Crypto Prices

EU Imposes Strict 24-Hour Reporting Regulations on Crypto Wallet Providers

6 hours ago
1 min read
3 views

New Cyber Resilience Act for Cryptocurrency Wallet Manufacturers

Cryptocurrency wallet manufacturers are now under stringent requirements to report security vulnerabilities, as stipulated by the European Union’s newly implemented Cyber Resilience Act (CRA). As part of this directive, providers must alert authorities within 24 hours should they become aware of significant bugs or critical security flaws that impact their products. A full report detailing the situation has to follow this initial notification within a 72-hour window.

Penalties for Non-Compliance

The penalties for failing to comply are severe; companies could face administrative fines reaching up to €15 million (approximately $17.3 million), or 2.5% of their global annual revenue, depending on which amount proves to be greater. Additionally, incorrect submissions may incur fines of up to €5 million. These measures were enacted as a response to increasing threats in cyberspace and aim to enhance the protection for both consumers and businesses against such risks.

Scope of the Regulation

Every digital product offered within the EU now falls under this regulation, continuing the EU’s commitment to strengthening its cybersecurity framework. This legislation comes after notable data breaches were reported by well-known hardware wallet providers, particularly those linking to phishing risks. For example, Trezor revealed that over 67,000 customers were at risk due to a breach involving its logistics partner, ShipMonk, far surpassing previous estimates of around 14,000 users.

Recent Security Incidents

Furthermore, both Trezor and BitBox recently had to notify their clients about phishing attempts disguised as urgent security communications, which arose from suspected breaches in third-party email providers. Earlier this year, Zilliqa, a prominent Layer-1 blockchain network, highlighted a vulnerability in its Ledger application that had the potential to expose users’ private keys through the misuse of publicly available blockchain data.

Industry Response

Cointelegraph is currently reaching out to Trezor and Ledger for their insights on adhering to these new compliance mandates.

This robust regulation is part of a broader EU strategy aimed at combating cyber threats and bolstering the overall security of digital services in the region.

Popular