Crypto Wallet Makers Now Face the EU’s 24-Hour Exploit Reporting Clock
• September 13, 2026 7:31 am • CommentsCrypto wallet makers that sell into the European Union now have a much shorter clock to manage when a serious security problem is under active attack.
The reporting provisions of the EU’s Cyber Resilience Act took effect on September 11. Under the new system, manufacturers of products with digital elements must send an early warning within 24 hours after becoming aware of an actively exploited vulnerability or a severe security incident.
That category reaches far beyond traditional hardware. It can include software and connected products, which puts many consumer crypto wallets and the companies behind them squarely inside the operational challenge.
The first deadline comes before the full technical report.
The European Commission’s reporting guidance says the first alert is only the beginning. A fuller notification is due within 72 hours, followed later by a final report.
Notifications go through the Cyber Resilience Act Single Reporting Platform built by the European Union Agency for Cybersecurity. The initial report goes to the computer security incident response team where the manufacturer has its main establishment and is generally shared with ENISA at the same time.
The Commission says a final report on an actively exploited vulnerability is due no later than 14 days after a corrective measure becomes available. For a severe incident affecting product security, the final report is due within one month after the 72-hour notification.
The sequence matters. A wallet company cannot wait until investigators have reconstructed every detail before deciding whether the clock has started.
It needs an incident process that can identify active exploitation, preserve evidence and get the first warning out while engineers are still containing the problem.
CryptoSlate’s examination of the new deadline notes that the rule lands in an industry where the most damaging incidents do not always begin inside a wallet’s core code. Stolen credentials, compromised service providers and social engineering can put users at risk even when the signing device itself remains intact.
The analysis draws a useful line between a vulnerability in a product and the wider infrastructure used to reach its customers. That distinction can determine which incident facts a manufacturer has available during the first 24 hours.
A fresh incident involving email provider Brevo showed that distinction in real time. Brevo said it was working with affected customers after access to customer accounts was abused.
Hi, thanks very much for bringing this critical issue to our attention. We are working with the affected customers to restore the security of their account. To confirm, this issue did not affect all of our customers. We apologize for any inconvenience caused.
— Brevo (@brevo_official) September 9, 2026
The preliminary review described in the next post pointed to a compromise at the newsletter provider rather than at the wallet itself.
Our preliminary review of the phishing mail that was sent out to our newsletter subscribers about an hour ago found that it is very likely that our newsletter provider got compromised.
Multiple other Bitcoin companies got targeted as well, and it appears that we all share the…
— BitBox (@BitBoxSwiss) September 9, 2026
The Brevo episode is not presented as a Cyber Resilience Act test case. It is a useful example of why the legal and technical boundaries can become complicated quickly: the wallet device may be secure while a connected vendor channel is being used to target wallet owners.
For manufacturers, the practical work is therefore broader than patching code. They need clear ownership for the 24-hour decision, an inventory of vendors and software dependencies, preserved timestamps showing when the company became aware, and a way for security, legal and communications teams to work from the same facts.
Users should not mistake faster regulatory reporting for an automatic shield against theft. The first defense remains basic but unforgiving: never enter a recovery phrase into a website or an app opened from an email, and verify security notices through the wallet maker’s official site or device.
The new EU clock does, however, change what customers can expect from companies. In a market built on self-custody, a wallet maker’s incident response is now part of the product.
Join the conversation!
We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.
