Loading IndicatorLoading Indicator

EU Orders Crypto Wallet Firms to Report Serious Security Flaws Within 24 Hours or Face Fines of Up to 15 Million Euros

Source
Suehyeon Lee

Summary

  • The EU said it now requires crypto wallet companies to report security vulnerabilities within 24 hours of becoming aware of them, with fines of as much as 15 million euros for noncompliance.
  • The rules took effect after a series of security incidents and vulnerability warnings involving Trezor, BitBox, and Zilliqa.
  • The European Commission said the measure applies across products with digital elements and is intended to protect consumers and businesses from cyber threats.

Forecast Trend Report by Period

Loading IndicatorLoading Indicator
Photo: ChatGPT-generated
Photo: ChatGPT-generated

The European Union now requires crypto hardware and software wallet providers to notify authorities within 24 hours of identifying a serious security vulnerability or an instance of active exploitation.

Cointelegraph reported on September 14 that the European Commission began enforcing incident-reporting rules under the Cyber Resilience Act, or CRA, on September 11.

Under the rules, crypto wallet makers offering products in the EU must submit an early warning within 24 hours if they discover a vulnerability that is being actively exploited or another serious security issue. They must then file a formal report within 72 hours.

The rules also impose follow-up reporting requirements. Companies must submit a final report within 14 days after putting in place a fix or mitigation measure for a vulnerability. In cases involving serious security incidents, a final report is required within one month.

Violations can trigger steep penalties. Companies that fail to comply with Articles 13 and 14 of the CRA can be fined as much as 15 million euros ($17.3 million), or 2.5% of global annual revenue, whichever is higher. Submitting inaccurate or incomplete information can also result in fines of as much as 5 million euros.

The rules took effect as security incidents involving crypto hardware wallets have continued to surface. Trezor said on September 4 that a data breach at shipping contractor ShipMonk left 67,000 U.S. customers exposed to additional risk. That was far above the initial estimate of 14,000.

Trezor and BitBox have also urged users to watch for phishing emails disguised as urgent security notices after concerns emerged over a possible compromise involving a third-party email service.

In June, layer-1 blockchain Zilliqa also warned that a flaw in the Zilliqa Ledger application could allow an attacker to recover users' private keys using public on-chain data.

The European Commission said the reporting requirement applies to all products with digital elements sold in the EU, including crypto wallets, and is intended to protect consumers and businesses from cyber threats.

#Cybersecurity
#Crypto Regulation
#Policy
Suehyeon Lee

Suehyeon Lee

shlee@bloomingbit.ioI'm reporter Suehyeon Lee, your Web3 Moderator.

What do you think about this news?








PiCK News






Hashtag News