Three Things Worth Your Attention
OFAC Extends Iran Sanctions to the Digital-Asset Sector
On August 24, the U.S. Treasury’s Office of Foreign Assets Control identified Iran’s digital-asset sector—alongside aviation, gold, shipping and technology—as an additional sector covered by Executive Order 13902.
The determination does not automatically sanction every company connected to Iranian digital assets. It gives the U.S. government authority to designate foreign persons that operate in, or knowingly conduct significant transactions involving, the sector. For exchanges, custodians and other crypto businesses, this broadens sanctions risk beyond screening individual wallets and named entities.
The SEC’s Crypto Custody Rewrite Enters White House Review
On August 25, proposed amendments to the SEC’s custody rules were submitted to the White House Office of Information and Regulatory Affairs for review.
The public text of the proposal has not yet been released, so its eventual requirements remain unknown. The SEC’s regulatory agenda says the initiative is intended to modernize custody rules for investment advisers and investment companies, including by clarifying how crypto assets can be held under the existing framework. The review is an important procedural step, but it is not yet an adopted rule—or even a publicly released proposal.
View the regulatory review record
Read the SEC rulemaking description
A Shared Cosmos EVM Vulnerability Reaches Six Networks
On August 28, Cosmos Labs published a post-mortem confirming that attackers had exploited a vulnerability in Cosmos EVM across six blockchain networks between August 20 and August 25.
According to the report, approximately $2.87 million in affected assets was exchanged through decentralized exchanges, while another estimated $2.85 million was sold through centralized exchanges. Cosmos Labs acknowledged that the vulnerability had previously been reported, but its initial testing incorrectly concluded that production networks were not exposed.
The incident highlights a recurring problem in modular blockchain ecosystems: when multiple networks rely on shared software, a vulnerability—and any breakdown in disclosure or patch coordination—can spread well beyond a single chain.