Buy now

Since Friday 11 September 2026, crypto wallet vulnerability reporting in the European Union runs on a clock. Any company selling a wallet into the EU now has 24 hours to warn regulators once it knows a flaw in its product is being exploited, and Cointelegraph reported that the obligation covers hardware and software wallets alike. Miss the window and the penalty reaches 15 million euros or 2.5% of worldwide annual turnover, whichever is larger.

We build one of the products this rule applies to, so we have a stake in how it reads. It is worth explaining anyway, because the thing it changes is not the engineering. It changes what you get told, and when.

What the rule says

The obligation comes from the EU's Cyber Resilience Act, which treats a wallet the way it treats any other product with digital elements. There are three deadlines stacked behind each other. An early warning goes to regulators within 24 hours of the maker becoming aware of an actively exploited vulnerability. A fuller notification follows at 72 hours. A final report lands 14 days after a fix is available, or within a month for severe incidents. Crypto Briefing's summary lays out the same sequence.

Supplying incomplete or misleading information carries its own penalty of up to 5 million euros, which matters more than it sounds. The expensive failure is not only staying quiet. It is also saying something reassuring that turns out not to hold.

What crypto wallet vulnerability reporting looked like before

For most of the last decade the answer was whatever the manufacturer felt like doing. Two incidents from 2026 show the range.

In August, Ledger shipped version 1.22.2 of its Ethereum app with a changelog that read, in full, "Security issues." The fix was correct and it went out fast. Ten days later a researcher at TestMachine published the finding it had quietly closed, at which point owners learned what they had been running. Ledger's CTO pushed back on the framing, and reasonable people disagreed about the disclosure timing, but nobody disagreed about the two words in the changelog.

The Coldcard case was worse, and it was worse in a way the EU rule is aimed at. A build configuration error in firmware 4.0.1, released back in March 2021, made some devices fall back on a weak software random number generator instead of the hardware entropy source, cutting effective key strength from 128 bits to as little as 40. TRM Labs documented what followed: starting 30 July 2026, attackers drained roughly 1,816 BTC, about 116 million USD, from more than 5,200 addresses across four waves. Owners had no way to inspect the flag that betrayed them, and the gap between the mistake and the day it became public ran to five years.

Why a clock helps, and how far it reaches

A deadline changes the incentive around bad news. When disclosure is voluntary, the quiet path is usually the cheapest one for the company and the most expensive one for the owner, because every day of silence is a day the people holding the affected device keep using it. Putting a regulator on the other end of a 24-hour timer removes the option of waiting to see whether anyone notices.

The limits are worth being clear about. This is an EU regulation, so it binds companies selling into the EU rather than every maker everywhere, though in practice a firm shipping worldwide tends to run one disclosure process rather than two. It covers vulnerabilities that are actively being exploited, which means a flaw nobody has found yet is still nobody's clock. Most of the Cyber Resilience Act's heavier obligations, the security-by-design and certification requirements, don't arrive until December 2027. And the rule tells you sooner that something went wrong; it cannot reach back and unwind a transaction that already signed.

That last limit is the one worth sitting with, because it defines the part of your setup that no regulation is going to fix for you.

The part no disclosure rule can reach

Faster reporting addresses one category of risk: the maker knew something and you didn't. It does nothing about the other category, which is what happens on an ordinary Tuesday when nothing has been exploited at all and the single object holding your recovery is gone. House fire, a move, a drawer someone cleared out, a relative who threw away a card with twelve words on it. No regulator gets notified, because nothing was breached.

This is where the standard advice runs out. Paper degrades and burns, so the usual upgrade is a steel plate, and a steel plate is a better object than paper by a wide margin. Your recovery still depends on one item surviving every scenario, and one item is a thin margin for something you cannot reissue.

How TapSafe changes the backup picture

We built TapSafe Recovery to remove that single point of failure rather than harden it. Recovery is split across a Recovery Tag that holds 50%, and a paired phone that holds the other 50%, stored encrypted in your iCloud or Google Drive instead of on the handset, so losing the phone doesn't lose the share. Optional Recovery Contacts each hold 25%, and those contacts can see nothing about your wallet. The split runs on a custom implementation of Shamir's Secret Sharing, and your seed phrase stays available on the device as a last resort, on the BIP-39 standard, so you are never locked to our hardware.

On the disclosure question itself, the Ryder One's firmware has been independently audited by Halborn, and the full report is public rather than summarized. Private keys are generated inside an EAL6+ certified Infineon SLC38 secure element and never leave it. Every transaction is shown on the 1.6-inch AMOLED screen in readable detail before you approve it, so what appears on the device is what gets signed.

What to do with this

If you own a hardware wallet from any maker, the practical move this week is dull and worth doing: check that you are on current firmware, and find out whether your manufacturer publishes readable changelogs or two-word ones. The EU has decided that owners are entitled to hear about live flaws within a day. That standard is a reasonable thing to expect from whoever made the device in your drawer, wherever they happen to be incorporated.

Ready to hold your keys without betting everything on one backup object? Get your Ryder One for 149 USD.


Meta description: Since 11 September 2026, EU crypto wallet vulnerability reporting runs on a 24-hour clock. What the Cyber Resilience Act covers, and what it leaves to you.

Target keyword: crypto wallet vulnerability reporting

Meet Ryder One

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More