Quiet multi-beat day: Coldcard CVE, three AI releases

Bitcoin Optech flagged a severe COLDCARD vulnerability plus two Core Lightning denial-of-service bugs. The Bitcoin beat saw a Bisq hotfix for the BitcoinJ chainwork bug, Coldcard Firmware 6.6, and a Fedimint Web RPC stream fix. AI infrastructure shipped three updates: llama.cpp added a driver version check for Windows Intel GPUs to mitigate crashes, InvokeAI 6.14.0 added video generation via Wan 2.2, and Cline CLI 3.0.48 moved history rendering into the TUI. Privacy side saw Tuta Calendar 355.260730.0 and a Proton blog post on document management systems. Self-hosting saw rclone 1.75.0.

Bitcoin

Privacy

Self-hosting

  • rclone 1.75.0. This is the v1.75.0 release of rclone; Full details of the changes can be found in the changelog.

AI

  • llama.cpp b10215. Windows Intel GPU driver version check added to prevent crashes; crash fixed in driver 32.0.101.8860 and later.
  • InvokeAI 6.14.0. Adds video generation support via Wan 2.2.
  • Cline CLI 3.0.48. History now opens inside the existing TUI with resume and delete actions; connector threads recover when bound session is gone.

Other

  • Bitcoin Optech Newsletter #416. Covers a severe COLDCARD wallet generation vulnerability, two Core Lightning DoS bugs, and a zero-knowledge proof-of-reserves proof of concept.

Read on Freedom.Tech: freedom.tech/posts/2026-08-01-bitcoin-daily-brief Get the weekly recap in your inbox: freedom.tech/subscribe

Freedom.Tech is powered by Foundation. Catch the weekly discussion on Freedom Tech Friday via Ungovernable Misfits.