The EU Cyber Resilience Act officially takes effect, requiring crypto wallet vendors to report vulnerabilities within 24 hours.
According to Cointelegraph, the EU Cyber Resilience Act (CRA) officially entered into force, requiring cryptocurrency hardware and software wallet providers to submit an early warning within 24 hours of discovering a serious security vulnerability or an actively exploited vulnerability, a complete notification within 72 hours, and a final report within 14 days after remediation measures are implemented. The regulation applies to all "products with digital elements" sold in the EU market.
Violating companies face administrative fines of up to €15 million (approximately $17.3 million) or 2.5% of their global annual turnover, whichever is higher; providing false or misleading information will result in an additional fine of up to €5 million. Previously, Trezor and BitBox have both disclosed user data breach incidents and warned users to be vigilant against phishing emails disguised as security notifications.