Public crypto companies must disclose cybersecurity incidents, per new SEC rules

The new rules add a layer of transparency for investors to see when a public company, such as Coinbase or MicroStrategy, has faced a cybersecurity incident

article-image

Michael Traitov/Shutterstock modified by Blockworks

share

The US Securities and Exchange Commission is requiring public companies, including public crypto companies, to disclose cybersecurity incidents.

The new rule, adopted on Wednesday, aims to ensure that investors receive potentially “material” information when a company has been attacked. 

“Currently, many public companies provide cybersecurity disclosure to investors. I think companies and investors alike, however, would benefit if this disclosure were made in a more consistent, comparable, and decision-useful way. Through helping to ensure that companies disclose material cybersecurity information,” SEC Chair Gary Gensler said. 

Companies such as Coinbase, Marathon Holdings, Bitdeer and MicroStrategy will be impacted by the new SEC rules. 

“There has been a substantial rise in the prevalence of cybersecurity incidents, propelled by several factors: the increase in remote work spurred by the COVID-19 pandemic; the increasing reliance on third-party service providers for information technology services; and the rapid monetization of cyberattacks facilitated by ransomware, black markets for stolen data, and crypto-asset technology,” the SEC noted.

The SEC added that “evidence suggests” that companies are “underreporting cybersecurity risks.”

The new rule change will make it necessary for companies to give clear and specific information about any incidents that occur. This information will include details about when the incident happened, how it affected the company and its users, whether any data was stolen or accessed, and updates on whether the company has remediated the situation. All of this will be included in a new item, dubbed 1.05, included on 8K forms. 

Public companies will also have to “describe their processes, if any, for assessing, identifying, and managing material risks from cybersecurity threats, as well as the material effects or reasonably likely material effects of risks from cybersecurity threats and previous cybersecurity incidents” on Regulation S-K. 

8K forms give investors updates on big changes at listed companies. 

The change comes as the SEC’s chief accountant warned that accounting firms working as auditors for the crypto industry need to be mindful of anti-fraud laws. 

SEC Commissioner Hester Peirce, who has shown support for crypto in the past, tweeted that “crypto platforms [and] their accountants should be clear about what proof of reserves is and isn’t,” but she warned against discouraging “good-faith efforts to provide more transparency.”


Get the news in your inbox. Explore Blockworks newsletters:

  • Blockworks Daily: The newsletter that helps thousands of investors understand crypto and the markets, by Byron Gilliam.
  • Empire: Start your day with top crypto insights from David Canellis and Katherine Ross.
  • Forward Guidance: Explore the growing intersection between crypto, macroeconomics, policy and finance with Ben Strack, Casey Wagner and Felix Jauvin.
  • 0xResearch: Get alpha directly in your inbox — market highlights, charts, degen trade ideas, governance updates, and more.
  • Lightspeed: All things Solana, in your inbox, every day from Jack Kubinec and Jeff Albus.
  • The Drop: The newsletter for crypto collectors and traders, covering games, tokens, apps, memes and more.
Tags

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 18 - 20, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

Industry City | Brooklyn, NY

TUES - THURS, JUNE 24 - 26, 2025

Permissionless IV serves as the definitive gathering for crypto’s technical founders, developers, and builders to come together and create the future.If you’re ready to shape the future of crypto, Permissionless IV is where it happens.

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Unlocked by Template (4).png

Research

Wormhole Settlement allows for a highly scalable liquidity venue to fill user intents into a multichain, multi-VM future. By concentrating solvers’ balance sheets on Solana, transaction costs associated with solvers rebalancing inventory across destinations are eliminated. With the ability to settle bridging, swapping, and arbitrary interactions, without the costs and frictions of fragmenting solver liquidity, Wormhole Settlement has the opportunity to settle a large share of volumes in the crosschain interoperability market with a beneficial framework for both users and solvers. 

article-image

Anthony Pompliano looks for folks who are running away from something rather than towards it

article-image

The Solana world has worked itself into a frenzy over SIMD-0228

article-image

Industry watchers weigh in on Trump’s Thursday night executive order

article-image

The new game lets you embark on quests, collect loot and socialize

article-image

It’s been 11 years since Newsweek ignited a media frenzy around Dorian Nakamoto