Europe's 24-Hour Flaw Clock Went Live Sept. 11. Wallet Makers Have Until Dec. 11, 2027.
The EU's Cyber Resilience Act now forces wallet makers selling into Europe to report actively exploited vulnerabilities within 24 hours. The rule covers existing products, not just new ones, and open-source licensing won't save you. Most teams in scope have no process for this yet.
Europe flipped a switch on Sept. 11, 2026, and a lot of hardware wallet makers haven't noticed.
The Cyber Resilience Act's rapid reporting regime is live. If your connected hardware wallet or downloadable wallet app is sold in the EU, and you discover an actively exploited vulnerability, you've got 24 hours to tell a national cybersecurity authority. Not 24 business hours. Not 24 hours after your incident response team finishes its triage call. Twenty four clock hours from the moment you become aware. That's it.
The Clock, In Order
Start with the first filing. It's an early warning, due without undue delay and no later than 24 hours after awareness. It has to name the member states where the product is known to have been made available. If it's a severe incident rather than a vulnerability, you also flag whether you suspect malicious or unlawful acts. That last bit matters. Regulators want to know if this was an attack or a bug before anyone has the full picture.
Then 72 hours. A fuller notification, unless you already handed over the same information. For an actively exploited vulnerability, that filing covers the product, the exploit, the vulnerability, and whatever corrective or mitigating measures exist. For a severe incident, it's the nature of the event, an initial assessment, and available mitigation info so far.
Final deadlines split by event type. A vulnerability report is due no later than 14 days after a corrective or mitigating measure becomes available. A severe incident gets one month after the 72-hour filing. Everything routes through one door, ENISA's Single Reporting Platform, run by the EU cybersecurity agency. That portal pushes the notification to the coordinating CSIRT, makes it visible to ENISA, and distributes to other relevant national teams. One filing, not twenty-seven.
Manufacturers also have to inform impacted users. Where appropriate, all users, with the measures they can take.
Here's the kicker. The reporting rule reaches in-scope products placed on the market before Dec. 11, 2027. So this isn't a future problem for future product lines. It's a now problem for the hardware already sitting in drawers across Europe.
Who Actually Feels This
The legal test is narrower than the headlines suggest. A product qualifies if it's made available on the EU market and its intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. A commercially supplied connected hardware wallet clears that easily. So does a downloadable wallet app. The EU doesn't name brands, and it doesn't declare every wallet service covered. Coverage depends on the specific product, how it's supplied, and any applicable exclusion.
Now the part that should worry anyone building in the open. Open-source licensing isn't a blanket exemption. Commercially supplied free and open-source products can still carry manufacturer obligations. Non-monetized software supplied by its manufacturer shouldn't count as commercial activity, and individual contributors aren't treated as manufacturers for software outside their responsibility. But the moment you sell it, you're in scope. That's a real shift for teams that treated a public repo as armor.
Timing is everything here. The reporting clock went live months after a stretch of wallet disasters that would've generated a stack of 24-hour filings. SafePal's breach exposed 40,000 customers and fed into attacks that escalated from data leaks to roughly $100 million in theft. Zilliqa traced a 683 million ZIL theft back to a hardware wallet flaw that discarded entropy and exposed private keys. Different failures, same lesson, and the same uncomfortable question for anyone holding keys.
Which brings me to the thing nobody in this industry wants to model properly. If an AI agent can hold a wallet, who writes the risk model? An agentic wallet doesn't wait for a human to click approve. It signs, it swaps, it bridges, and it does all of it at machine speed. Under the CRA, a manufacturer shipping agent software bundled with wallet functionality now watches a 24-hour clock it can't manually outrun. You don't get to sleep on an actively exploited vulnerability when the exploited thing moves funds autonomously.
That's the collision I care about. Not tokens. Liability. The convergence of AI and crypto keeps getting pitched as a product story. The CRA just reframed it as a disclosure story, and disclosure comes with deadlines.
And here's who gets squeezed. A two-person hardware team in Lisbon with a sold-out product line and no legal counsel doesn't have a 24-hour reporting process. they've a Signal group. The CRA effectively taxes small manufacturers with paperwork they can't staff, which pushes the market toward whoever can afford a compliance function. That might be the point. It might also be a moat dressed up as consumer protection.
What Comes Next
Two dates to circle. Sept. 11, 2026, already happened. That's when rapid reporting began. Dec. 11, 2027, is the bigger one. That's when the CRA's main product-security requirements kick in, and it's also when open-source software stewards pick up their own reporting duties as a separate legal category. The Sept. 11 change started the fast clock. It didn't start the secure-design framework.
Between now and then, watch three things. First, whether wallet vendors publish their reporting pipelines or quietly hope nobody asks. Second, whether the first wave of 24-hour filings leaks into public view, because a disclosed vulnerability is a short signal on the product. Third, how agentic wallet startups price in the risk. Show me the inference costs and the liability model, then we'll talk about whether the product is real.
My read is blunt. The rapid reporting regime is one of the few pieces of EU crypto-adjacent regulation that targets an actual failure mode instead of a vibe. Wallet breaches aren't hypothetical. They're a line item. A 24-hour clock won't stop the next SafePal, and it won't fix discarded entropy in a signing routine. But it does force manufacturers to say something while users can still move their funds.
That's worth more than most of what passes for crypto regulation. Now the only question is whether the teams in scope actually built the process, or whether they'll find out the hard way at 3 a.m. on day one.
Explore More
Key Terms Explained
An autonomous program that can perceive on-chain data, make decisions using machine learning models, and execute blockchain transactions without human intervention.
Following the laws and regulations that apply to financial activities, including crypto.
A physical device that stores cryptocurrency private keys offline.
An Ethereum Layer 2 in the Optimism Superchain ecosystem that incentivizes developers and users through its referral and fee-sharing system.