities or actively exploited bugs within 24 hours of awareness. The regulation aims to enhance consumer and business protection against cyber threats across digital products with embedded software available in the European Union.

Obligations for Wallet Manufacturers

Under the new regulation, providers of cryptocurrency hardware and software wallets must submit an early warning about critical vulnerabilities within 24 hours of becoming aware. A full notification must follow within 72 hours. A final report is due 14 days after corrective or mitigating actions are available, and for severe incidents, no later than one month.

The European Commission emphasizes that these new reporting requirements aim to better protect consumers and businesses from cyber threats. The rules apply to all products with digital elements made available in the EU and fit within the broader EU cybersecurity strategy.

Penalties for Non-Compliance

Failure to comply with Articles 13 and 14 of the Cyber Resilience Act can lead to administrative fines of up to 15 million euros (approximately $17.3 million) or 2.5% of a company’s worldwide annual turnover, whichever is higher. Providing incorrect, incomplete, or misleading information may incur an additional fine of up to 5 million euros.

These penalties are designed to encourage timely and accurate reporting of cybersecurity issues, ensuring high standards of accountability among digital product manufacturers.

Recent Incidents Prompting the Regulation

The regulation was unveiled shortly after several significant security incidents involving wallets. On September 4, Trezor disclosed that a data breach affecting its shipping provider ShipMonk compromised an additional 67,000 US customers, exceeding the initial estimate of 14,000 users.

Both Trezor and BitBox later warned users about phishing emails impersonating urgent security alerts following alleged compromises of third-party email services.

In June, Layer-1 blockchain network Zilliqa reported a vulnerability in the Zilliqa Ledger app that might allow attackers to recover users’ private keys using publicly available on-chain data.

Industry Response and Next Steps

Cointelegraph reached out to wallet manufacturers Trezor and Ledger for comments on their approach to meeting the new reporting requirements and improving cybersecurity measures.

The European Commission has not provided further details yet but stated that the new rules form part of the EU’s comprehensive digital security policy to protect users and build trust in digital products.

Why it matters

The EU’s new regulation represents a significant advance in fortifying the cybersecurity of digital products, including cryptocurrency wallets which are frequent targets of hacking. By imposing strict deadlines for reporting critical vulnerabilities and imposing steep fines for non-compliance, the law incentivizes providers to act swiftly against threats, reducing risks for both end-users and businesses. This will bolster trust in crypto infrastructures and enhance overall security standards within the EU market, aligning with a global trend towards stronger regulation of digital technologies.

Prepared from the source material with AI-assisted editing and checked against the supplied facts.

Open original source ↗