to leave a comment.

▲ European Union, Bitcoin (BTC), Ethereum (ETH), cryptocurrency wallet, cryptocurrency security/AI-generated image
The EU has mandated cryptocurrency wallet providers to report critical security vulnerabilities within 24 hours. Violations could result in fines of up to $17.3 million.
According to the cryptocurrency specialized media Cointelegraph on September 14 (local time), the reporting obligation under the EU's Cyber Resilience Act (CRA) came into effect on the 11th. Hardware and software cryptocurrency wallet providers must submit an initial warning within 24 hours if they become aware of a flaw exploited in an actual attack or a severe security vulnerability. This regulation applies to all products containing digital elements sold in the EU.
The reporting process does not end within 24 hours. Providers must submit a full notification within 72 hours. After corrective or mitigating measures are established, a final report must also be submitted within 14 days. Serious incidents require a final report within one month. The European Commission (EC) explained that this measure is intended to protect consumers and businesses from cyber threats.
The cost of non-compliance is also significant. Failure to comply with Articles 13 and 14 of the Cyber Resilience Act can result in fines of up to 15 million euros or 2.5% of the worldwide annual turnover, whichever amount is greater. 15 million euros is approximately $17.3 million according to the article. Submitting inaccurate, incomplete, or misleading information can result in fines of up to 5 million euros.
The new regulation was implemented shortly after a series of personal data breach issues occurred at major hardware wallet providers. Trezor announced on September 4 that 67,000 US customers were exposed to additional risk due to a data breach at the shipping company ShipMonk. The initial estimate was 14,000 people. Subsequently, Trezor and BitBox warned of phishing emails disguised as urgent security announcements related to alleged third-party email service compromises.
The EU's new system directly includes the speed of response to cryptocurrency wallet security incidents as a regulatory target. Wallet providers must complete an initial report within 24 hours of discovering a vulnerability and a full notification within 72 hours. Failure to comply will result in fines of up to 15 million euros or 2.5% of the worldwide annual turnover.
[Article Key Summary]
-The EU has mandated cryptocurrency wallet providers to submit an initial report within 24 hours of becoming aware of a severe security vulnerability.
-Providers must submit a full notification within 72 hours and subsequently go through a final reporting process.
-Failure to comply with regulations may result in fines of up to 15 million euros or 2.5% of the worldwide annual turnover, whichever is greater.
*Disclaimer: This article is for investment reference only, and we are not responsible for any investment losses based on it. The content should be interpreted for informational purposes only.*
Newsletter
Get key news delivered to your email every morning
to leave a comment.