
New reporting mandates for actively exploited vulnerabilities and severe security incidents took effect September 11, 2026.
Under the EU's Cyber Resilience Act, manufacturers of connected hardware wallets and software must report actively exploited vulnerabilities or severe security incidents to cyber authorities within 24 hours, effective September 11, 2026.
AI-generated summary
The Cyber Resilience Act (CRA) is a horizontal product law in the EU requiring manufacturers to meet security standards for products with digital elements. It applies to hardware and software connected to devices or networks.
Commercial manufacturers whose connected hardware wallets or wallet software meet the European Union's product test must now warn cyber authorities within 24 hours of discovering an actively exploited vulnerability or severe security incident.
The requirement took effect Sept. 11, 2026, under the EU's Cyber Resilience Act, or CRA. The European Commission's reporting guidance says the clock applies to manufacturers of products with digital elements.
The CRA is a horizontal product law. The Commission's implementation FAQ says it applies to hardware and software made available on the EU market. The legal test also requires the product's intended or reasonably foreseeable use to include a direct or indirect data connection to a device or network.
A commercially supplied connected hardware wallet or downloadable wallet app can meet that test. However, EU guidance does not name wallet brands or declare every wallet service or project covered. Coverage depends on the specific product, how it is supplied and any applicable exclusion.
What manufacturers must report
The first filing is an early warning due without undue delay and no later than 24 hours after a manufacturer becomes aware of the vulnerability or incident. It must indicate, where applicable, the member states where the product is known to have been made available. For a severe incident, the warning must also say whether unlawful or malicious acts are suspected.
A fuller notification is due within 72 hours unless the relevant information was already provided. For an actively exploited vulnerability, that filing adds general information about the product, exploit and vulnerability, plus corrective or mitigating measures. For a severe incident, it adds the nature of the incident, an initial assessment and available mitigation information.
The final deadline differs by event. A vulnerability report is due no later than 14 days after a corrective or mitigating measure becomes available. The CRA sets the severe-incident final report deadline at one month after the 72-hour notification, as detailed in the regulation.
Manufacturers file once through the Single Reporting Platform launched by ENISA, the EU cybersecurity agency. The portal sends the notification to the designated coordinating Computer Security Incident Response Team and makes the information available to ENISA, then supports distribution to other relevant national teams. Manufacturers must also inform impacted users and, where appropriate, all users when action is needed, including measures they can take.
The reporting rule reaches in-scope products placed on the market before Dec. 11, 2027. That makes the new clock relevant to existing product lines, not only wallets first sold after the broader law takes effect.
Open-source licensing does not create a blanket exemption. The Commission's open-source guidance says commercially supplied free and open-source products can face manufacturer obligations. Non-monetized software supplied by its manufacturer should not count as commercial activity, while individual contributors are not treated as manufacturers for software outside their responsibility.
Open-source software stewards are a separate legal category, and their reporting duties begin Dec. 11, 2027. That is also when the CRA's main product-security requirements take effect. The Sept. 11 change starts the rapid reporting regime, not the law's broader secure-design and product-lifecycle framework.
AI outlook — possibilities, not facts
Manufacturers will update incident response protocols to meet the 24-hour reporting window.
Very likely · Within months

Anthropic CEO Dario Amodei warned that rapid AI development risks outrunning human control through recursive self-improvement, proposing international safety standards supported by OpenAI CEO Sam Altman.

Fintech company Revolut exposed sensitive customer data including IDs and transaction histories after receiving a fraudulent information request from a spoofed government email domain.

The XRP Ledger has activated the fixCleanup3_3_0 amendment, introducing maintenance updates for transaction handling and AMMs. Servers failing to support the new rules risk becoming amendment-blocked, necessitating software updates for infrastructure operators.

OpenAI's new ChatGPT Images 2.5 model is compared against Google's Nano Banana 2. While OpenAI resolved previous oversharpening issues, the models remain closely matched in performance, with each showing specific strengths in text rendering, spatial awareness, and factual accuracy.

Greenberg Traurig reported an unauthorized actor accessed and posted limited documents on the dark web, exposing client Social Security information. The breach is part of a growing trend targeting law firms, with BakerHostetler handling nearly 60 cybersecurity incidents in 2025. Other firms including Taft Stettinius, Herbert Smith Freehills, WilmerHale, Goodwin Procter, and Quinn Emanuel disclosed breaches. Crypto companies Coinbase, Ledger, and SafePal also reported customer data exposures.

OpenAI has consulted members of Congress on whether rival AI companies could legally agree to slow development, following internal calls for shared safety standards amid intense commercial and geopolitical competition. The outreach comes as researchers warn of pressure to cut corners on safety, with concerns that unilateral slowdowns put companies at a competitive disadvantage without industry-wide coordination.