EU Crypto Wallet Firms Face $17.3M Fines Under New Cybersecurity Rules

Cryptocurrency wallet providers operating in the European Union face tighter cybersecurity requirements under the bloc’s new Cyber Resilience Act (CRA), including strict deadlines for reporting exploited vulnerabilities and severe security incidents.
The legislation took effect Friday, introducing rules that require manufacturers of hardware and software wallets to notify authorities when they become aware of serious security weaknesses affecting their products.
Under the new framework, companies must submit an initial warning within 24 hours of discovering an actively exploited vulnerability or severe security flaw. A more detailed report must follow within 72 hours, while a final update is required 14 days after corrective or mitigating measures become available.
For severe cybersecurity incidents, manufacturers must submit their final report within one month.
The European Commission said the reporting rules are designed to strengthen protection for consumers and businesses against growing cyber threats. The requirements apply broadly to products with digital elements made available in the EU, bringing crypto wallet providers into a wider cybersecurity framework.
Noncompliance Could Cost Millions
Wallet manufacturers that fail to meet the cybersecurity obligations under Articles 13 and 14 of the CRA could face administrative fines of up to 15 million euros ($17.3 million), or 2.5% of their worldwide annual turnover, depending on which amount is higher.
Companies that provide incorrect, incomplete or misleading information may also face fines of up to 5 million euros.
The penalties add financial pressure on crypto wallet providers to establish clear procedures for identifying vulnerabilities, reporting incidents and communicating security risks to regulators.
Wallet Breaches Raise Security Concerns
The new requirements arrive shortly after several security incidents involving major hardware wallet providers and related services.
On Sept. 4, Trezor disclosed that an additional 67,000 customers in the United States were potentially affected by a data breach involving its shipping provider, ShipMonk. The revised figure was significantly higher than the initial estimate of 14,000 users.
Trezor and BitBox later warned customers about phishing emails posing as urgent security notifications. The warnings followed suspected compromises involving third-party email services, raising concerns about attacks designed to trick users into revealing sensitive information.
In June, the Zilliqa blockchain team also reported a vulnerability in the Zilliqa Ledger app. The flaw could potentially allow attackers to recover private keys using publicly available onchain data.
While the EU’s Cyber Resilience Act covers a broad range of digital products, the new reporting deadlines could have particular importance for crypto wallet companies, where security failures can expose users to the loss of digital assets.
The European Commission has been approached for further details about the new cybersecurity measures. Trezor and Ledger have also been contacted for information on how wallet manufacturers plan to comply with the reporting obligations.
