Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Balance‑Handling Flaw in Cosmos EVM Module Exploited, Draining Funds Across Six Blockchains

Cosmos Labs reported a critical GHSA‑identified flaw in its shared EVM module that was exploited in August 2026 to drain assets from six blockchains. The incident underscores the need for SOC 2‑aligned control mapping and continuous evidence of remediation.

LiveThreat™ Intelligence · 📅 August 29, 2026· 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
2 recommended
📰
Source
thehackernews.com

Critical Balance‑Handling Flaw in Cosmos EVM Module Exploited, Draining Funds Across Six Blockchains

What Happened — Cosmos Labs disclosed a critical balance‑handling vulnerability (GHSA‑7g4w‑cg88‑2cq2) in its shared Cosmos EVM module. Between 20 and 25 August 2026 attackers exploited the flaw to siphon funds from six independent blockchains that run the module.

Why It Matters for Compliance & Audit Readiness

  • The incident illustrates a classic control‑gap: unpatched code in a shared runtime that directly impacts asset integrity.
  • SOC 2 continuous‑compliance programs require documented evidence that such critical vulnerabilities are identified, prioritized, and remediated before they can be leveraged.
  • Mapping the flaw to the Control Mapping capability gives you auditable proof that the vulnerability was tracked, mitigated, and that evidence of the remediation is continuously collected.

Who Is Affected – Crypto‑exchange platforms, DeFi protocols, blockchain‑as‑a‑service providers, and any organization running the Cosmos EVM module (primarily the TECH_SAAS sector).

Recommended Actions

  • Align the vulnerability with SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management) controls; record the finding in your risk register.
  • Deploy the patched Cosmos EVM version ≥ 0.6.2 across all environments and verify the rollout with automated evidence collection.
  • Implement continuous monitoring of third‑party module versions and integrate GHSA alerts into your compliance dashboard. Source: The Hacker News

Technical Notes – The flaw resides in the balance‑handling logic of the shared EVM module (versions < 0.6.2). It was disclosed without a CVE, CVSS score, or formal weakness classification, but Cosmos Labs rates it Critical. Exploitation leveraged direct contract calls to manipulate token balances, resulting in fund loss on six blockchains. Source: same

📰 Original Source
https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →