Developers of cryptocurrency wallets in Europe are now required to report any software vulnerabilities within 24 hours of discovery. This obligation is part of the updated Cyber Resilience Act.

The regulations took effect on September 11. This mandate applies to providers of both hardware and software cryptocurrency wallets that are registered in the EU.

According to the new rules, manufacturers must notify authorities of any vulnerabilities or significant security incidents within a day of becoming aware of the issue. A comprehensive report must follow within 72 hours.

Final incident reports are required to be submitted no later than 14 days after the implementation of fixes. In cases of serious incidents, the report should be filed within a month following the initial 72-hour notification.

Wallet manufacturers are also obligated to inform all affected or potentially vulnerable users.

Reports are to be submitted via the Single Reporting platform established by ENISA. Notifications will be sent to the Computer Security Incident Response Team (CSIRT), which must promptly relay the information to relevant teams in other EU countries where the product is available.

Background

Concerns regarding security in the cryptocurrency sector have heightened following a hacking incident involving Coldcard hardware wallets. In July, hackers exploited a flaw in the generation of seed phrases that had been present in the firmware for several years.

By mid-August, Galaxy Research confirmed the theft of at least 1,778.84 BTC valued at $112.7 million. Including unverified incidents, the total estimated damage reached approximately $153 million.

In parallel, the Bitcoin Red Team initiated a large-scale AI scan of Bitcoin projects. The team examined hundreds of repositories and reported thousands of potential issues.

Wallet manufacturers are facing various other threats as well. On August 13, Trezor reported a data breach affecting nearly 14,000 customers through a logistics partner. On September 9, attackers sent users of the platform a fake vulnerability alert following a hack of a third-party mailing service.

BitBox customers also experienced a similar phishing attack.

On August 16, SafePal disclosed a data breach affecting around 39,800 clients. The leaked information included delivery addresses, phone numbers, and email addresses, which could be exploited for phishing and targeted attacks.

Additionally, the OneKey Anzen team was able to replicate a transaction substitution attack in a test environment on the Ledger wallet's Ethereum application version 1.22.1. The developers have since addressed the vulnerability.