- Cointelegraph reports that EU cyber rules put crypto wallet providers on a 24-hour early reporting deadline after an exploited vulnerability, with a fuller notification due inside 72 hours.
- The penalty quoted is up to $17.3m, about £13m. That figure lines up with an EU ceiling of €15m or a percentage of global turnover.
- We could not find the underlying legal text or any official statement, so treat the specifics as one outlet’s account rather than a verified reading of the rules.
The gap between a wallet flaw being exploited and the maker saying so publicly has lately been measured in days. Brussels wants it measured in hours. Rules reported this week put wallet providers serving EU users on a 24-hour clock, with a fine attached to missing it.
When a wallet’s security fails, the thing that decides whether you can do anything about it is not the flaw itself. It’s how fast you find out. Every hour a maker spends deciding what to say is an hour you spend not knowing whether to move your coins.
A deadline with a large fine behind it changes what a nervous company does with that hour. If you hold crypto on a device or app from an EU-based maker, that change reaches you even though you live in the UK. If your provider is UK-only, it doesn’t.
What a disclosure clock actually is
A vulnerability is a flaw in a product that someone can abuse. Most are found quietly and patched quietly, which is the system working. The problem is the ones already being used against customers while the company decides how to handle it.
A disclosure clock is a legal deadline to tell a designated authority, usually a national cybersecurity team, within a fixed number of hours of learning that a flaw is being actively exploited. The first filing is short: what is broken, roughly how bad. A fuller account follows.
Worth being clear about one thing, because it is where these rules are most often oversold. Telling a regulator is not the same as telling customers. A disclosure clock forces information into an official channel on a schedule. Whether and when the affected owners hear about it is a separate question, and the reporting we have does not resolve it.
Which rules, and how confident we are

Cointelegraph’s write-up is the only account of this we have found. No primary document, no official statement, and no other outlet covering the same development at the time of writing. That matters more than usual here, because the exact instrument determines who is bound.
The shape described, a 24-hour early warning followed by a 72-hour notification, and a maximum penalty of €15m or a share of worldwide turnover, matches the EU’s Cyber Resilience Act, which applies to products with digital elements rather than to financial firms specifically. That is our inference from the numbers, not something we can confirm from a source document. The EU also has a separate operational resilience regime for regulated financial entities with its own incident timelines, and the two are easy to conflate.
The pattern it is aimed at
Anyone who has followed a wallet security story to its conclusion will recognise the behaviour these deadlines are written against. A flaw surfaces, funds move, and the maker publishes nothing specific for days. Owners are left refreshing a status page, unable to tell whether their particular device or firmware version is one of the affected ones.
That was the shape of the Coldcard key generation failure, where the company had still not published a list of affected devices well after money had gone. It is also the shape of several smaller incidents we have covered in our technology coverage, where the disclosure arrived long after the exploit.
None of which is unique to crypto. Consumer hardware companies have been slow with bad news for as long as consumer hardware has existed. The difference is that a bad week for a router is an inconvenience, and a bad week for a wallet is somebody’s savings.
Where a UK holder stands
Two of the largest hardware wallet makers, Ledger and Trezor, are based in France and the Czech Republic. A UK buyer using an EU-established provider is likely to benefit from any EU reporting duty in practice, because companies rarely run one disclosure process for Paris and another for Peterborough.
The UK itself has no equivalent. Post-Brexit product security law requires manufacturers of connectable consumer devices to publish a route for reporting vulnerabilities, but it does not set an hours-based clock for notifying a regulator, and crypto wallets are not singled out anywhere in UK rules. A provider that is UK-only, or one based outside both jurisdictions, is under no comparable obligation. If you keep coins on a device, the practical response is the boring one covered in our self-custody guide: know who makes your wallet, know where they are established, and know where they publish security notices before you need it.
What to watch
Confirmation of which instrument this is and when it bites. Until the legal text or an official summary is on the table, the scope is guesswork, and the aggregator’s framing has not been tested against anything.
Then the extraterritorial question, which the reporting leaves alone entirely. EU product rules usually catch anyone placing goods on the EU market, including firms with no European office, and open-source projects with no commercial sponsor often sit outside them. How a regulator enforces a 24-hour deadline against a wallet developer in Singapore or an anonymous code repository is not obvious, and nobody has explained it yet. No regulator and no wallet maker is quoted on the record in the coverage we have seen.