Crypto Law Brief: The SEC Cancels Its Own Reg Crypto Vote, Hawaii Bans Cash at the Kiosk, and a Zero-Click Zoom Flaw
Crypto's legal calendar rearranged itself overnight. The SEC scrapped its own rulemaking vote with a day's notice, Hawaii pulled cash out of crypto kiosks, a zero-click Zoom flaw hit the industry's favorite meeting tool, and a no-action letter cracked open custody rules for tokenized funds. Here is what each changes.
The SEC Cancels the Vote It Scheduled
The Commission was set to meet at 10 a.m. Eastern on August 14 to vote on publishing Regulation Crypto, a roughly 400-page proposal creating three pathways for token issuers: a $5 million startup exemption on whitepaper-style disclosure, a $75 million fundraising exemption with audited financials, and a safe harbor letting sufficiently decentralized tokens exit securities classification. On August 13, one day out, the SEC pulled the meeting, citing an "unforeseen scheduling issue," with no new date.
A cancelled meeting is not a withdrawn rule, but the timing matters. Commissioner Hester Peirce, who authored the safe harbor framework, leaves in November with no successor nominated, and the CLARITY Act's Senate procedural vote has slipped to September 15. Until one lands, token issuers are governed by the same law as last week: SEC v. Howey and enforcement discretion. An unpublished proposal is not a defense.
Hawaii Cuts Off Cash at the Kiosk
Act 224, signed as House Bill 1642 on July 9, takes effect October 1. It bars operators from running any kiosk that accepts U.S. currency in exchange for a digital asset; crypto-to-cash and crypto-to-crypto remain permitted. The FBI logged 92 kiosk complaints and $3.85 million in adjusted losses among Hawaii residents in 2025. Hawaii is the 35th state with a kiosk consumer-protection law and the first to ban cash-in machines outright. Attorneys general in D.C. and Iowa found over 93% of examined kiosk transactions were scams.
For victims, kiosk statutes matter more than they appear to. They add disclosure duties, transaction caps, refund windows, and licensing obligations — statutory hooks a fraud claim against an offshore scammer does not offer, because the operator is domestic, licensed, and reachable.
A Zero-Click Zoom Flaw Aimed at Crypto Teams
Researchers disclosed CVE-2026-53413, nicknamed "Zoomsday," a memory-safety defect in Zoom's annotation protocol that lets a malicious meeting participant execute code on another attendee's device with no click, download, or prompt. It was confirmed on Windows, macOS, iOS, and Android, and the researchers built a working exploit in under 24 hours using fewer than 20 prompts against public AI models. Zoom has shipped fixes in Workplace 7.1.5 and 7.0.6, Rooms 7.1.5, and Meeting SDK 7.1.5.
Fake investor calls and sham recruiter interviews are already a standard entry point against founders and fund staff, which makes this a crypto story rather than an enterprise IT one. The legal wrinkle is evidentiary: patch status is logged and discoverable. An unpatched client on a machine that touches signing keys is the sort of detail that surfaces in a negligence claim or an insurer's denial letter.
A Custody Door Opens for Tokenized Money Funds
On August 12, the SEC's Division of Investment Management issued a no-action letter permitting Franklin Templeton's registered mutual funds and ETFs to hold shares of FOBXX, its roughly $726 million onchain government money fund known by the BENJI token, without satisfying certain Rule 17f-2 custody requirements written around physical certificates.
Read the scope carefully. No-action relief is fact-specific and binds no one else. It turns on one feature: an affiliated transfer agent that keeps the official ownership record and can correct blockchain entries. A structure where the chain is the sole record of ownership is a different question this letter does not answer.
How to Protect Yourself
Update every Zoom client to 7.1.5 or 7.0.6 now, and be strictest about the machine that touches your wallets; decline unscheduled calls from unknown investors or recruiters on any device holding keys. If someone has told you to deposit cash at a crypto ATM, that instruction is a scam with a 93% base rate, and the urgency is the tell.
Recourse exists more often than people assume. Kiosk losses may be recoverable from a licensed domestic operator under state consumer-protection statutes. Device-compromise losses may implicate a custodian's or employer's duties, and cyber coverage often turns on facts developed in the first days. Any claim's value depends on evidence gathered quickly: transaction hashes, device logs, exchange records, and a prompt IC3 report.
At Coin Counsel, we work with individuals and businesses navigating the legal fallout of crypto fraud — whether you're a victim seeking recovery, a company facing regulatory scrutiny, or a project working to stay compliant in an increasingly complex legal landscape. The rules are evolving fast, and the cost of getting it wrong has never been higher. Contact us at coin-counsel.com to speak with a crypto-focused attorney today.
Disclaimer
This blog post is for informational purposes only and does not constitute legal advice. Reading this content does not create an attorney-client relationship between you and Coin Counsel or Franco Law PLLC. The legal landscape surrounding cryptocurrency is rapidly evolving and varies by jurisdiction. Do not act or refrain from acting based on information in this post without first consulting a qualified attorney. If you believe you have been the victim of crypto fraud, contact us at coin-counsel.com for a consultation.