Back Kucoin EU Mandates 24-Hour Vulnerability Reporting for Connected Wallet Makers
EU rules require commercial manufacturers of in-scope connected hardware wallets and wallet software to warn cyber authorities within 24 hours of discovering an actively exploited vulnerability or severe security incident. The requirement took effect Sept. 11, 2026, under the EU's Cyber Resilience Act. The law applies to hardware and software made available on the EU market. A product must have an intended or reasonably foreseeable use that includes a direct or indirect data connection to a device or network. Commercially supplied connected hardware wallets and downloadable wallet apps can meet that test. EU guidance does not name wallet brands or declare every wallet service or project covered. The first filing is an early warning due without undue delay and no later than 24 hours after the manufacturer becomes aware of the vulnerability or incident. The filing must indicate the member states where the product is known to have been made available. For a severe incident, the filing must say whether unlawful or malicious acts are suspected. A fuller notification is due within 72 hours unless the relevant information was already provided. For an actively exploited vulnerability, that notification includes general information the product, exploit and vulnerability. It also includes corrective or mitigating measures. For a severe incident, it includes the nature of the incident, an initial assessment and available mitigation information. A vulnerability report is due no later than 14 days after a corrective or mitigating measure becomes available. The final report for a severe incident is due one month after the 72-hour notification. Manufacturers file once through the Single Reporting Platform launched by ENISA. The platform sends the notification to the designated coordinating Computer Security Incident Response Team. Manufacturers must inform impacted users when action is needed. The rule reaches in-scope products placed on the market before Dec. 11, 2027. Commercially supplied free and open-source products can also face manufacturer obligations. Non-monetized software supplied by its manufacturer should not count as commercial activity. Individual contributors are not treated as manufacturers for software outside their responsibility. Open-source software stewards have separate reporting duties beginning Dec. 11, 2027. The broader CRA product-security requirements also take effect on that date.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
