The European Union has adopted a new regulatory framework that changes the way cryptocurrency wallet companies handle security incidents. Under the Cyber Resilience Act, software and hardware wallet providers must report within 24 hours of becoming aware of a serious vulnerability or an active exploitation that affects their products.

The rule is not limited to wallets only; it extends to all “products with digital elements” available within the European Union. According to the European Commission, the purpose of these requirements is to strengthen the protection of consumers and businesses from cyber threats, as part of a broader digital security strategy in Europe.

What should be done in practice?

When a serious vulnerability is discovered or there are indicators of it being exploited, it is not enough to wait for the completion of the internal investigation. The first step is to send an early alert within 24 hours, followed by a full notification within 72 hours. After that, a final report must be submitted within 14 days of the availability of remediation or mitigation measures, and within one month in cases of serious incidents.

This sequence means that the security and compliance teams within crypto-asset custodian firms will need an incident response mechanism that is much faster than usual, with the ability to:

• Quickly assess the severity of the vulnerability or exploitation.

• Document what is known and what is still unconfirmed.

• Notify the competent authorities before all technical details are finalized.

• Continue internal updates until the final report is issued.

The difference between early reporting and the full notification

Early reporting within 24 hours is an initial step intended to quickly alert regulators to the existence of a real or potential risk. Meanwhile, the full notification within 72 hours is expected to provide a clearer picture of the nature of the incident, the scope of the impact, and the actions taken or planned.

In other words, the law does not wait for investigations to end before reporting begins. This forces companies to operate under intense time pressure, with the potential for higher compliance costs due to the need for teams available around the clock, stricter internal procedures, and faster monitoring and documentation systems.

Fines that could reach $17.3 million

Compliance with these requirements is not optional. Companies that do not comply may face an administrative fine of up to €15 million, i.e., about $17.3 million, or 2.5% of total worldwide annual revenue—whichever is higher. In addition, providing incorrect, incomplete, or misleading information may result in a fine of up to €5 million.

These rules arrive at a sensitive time for the digital custody sector, following a series of recent security disclosures. On September 4, Trezor announced that an additional 67,000 U.S. customers were put at risk due to a breach affecting the ShipMonk shipping provider—an amount that exceeds the initial estimate of 14,000 users. Trezor and BitBox also warned users about phishing messages impersonating urgent security notifications after suspicions of a compromise of email services run by third parties.

In June, the Zilliqa network warned about a vulnerability in the Zilliqa Ledger app that could allow attackers to recover users’ private keys using data available on-chain. These developments highlight why the European Union views rapid reporting as a core component of risk management—not just an administrative requirement.

For custody companies, the message is clear: response times for incidents are getting shorter, the cost of delays is rising, and security compliance is becoming directly tied to the ability to operate in the European market.

#تنظيم #أمن_سيبراني $TREZOR $BITBOX $ZIL