EU Cyber Resilience Act Starts 24-Hour Flaw Reporting
The EU has put 24-hour vulnerability reporting into force under the Cyber Resilience Act, raising security duties for software makers including crypto wallets and exchanges.

Sofia Marquez
Regulation & Tech Editor, RefreshCoin
EU Cyber Resilience Act vulnerability rules are now in force with a 24-hour reporting standard for actively exploited flaws. The requirement calls for a fast initial notice to authorities after a vendor learns of exploitation, with fuller detail to follow as analysis develops. The update was dated Sept. 19, 2026. For digital assets, the shift touches wallet developers, custody technology providers and trading platforms that offer software or connected products in the EU.
What the 24-hour rule requires
At its core, the 24-hour duty is about early warning. A vendor that discovers its product is being exploited in the wild is expected to send an initial alert within a day, even when the full technical picture is incomplete. That early notice is meant to help authorities track active abuse, warn other vendors and coordinate fixes across the single market. Time now matters.
The model separates a quick initial notice from later updates. The first message can be limited to what is known: the product concerned, signs of exploitation and a contact point for follow up. More complete information on cause, impact and patches follows once investigation advances. The design reflects how security work actually happens, with triage first and root cause later.
The trigger is active exploitation, not every theoretical bug. Internal findings, penetration tests and research reports handled through normal patch cycles are treated differently from flaws attackers are already using. That distinction keeps the fast channel focused on urgent risk. It also means vendors need clear internal rules for deciding when exploitation is confirmed.
Why does this matter now for crypto firms?
It matters now because crypto products are software products, and software flaws can move funds in minutes. An exchange matching engine, a mobile wallet, a browser extension or a hardware wallet companion app can all fall under product security duties if offered in the EU. A reporting clock that starts on learning of exploitation leaves little room for slow escalation chains.
Crypto firms often run continuous deployment, open-source dependencies and third party integrations. That structure speeds up releases but widens the area that must be monitored for abuse. Centralized incident logging, defined severity levels and a named security contact become practical needs rather than optional controls. Teams that already publish advisories and run bug bounties will adjust faster than teams that handle reports by email alone.
How the EU built up to this point
The Cyber Resilience Act grew out of years of EU work on product safety and network security. Policymakers argued that connected devices and applications reached buyers without consistent security baselines, update commitments or coordinated disclosure. The Act extends familiar product safety logic to code: define essential security properties, require risk assessment, document support periods and fix flaws responsibly.
The law distinguishes between manufacturers, importers and distributors, with the heaviest duties on those that create or brand the product. Open-source projects and researchers were a major point of debate during drafting, since EU officials wanted stronger security without discouraging open development. The result keeps a focus on commercial supply, while stewards of widely used components face lighter transparency duties tied to their role in the supply chain.
What does this mean for bitcoin (BTC) traders?
It means fewer silent flaws in the tools traders rely on, but also more short term disclosure noise. Bitcoin custody apps, signing devices, portfolio trackers and exchange interfaces sold or operated in the EU will sit inside stricter handling and notification routines. Over time that should improve patch quality and incident communication, two factors that affect uptime during volatile markets.
Traders should not read every filing as a reason to move coins. An early 24-hour notice often contains limited facts and may precede a patch by days or weeks. Past episodes across centralized platforms showed that rushed reactions to partial bug reports caused more losses through phishing copies and fake upgrades than the original flaw. The useful response is operational: confirm official channels, verify software signatures, review withdrawal allowlists and watch for vendor guidance on ether (ETH) and other supported assets.
How wallets, exchanges and custody providers are affected
Wallet makers face the most direct change because they ship executable products. They will need vulnerability intake, severity scoring, coordinated disclosure with researchers and records of fixes and user notices. Hardware wallet vendors have an added layer, since firmware, desktop software and mobile apps can each carry separate version lines and update paths. Clear support windows and automatic update prompts reduce exposure when exploitation is confirmed.
Exchanges and custodians are affected both as software vendors and as operators of critical infrastructure. Their customer apps and APIs look like products, while their back end systems sit under financial and operational resilience rules as well. That overlap calls for joint playbooks between product security, platform engineering and compliance teams. Evidence handling, log retention and customer communication templates will be tested under real time pressure.
Third party dependencies add another test. Most crypto stacks use open-source libraries for cryptography, networking, databases and key management. Vendors will need software bills of materials, upstream monitoring and contracts that define who patches what and how fast. A flaw in a shared library can trigger duties for many downstream products at once, which makes coordinated timelines and consistent user messages central to containing damage.
What to watch next
Watch for guidance on how the early notice channel will work in practice. Forms, intake points, required fields and confidentiality handling will determine the burden on small teams and solo developers. Industry groups, national authorities and EU bodies are likely to publish templates, examples and help for small firms. The quality of that implementation detail will shape compliance costs more than the headline 24-hour number.
Watch also for first filings, vendor advisories and enforcement signals. Early cases will show what counts as sufficient initial information, when follow up reports are expected and how user notifications should be worded. Crypto teams should track update cadence for major wallets and exchanges, researcher disclosure policies and any product withdrawals from the EU market. Risks include uneven interpretation across member states, alert fatigue from low quality reports and phishing waves that mimic official security notices.
Mentioned in this article
Frequently asked questions
What changed under the EU Cyber Resilience Act?
A 24-hour reporting duty for actively exploited vulnerabilities is now in force. Vendors must send a fast initial notice after learning of exploitation, then provide fuller detail as investigation proceeds.
Does this apply to crypto wallets and exchanges?
Yes, where they supply software or connected products in the EU. Wallet apps, companion software and exchange client software can fall in scope, with duties centered on the manufacturer or brand owner.
Should traders act on each vulnerability notice?
Not on the early notice alone, since it is often incomplete. Verify announcements through official vendor channels, check software signatures and wait for patch guidance before changing custody setups.
Comments(0)
No comments yet. Be the first to weigh in.