Self-Custody
The EU's New Wallet Disclosure Rule, By the Numbers
The EU now gives crypto wallet makers 24 hours to report exploited flaws. Here is what the Cyber Resilience Act's actual numbers mean for you.
The number to know is 24. Since September 11, 2026, any company that sells a hardware wallet or wallet software into the European Union has 24 hours from the moment it learns of an actively exploited vulnerability to file an early warning with EU authorities. That clock is the core of the EU Cyber Resilience Act wallet disclosure requirement, and it switched on at the end of a summer in which self-custody devices, the tools people buy so nobody else holds their coins, failed in ways their owners learned about long after the damage started.
The Numbers Behind the EU Cyber Resilience Act Wallet Disclosure Rule
Article 14 of the Cyber Resilience Act sets a staged clock, not a single deadline. Each stage asks for something different.
| Stage | Deadline | What must be reported |
|---|---|---|
| Early warning | 24 hours | That an actively exploited vulnerability or a severe incident exists |
| Full notification | 72 hours | Technical detail on the flaw, its scope, and any mitigation so far |
| Final report (vulnerability) | 14 days after a fix is available | What the manufacturer did to correct or mitigate it |
| Final report (severe incident) | 1 month after the 72-hour notification | Root cause, impact, and the measures taken |
| Full CRA obligations | December 11, 2027 | Security-by-design requirements beyond incident reporting |
Manufacturers file once, through the Single Reporting Platform that ENISA, the EU's cybersecurity agency, operates. ENISA's page on the Single Reporting Platform describes the same staged timeline and explains that the platform forwards each report to the relevant national response teams, so a wallet maker does not have to notify a dozen regulators one by one.
Why the 24-Hour Clock Lands Now, By the Numbers
The EU did not write this rule in reaction to this summer. Lawmakers adopted the Cyber Resilience Act in 2024 as Regulation (EU) 2024/2847 and gave manufacturers until September 11, 2026 to be ready for the reporting duties. What changed is the context the clock starts ticking in.
The case every crypto reader has in mind is the Coldcard firmware flaw. Galaxy Research's running tally put losses near 1,816 BTC, close to 116 million dollars, drained from more than 5,200 addresses across four waves of theft starting July 30, 2026. The root cause was a firmware bug, shipped since 2021, that weakened the randomness behind some wallet seeds, so attackers could rebuild seed phrases without touching the device. More than five years passed between the flawed firmware shipping and owners learning their seeds were at risk.
Article 14 would not have stopped that bug from existing. It puts a clock on how fast the company that shipped a flaw has to tell regulators once someone exploits it. For a seed-generation bug, the damage clock and the disclosure clock start at the same moment: the first sweep.
Other vendors were not implicated. Coinkite traced the flaw to a specific Coldcard firmware line, and Trezor published its own write-up on the incident for its users. The pattern the new rule targets is the gap between exploitation and public knowledge, whoever the vendor is.
What Self-Custody Means in These Numbers
Casual coverage blurs what this law covers. Article 14 applies to manufacturers of "products with digital elements," a category that includes hardware wallets and wallet software because those products connect to networks and other devices. A hosted mining pool sits in a different place. A non-custodial pool like NexusPool never holds a miner's private keys or a balance: the coinbase transaction in a found block pays the miner's own address, with no internal account for the pool to control. That is a different failure mode from a reconstructable seed, but it rests on the idea the EU is now writing into law. A system that claims to be non-custodial should be checkable, not taken on the maker's word.
The same reasoning sits behind NexusPool's Glass Ledger, which signs custody and work receipts so you can check them offline instead of trusting a dashboard figure, and behind the Payout Preflight tool, which rebuilds the exact coinbase transaction the pool would pay to your address, against the live block template, before your hardware ever finds a block. Neither exists because of the CRA. Both exist for the reason the CRA's clock exists: "trust the manufacturer" has a documented, expensive failure rate.
What the Numbers Mean If You Own a Hardware Wallet
You do not need to panic about any specific device. You need three habits tied to the numbers above. First, write down your wallet's firmware version and the date you generated your seed, before an advisory forces you to look it up under pressure. Second, use the clock as a yardstick: an exploited flaw should produce an early warning within a day, technical detail within three days, and a final report within two weeks of a fix, so a vendor that stays silent well past those windows is telling you something. Third, remember that the filing goes to regulators, not to your inbox, so keep following the vendor's own advisories and independent researchers rather than assuming an EU report will reach you.
This post does not claim any specific device is unsafe today, that self-custody removes all risk, or that a faster disclosure clock changes mining odds or payout mechanics on any chain. Odds depend on your hashrate divided by the network's, identical at every pool. It is not investment or financial advice, and it does not claim NexusPool's core software is open source, because it is not.
Twenty-four hours to warn, seventy-two to explain, fourteen days after a fix to close the file. Put those three numbers next to your firmware version and you know what to expect the next time a wallet maker has bad news. Trust nothing. Verify how fast your own wallet's maker has to tell you when something breaks.