Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Seattle judge deals blow to Kalshi, rejects prediction market’s federal defense

21 July 2026 at 16:33
GeekWire Illustration

A judge in Seattle issued a preliminary injunction against Kalshi, finding that Washington state is likely to prove that the fast-growing prediction market is running illegal online gambling.

The ruling by King County Superior Court Judge John McHale, issued Monday, does not immediately halt Kalshi’s operations in the state. McHale granted the injunction in the case brought by Washington AG Nick Brown, but deferred the specifics until early next month.

McHale rejected Kalshi’s argument that oversight by the U.S. Commodity Futures Trading Commission preempts state gambling laws. That has been the basis of Kalshi’s defense against regulators across the country. Washington is the latest state where a court has shot it down.

Kalshi quickly pushed back on the ruling.

“States don’t have jurisdiction to regulate prediction markets. Many courts — including the Third Circuit — have made this clear,” spokesperson Jacki McGavick said in a statement. “We’re disappointed to see Washington State continue wasting taxpayer dollars.”

In his ruling, McHale said Kalshi “willfully ignored” a December 2025 notice from the Washington State Gambling Commission that event-based contracts were not authorized in the state, and cited a Kalshi ad showing a text exchange where one user tells another: “I found a way to bet on the NFL even though we live in Washington.”

Kalshi’s platform lets users bet “yes” or “no” on thousands of events across sports, elections, entertainment, and so-called “mention markets” — wagers on whether public figures will say specific words. The New York-based company, which markets itself as a federally regulated “prediction market,” takes a transaction fee on each bet.

Washington has some of the strictest gambling laws in the country: the legislature banned internet gambling in 2006, and while the state allows a lottery, horse racing, and tribal-casino gambling, online betting is broadly prohibited and sports wagers are legal only in person on tribal lands.

The order requires Kalshi to preserve all records tied to Washington users, including logs, communications, geolocation data and marketing materials.

The specific operational terms of the injunction are still being determined: McHale gave both sides until Aug. 3 to submit proposed language, with a full order to follow by Aug. 5.

DA: Cop covered bodycam to snap nude prisoners on his iPhone—but other cams caught him

20 July 2026 at 18:15

On March 31, 2026, a rather odd complaint arrived at the Bucks County, Pennsylvania District Attorney's Office.

It came from the local sheriff's office, and it concerned one of their own, Deputy Sheriff Ryan Gaffney. The allegation was unusual: Gaffney had used his iPhone to snap photos of nude prisoners he had encountered in his job—and he had then shared those photos with "several female civilian employees inside the Sheriff's Office."

The main claim involved a local man suffering a mental health crisis on the morning of January 30, 2026. Five fully uniformed deputies had arrived at the house and were in the upstairs bedroom. Their detainee was naked from the waist down and had just been persuaded to put on some pants.

Read full article

Comments

© Getty Images

How law and regulation are responding to technological change in digital assets and money: what…

How law and regulation are responding to technological change in digital assets and money: what does it mean for businesses?

Written by Brett Hillis, Partner Reed Smith LLP

Technological change is nothing new and legal systems have been responding to it since at least the introduction of the printing press. Changes in technology gives rise to questions that the law has not needed to answer before, or not at the same scale. To take an example, how should law and regulation respond to driverless vehicles? Should such vehicles be allowed on public roads? What safety requirements do such vehicles need to comply with? Who is liable for accidents caused by such vehicles?

Whilst there is an interesting history to how law and regulation respond to technological change, the purpose of this article is to identify different approaches that law and regulation is taking to technological change today, looking specifically at digital assets and digital money. These are important issues for business; the carrying on of transactions between AI agents is going to require some form of programmable money as measure of value and a means of exchange. Tokenisation has the capacity to reduce settlement times and make many transactions more efficient. At the same time, the stakes in decisions on where to invest feel higher than ever before, as such decisions face conflicting trends. Capital feels more mobile than ever and can search out opportunities across jurisdictions. Businesses have greater opportunities to create brand value globally and network effects create “winner take all” markets, where a Taylor Swift is dominant in a way no one else has been for decades. At the same time, countries are taking much more varied approaches to how these markets affect their economies. Some are adopting an “open doors” policy, others are pragmatically adopting regulatory regimes, whereas others have rejected these markets in favour of centralised national paradigms.

CBDCs vs private stablecoins

At present, the most obvious distinction is between those jurisdictions which are embracing private stablecoins, chiefly the US, and those looking to develop their own central bank digital currencies (all be it not using blockchain technology to do so), most notably China. Through the GENIUS Act, the US has developed a comprehensive regulatory framework for USD denominated stablecoins. The same time, the US has taken steps to prevent the establishment, issuance and use of CBDCs within the US. This ban affects not just foreign issuers but the US Federal Reserve itself.

China bans unapproved yuan stablecoins

Source: X

At the other end of the spectrum, China has maintained a ban on cryptocurrency transactions since 2017, which continues to be extended. For example, earlier in 2026, China was reported to have banned unauthorised offshore issuance of yuan-pegged stablecoins. At the same time China has been promoting the digital yuan, which is seen as part of a strategy to reduce reliance on the US dollar. The two superpowers represent opposites in their approach and, while interesting geopolitically, their different approaches to this most obvious issue are not the most elucidating for businesses since the choice likely amounts to being ‘open for business’ or not. Of more interest are some of the more subtle distinctions regarding how countries are responding to digital assets and programmable money.

Laying the groundwork?

Before one gets to regulation, a fundamental question is the legal nature of digital assets — in particular, are they a form of property and, if so, what form of property? Answering these questions are key to establishing dependable ways in which digital assets can be used. A legal regime that does not reliably address these questions can leave the most basic questions for business uncertain. Whilst this may not stop innovation, it puts a break on investment especially where the underlying issue manifests itself. The way to approach these issues can vary between countries based on the legal system with courts, legislators, academics and trade bodies all potentially playing a role. In England, whilst there are critical voices, a response to these questions has received broad acceptance. Work on the issues proceeded through the UK Jurisdiction Taskforce’s (“UKJT”) Legal Statement on cryptoassets and smart contracts, Law Commission projects and decided cases, and included a short piece of legislation (the Property (Digital Assets etc) Act 2025) to address one specific uncertainty. Whatever the questions about regulation, attention to these essential issues of legal classification is vital.

Early regulation vs “wait and see”

Some jurisdictions moved early to set up regulatory regimes for digital assets. An interesting example was the EU and its MiCAR regulation. In setting out a regime early, MiCAR gave market participants a level of predictability about the scope and content of regulation. Having a clear target as to what businesses need to do and, crucially, certainty that it will not change with the political weather, has encouraged many international digital asset companies set up MiCAR regulated entities in response. That early approach can also act as an anchor, pulling the regimes of other jurisdictions towards it, in terms of the scope and content of regulation. The EU’s approach has generated a lot of institutional interest, and early regulatory adoption can build credibility. But early adoption risks rules becoming out of date. Much of MiCAR was already written by the time of the FTX collapse. It appears that the EU digital assets industry has achieved good growth with no obvious failures, but there is a perception (fair or unfair) of unnecessary friction in the EU regime.

An obvious comparator to the EU is the UK’s approach, which has been to move later and in a more piecemeal fashion seeking to learn lessons from other countries’ approaches. The UK introduced AML requirements for cryptoasset firms at the same time as the EU, then moved to regulate financial promotion and is bring cryptoassets fully within the UK regulatory perimeter, with effect from October 2027. The theory behind this approach is that it will better enable the UK to calibrate its regime to reflect the experiences of other jurisdictions. Certainly, the UK’s consultations on the new regime have been extensive and industry has been given a good opportunity to consider and comment on the potential new rules. Whether that effort is worth it will partly come down to the extent to which this work has produced a better regime, or one that industry and the public better understand.

But that is not the only factor. The “wait and see approach” has allowed some crypto businesses to develop and grow in the UK whilst complying with the more limited current or developing regime and gain traction and size whilst not imposing full regulation on them from the outset. On the one hand, these businesses face a more complex and changeable path to dealing with emerging regulation; on the other hand, some of that greater complexity only arises when they are in a better position to address it. The approach has also given the UK the time and space to work out its views regarding digital assets. There was considerable scepticism at the regulatory level regarding these products and markets but those views have become somewhat more balanced, although there is room for further movement. There is also evidence that UK authorities have been listening to industry (see its response to criticism of holding limits on stablecoins discussed below).

Embrace the substitutes?

One way to distinguish different countries’ approaches to this area is how comfortable they are with products and services that are substitutes (sometimes less than perfect substitutes) for existing products and services. More specifically, to what extent are they comfortable with holdings of stablecoins as a substitute for deposits? The US has established a comprehensive prudential regime for stablecoins through the GENIUS Act and appears unperturbed about any potential for holdings of stablecoins to reduce bank deposits and its effect on US financial stability. Stablecoins appears to be an acceptable substitute for bank deposits — indeed, the point seems hardly to have been raised. The UK approach has been different in that the Bank of England has been exercised about the effect on bank deposits. In part, this has been to avoid customer confusion — setting up guardrails to reduce the risks a stablecoin issued by a bank is, in fact, a deposit with deposit protection sitting behind it. This lies behind the Bank of England preventing banks issuing stablecoins except through a separate company. But the UK approach has gone beyond this and the Bank has proposed strict holding limits on stablecoins, a move which provoked industry backlash — even from the House of Lords. In response, the Bank has said it is examining alternative means of ensuring financial stability (e.g. through issuance limits). It will be interesting (and important) to see where it lands.

Are there lessons for firms from this experience?

I think there are several general points for those firms navigating policy in this field:

· understand how policy can shift — firms need to think through and hedge against how the policy approach can change, as demonstrated by the variety by the shifts in US policy.

· good regulation can build credibility — there is comfort in dealing with firms that are well-regulated.

· respond to consultations — whether through trade associations or on your own. It may well make a difference.

The battle over stablecoins, CBDCs and tokenisation is often presented as a technology story. It is not. It is a competition for economic influence. Just as previous generations fought to host stock exchanges, payment networks and internet platforms, today’s race is about who controls the rails of programmable value. The jurisdictions that get law and regulation right will attract capital, talent and innovation. Those that get it wrong may discover that in the digital age, financial leadership can migrate far faster than anyone imagined.


How law and regulation are responding to technological change in digital assets and money: what… was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

DHS IG investigating reassignments of senior staff under Noem

The IG review comes after hundreds of DHS staff received mandatory reassignments, in some cases to support the Trump administration's immigration crackdown.

© AP Photo/Susan Walsh

FILE - The Homeland Security Department headquarters in northwest Washington, on June 5, 2015. The Department of Homeland Security says the U.S. faces a "heightened threat environment" with the approach of the holidays. (AP Photo/Susan Walsh, File)

A Rare Drone Common Sense Outbreak, In Denmark

2 July 2026 at 04:00

Last September, Denmark was gripped by a spate of drone sightings near airports. It’s familiar territory for Hackaday, as we reported on a similar drone panic saga at British airports back in the last decade. Back then the British police dragged their feet and hid behind secrecy laws for years to avoid admitting they overreacted, but it seems in Denmark they do things differently (Danish language, Google Translate link.).

The Danish police in Jutland have rolled back their report, and noted that a reported observation alone is not enough to confirm a drone was present. It’s not confirmed why they’ve taken this step, but we’ve been told that there’s been an effort within the drone community to identify possible aircraft flight paths which could have resulted in a false drone sighting at the times in question.

We welcome this correction, and hope that its important message travels widely. Of course it is the right thing to do for a police force to take drone reports seriously, but overreacting as the British police did is of little help. We commend the Danish police for taking this step, and we’re likely to trust any drone reports from them a little bit more in the future. If you’d like to read our plea for a sensible response at the time, it’s here.

Thanks [UAVHive] for the tip.

OpenClaw: risks for the users and how to mitigate them

By: Kaspersky
1 July 2026 at 02:42

OpenClaw, which was previously known as Clawdbot and Moltbot, is today one of the most successful and fast‑growing ecosystems for AI agents, recognized worldwide. The project quickly became popular with users because of its flexibility and ability to solve fairly complex tasks that previously required a lot of time for automation and execution. A dedicated marketplace appeared quickly after the project started gaining traction, where developers and users began publishing tools that integrate with OpenClaw. Currently, employees all over the world use OpenClaw to automate their tasks, often unaware of risks this practice introduces to them and their employers.

In this article we will examine several security aspects of OpenClaw, look at how attackers can target this system, which vulnerabilities are already known, and how to protect your organization against these issues.

OpenClaw skills

The project’s success was ensured by the fact that the agent accepts natural language instructions, does not require knowledge of programming languages, and allows the use of skills, which expand its capabilities. The overall architecture of OpenClaw can be seen below:

The OpenClaw overall architecture

The OpenClaw overall architecture

As shown in the diagram, the system is designed to be used with agent skills. These skills can reside locally on the system where the agent is installed or they can be obtained from external sources. At the time of writing this article, a dedicated hub named “ClawHub” is used for sharing skills with other users.

One of the key features of OpenClaw skills is that they are easy to create and do not require coding. A skill is in essence a set of commands written in natural language, although it can contain code. Currently, there is a general description of the skill format: it is usually a text file named SKILL.md, although more complex variants may exist. The primary requirement for these files is that they use a plaintext format. To illustrate what this looks like, here is a fragment of a skill:

Openclaw skill example

Openclaw skill example

The applications for OpenClaw skills are quite broad and can include everyday tasks like checking email, performing routine operations and calculations on a computer, as well as more complex pipelines that handle testing, research, or software development. For most actions, the agent requires access to the operating system’s file system, as well as to the tokens and keys of the systems it will interact with. All necessary data are usually provided by users either through environment variables or in plaintext files located alongside the agent.

Since many skills enable automation of work processes, employees worldwide actively use them. This fact, combined with the widespread adoption of the system and the overall popularity of artificial‑intelligence technologies, has attracted attackers to the project.

OpenClaw vulnerabilities

In less than two years, around 530 vulnerabilities have been discovered both in OpenClaw itself and in the underlying technologies. That said, the publication of OpenClaw vulnerabilities in the CVE database began only in February 2026. Below is a breakdown of these vulnerabilities by severity.

Registered vulnerabilities (download)

As shown in the chart, the number of high-severity vulnerabilities is quite large. Most of these vulnerabilities fundamentally involve issues with storing sensitive data and operating with excessively high privileges. Each of them can be exploited to hijack the agent or inject commands that it will execute.

Malicious skills

Besides exploiting vulnerabilities and deceiving users, there are more specific attack vectors against OpenClaw, namely, skills.

Research logically draws a parallel between supply‑chain attacks and the distribution of malicious skills. However, unlike usual supply-chain attacks, creating malicious skills is trivial because there is no longer a need to develop custom malware. Despite this, until February 7, 2026, no skills had undergone even a basic security check, which allowed malicious skills to appear immediately. Our scan of the skill hub in April identified 24 accounts that were distributing more than 600 malicious skills. Overall, open‑source intelligence indicates that over 1100 malicious accounts have been created since January.

Following the investigations and a lengthy effort to clean the skill repository of malicious entries, it was announced that files would undergo preliminary scanning with VirusTotal (VT) and NVIDIA’s SkillSpector. On the one hand, this is a more responsible approach to publishing skills; on the other, because OpenClaw is primarily an agent that executes a set of instructions, detecting malicious activity moves to a different level. Now it is necessary not only to analyze a file for dangerous commands that should be blocked, but also to examine all possible malicious behaviors that could be triggered by a harmful instruction within a skill. An example of a malicious command in natural language:

Example of a malicious command within a skill action

Example of a malicious command within a skill action

An example of a malicious command using a part of a bash command:

Malicious command inside a skill

Malicious command inside a skill

The example in the image and similar malicious skills are detected by Kaspersky products as HEUR:Trojan.ANSI.MalClaw.gen.

In addition, Kaspersky products monitor malicious OpenClaw skill activity on the system. Below are detection statistics from our systems that have identified malicious OpenClaw client behavior. The data for June cover the first half of the month.

Statistics on Kaspersky product detections of OpenClaw malware (download)

As shown in the chart, even despite the measures taken to counter the publication of malicious skills, attacks continue. Therefore, it is important to employ layered protection that isolates the OpenClaw agent from critical data and infrastructure systems. We also recommend checking all skills that enter the organization’s perimeter. For this purpose, Kaspersky Scan Engine is suitable. This solution is designed to protect web applications, proxy servers, network attached storage, and mail gateways. It can be integrated into almost any application, and it is easy to deploy and manage.

Malicious skill detected by Scan Engine

Malicious skill detected by Scan Engine

Additionally, monitor network accesses used by the agent. For this purpose, the project already provides a sandboxing subsystem and various wrappers for working with APIs and services. Last but not least, develop a comprehensive AI policy and make sure your employees never use third-party tools that they are not explicitly allowed to use.

Trump administration expands options for firing federal employees deemed ‘unsuitable’

A final rule from OPM will require agencies to consider additional factors when determining whether federal employees should remain in their jobs.

© AP Photo/Mark Schiefelbein

FILE - The Theodore Roosevelt Building, location of the U.S. Office of Personnel Management, on Feb. 13, 2024, in Washington. The government's chief human resources agency has issued a new rule making it harder to fire thousands of federal employees. Advocates hope the rule will head off former President Donald Trump's promises to radically remake the workforce along ideological lines if he wins back the White House in November. (AP Photo/Mark Schiefelbein, File)
❌
❌