Crypto wallet providers operating in the European Union will soon face some of the tightest cybersecurity disclosure deadlines applied to the sector so far. New EU rules require an early warning within 24 hours of an exploit being discovered, followed by a full notification within 72 hours. Providers that fail to comply face administrative fines of up to $17.3 million.

The requirements place wallet providers under the same kind of urgency long expected of banks and critical infrastructure operators when it comes to reporting breaches. For an industry that has repeatedly suffered high-profile hacks and exploits, the compressed timeline leaves little room for internal investigation before regulators must be told something has gone wrong.

What the deadlines mean in practice

The 24-hour window applies to an initial, early warning notice, meant to flag that an incident has occurred even before its full scope is understood. The 72-hour deadline covers a more complete notification, giving authorities a fuller picture of the exploit, its impact and the response taken by the provider.

For wallet providers, this means building or upgrading internal processes to detect and escalate incidents fast enough to meet both deadlines. Firms that historically took days or weeks to confirm and disclose a breach publicly will now need to notify regulators far sooner, regardless of whether they have finished their own forensic review.

Fines set a firm ceiling

The maximum administrative fine for failing to meet the reporting obligations is set at $17.3 million. That figure represents the ceiling regulators can impose on providers found to have missed the deadlines or failed to report at all, rather than a fixed penalty applied in every case.

The scale of the potential fine signals that EU authorities intend the rules to carry real weight rather than function as a symbolic requirement. For smaller wallet providers in particular, the prospect of an eight-figure fine is likely to accelerate investment in incident-response capacity.

The rules add to a broader pattern of the EU tightening its grip on crypto-related cybersecurity and operational resilience, following earlier measures aimed at bringing digital asset service providers under frameworks originally designed for traditional financial institutions. Wallet providers serving EU customers will now need to treat rapid breach disclosure as a core compliance function rather than an afterthought.