BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

Cyber Resilience Act Gives Crypto Wallets 24 Hours to Report Hacks

The Cyber Resilience Act puts EU-facing crypto wallet makers on a fixed vulnerability-reporting clock. An exploited flaw must reach ENISA in 24 hours, with a full report in 14 days and fines

AnonymousCryptoCompass newsroom
September 11, 2026
6 min read
NEWS
Cyber Resilience Act Gives Crypto Wallets 24 Hours to Report Hacks
CryptoCompass editorial visual for policy coverage.
  • The Cyber Resilience Act puts EU-facing crypto wallet makers on a fixed vulnerability-reporting clock.
  • An exploited flaw must reach ENISA in 24 hours, with a full report in 14 days and fines up to €15 million.
  • In 2026 only 11% of losses at audited projects came from smart-contract code.
  • Most crypto money left through stolen keys and infrastructure, not the flaws the CRA targets.

The European Union switched on the reporting duties of its Cyber Resilience Act this month, and for crypto the timing is almost ironic. Wallet makers now have 24 hours to tell Brussels when a vulnerability in their product is under active exploitation, yet the 2026 data shows that product vulnerabilities are not where the money leaves. The Act drags hardware and software wallet developers into a fixed disclosure schedule backed by fines reaching €15 million, and it does so in the same year crypto logged its highest-ever hack count while the thefts themselves walked around the code the regulation is built to police.

24 hours to ENISA, 14 days to explain, €15 million if you are late

The regime hangs on three fixed points, each triggered when a manufacturer discovers an actively exploited vulnerability or a severe incident. An early warning goes to ENISA, the European Union Agency for Cybersecurity, within 24 hours. A detailed notification carrying mitigation steps follows at 72 hours. The full post-mortem, naming the root flaw and its fix, is due 14 days after discovery. Miss any of them and the penalty runs up to €15 million or 2.5% of global annual turnover, whichever is larger, which for a firm with €500 million in annual turnover reaches €12.5 million on the percentage alone. Micro and small enterprises get relief from the strict 24-hour early-warning deadline, but most venture-backed wallet firms will not qualify.

WindowWhat must be filedDeadlineEarly warningNotice to ENISA that an exploited flaw or severe incident exists24 hoursNotificationDetailed update with mitigation steps and initial impact72 hoursFinal reportRoot-cause post-mortem and resolution14 days

How a hardware wallet ended up under product-safety law

The Act never names crypto. It governs any product with digital elements, meaning anything that ships with software or firmware and connects to a device or a network. A signing device with firmware and a companion app fits the definition without argument, and a browser-extension or mobile wallet counts as standalone software with a security function, a category the regulation watches more closely. Exchanges and custodians stay largely with MiCA, but the tools that hold private keys now answer to product law, and that line is what routes wallet teams to ENISA.

207 hacks, under $1 billion gone, and only 11% from code

The first half of 2026 produced more than 207 hacks, over double the 83 seen a year earlier, while total losses stayed under $1 billion across the six months. More attempts, thinner takings. A CoinGecko study from August 2026 sharpened the picture: 88.4% of everything stolen since 2025 came from platforms that had already passed an independent audit, and only 11% of the attacks on those audited projects touched the smart-contract code at all. The rest went through third-party dependencies, front-end supply chains and stolen employee credentials. Lazarus Group, working for North Korea, sat behind roughly 76% of global losses in early 2026.

Metric2025 full yearH1 20262026 to dateTotal stolen$2.38B to $3.4B$972M to $1.31B~$1.5B and rising (est.)Incident volumeLower frequency207+, a record50 in August aloneMain root causeCentralized entity failuresInfrastructure and keys, 72–76%Infrastructure and keys, 72–76%

The regulation reports the flaw the thieves stopped using

The friction is hard to miss. A 24-hour filing works when a bug in a wallet’s own code is under active attack. It does little when someone phishes a multisig signer or hijacks a developer’s session, which is how the year’s biggest thefts unfolded. The CRA does oblige manufacturers to run a coordinated vulnerability process and to keep a software bill of materials, so the third-party components behind most losses at least have to be inventoried. Whether a reporting deadline shifts attacker behaviour is another matter, and nothing in the 2026 record suggests disclosure speed is what stands between a treasury and an emptied wallet.

Where 2026’s money actually left

 

January 2026 · Ledger / Global-e Customer names and contact details exposed through a third-party payment processor. A data breach, not a theft of funds, but the kind of outside failure the CRA now expects wallet makers to log.

 

April 2026 · KelpDAO — $292M A bridge verification failure let attackers mint unbacked rsETH that later drained value from lenders. The second-largest theft of the past 18 months.

 

April 2026 · Drift Protocol — $285M A private-key compromise that investigators have tied to state-sponsored actors.

 

June 2026 · Humanity Protocol — $30–32M Drained by a single stolen private key, a plain illustration of how one leaked credential empties a treasury.

 

August 2026 · Tectonic.cro — $120M exploit, ~$9M net A Cronos-chain exploit; validators rewound the chain and clawed back most of the funds, leaving about $9 million gone.

Retail phishing shrank over the same stretch, from $494 million drained in 2024 to $83.85 million in 2025. The operators did not leave; they moved up the chain, using language models to write lures for the administrators and signers who move institutional-sized balances.

The build wallet teams now owe before December 2027

The immediate work is procedural. A wallet maker needs a path that carries it from spotting an exploited flaw to filing with ENISA inside a day, which means monitoring, an on-call rota and templates written before anything breaks. Layer on the software bill of materials and the coordinated disclosure policy, and the dependencies behind 2026’s losses stop being invisible. A large issuer absorbs this through a compliance desk. A lean EU-facing wallet team either finds that capacity or geofences the bloc out, a route some builders already chose after MiCA.

Application will not look the same everywhere at once. National market-surveillance authorities in each member state carry enforcement, and the harmonized standards that define what adequate security means are still in draft at the European standards bodies. This month’s reporting duties are only the first part of the Act to bite; the security-by-design obligations follow in December 2027. Wallet makers have a short runway to stand up the reporting side, and the first penalties will show whether regulators read the 24-hour deadline as strictly as it is written.

The post Cyber Resilience Act Gives Crypto Wallets 24 Hours to Report Hacks appeared first on ETHNews.