Critical Balance‑Handling Flaw in Cosmos EVM Module Exploited, Draining Funds Across Six Blockchains
What Happened — Cosmos Labs disclosed a critical balance‑handling vulnerability (GHSA‑7g4w‑cg88‑2cq2) in its shared Cosmos EVM module. Between 20 and 25 August 2026 attackers exploited the flaw to siphon funds from six independent blockchains that run the module.
Why It Matters for Compliance & Audit Readiness
- The incident illustrates a classic control‑gap: unpatched code in a shared runtime that directly impacts asset integrity.
- SOC 2 continuous‑compliance programs require documented evidence that such critical vulnerabilities are identified, prioritized, and remediated before they can be leveraged.
- Mapping the flaw to the Control Mapping capability gives you auditable proof that the vulnerability was tracked, mitigated, and that evidence of the remediation is continuously collected.
Who Is Affected – Crypto‑exchange platforms, DeFi protocols, blockchain‑as‑a‑service providers, and any organization running the Cosmos EVM module (primarily the TECH_SAAS sector).
Recommended Actions
- Align the vulnerability with SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management) controls; record the finding in your risk register.
- Deploy the patched Cosmos EVM version ≥ 0.6.2 across all environments and verify the rollout with automated evidence collection.
- Implement continuous monitoring of third‑party module versions and integrate GHSA alerts into your compliance dashboard. Source: The Hacker News
Technical Notes – The flaw resides in the balance‑handling logic of the shared EVM module (versions < 0.6.2). It was disclosed without a CVE, CVSS score, or formal weakness classification, but Cosmos Labs rates it Critical. Exploitation leveraged direct contract calls to manipulate token balances, resulting in fund loss on six blockchains. Source: same