Crypto wallet providers must submit an early vulnerability report within 24 hours and a full notification within 72 hours of exploits, or risk administrative fines of as much as $17.3 million. The EU is telling cryptocurrency hardware and software wallet providers that they have 24 hours from awareness to report actively exploited bugs or severe security vulnerabilities affecting their products. The measure is part of the EU’s Cyber Resilience Act (CRA), which took effect on Friday, according to an announcement from the European Commission. Manufacturers must submit an early warning for severe vulnerabilities within 24 hours, followed by a full notification within 72 hours. A final report will be required 14 days after corrective or mitigating measures are available and within one month for severe incidents. Read more
Bitcoin traders brace for volatility as the CLARITY Act awaits a Senate vote to move forward and the Fed is due to announce its latest rate decision. Bitcoin (BTC) is starting the third week of September below key weekly support levels as traders eye volatility cues. Read more
Symbiosis is offering a 20% bounty for information leading to asset recovery after the hacker refused to return the stolen funds for the same white-hat bounty. Cross-chain liquidity protocol Symbiosis said it recovered 15 Bitcoin, worth around $1.1 million, from a Bitcoin bridge exploit it suffered Friday. Symbiosis said it recovered 15 Bitcoin (BTC) into a team-controlled multi-sig wallet and clarified that all routes remain operational, according to a Friday X post. The exploit affected Symbiosis’ native Bitcoin bridge, which remains paused. The attacker’s address minted 46.1 billion unbacked tokens from the protocol’s Bitcoin bridge but realized net proceeds of 4.3 Wrapped Bitcoin (WBTC), worth $336,000, according to blockchain security company Blockaid, which flagged the exploit on Friday. The protocol has not specified how the recovered Bitcoin relates to the $336,000 in proceeds attributed to the attacker. Read more