Key Takeaways
- MARA Basis opened Slipstream to the general public on August 3, 2026, dropping its shopper code requirement.
- A Coldcard firmware flaw from March 2021 let hackers drain as much as $88 million from about 500 wallets.
- Look ahead to up to date Coldcard firmware steering and additional loss estimates as extra addresses are checked.
MARA Strips Away the Entry Codes
MARA Holdings, the Nasdaq-listed bitcoin miner and synthetic intelligence (AI) infrastructure supplier, previously generally known as Marathon Digital, constructed the Slipstream service so folks can ship bitcoin transactions straight to its mining pool as a substitute of broadcasting them to the general public community.
Most bitcoin transactions journey by way of a shared ready room referred to as the mempool, the place each node on the community can see a transaction earlier than it will get confirmed right into a block. Slipstream skips that ready room. A consumer submits a signed transaction on to MARA, and it stays hidden till MARA mines a block with it inside.
On August 3, 2026, MARA Basis posted the replace on X:
“MARA Slipstream is now accessible as a permissionless public good with no shopper code requirement. Please watch out and conservative with charges to keep away from transactions getting caught within the Slipstream mempool within the occasion that aggressive charges spike. For the foreseeable future, we aren’t charging extra charges for this service, however customers are chargeable for paying applicable Bitcoin transaction charges.”
That final level issues. MARA shouldn’t be including its personal surcharge. Customers nonetheless pay regular Bitcoin community charges, they simply ship the transaction by way of a personal channel as a substitute of the open one.
A {Hardware} Pockets Flaw Forces the Timing
The timing shouldn’t be a coincidence. On the finish of July, researchers disclosed a critical flaw in Coldcard {hardware} wallets, tracing again to a firmware coding error from March 2021. As an alternative of pulling randomness from the gadget’s devoted {hardware} generator, affected Coldcard fashions fell again to a weaker software program course of when making a pockets’s 24-word seed phrase. That mistake reduce the efficient randomness from an anticipated 128 bits right down to roughly 40 bits on older fashions and 72 bits on newer ones. Fewer doable mixtures means an attacker with sufficient computing energy can guess the seed and unlock the pockets.
Hackers Race to Drain Weak Wallets
Attackers moved quick. Early tallies counted round 594 BTC, near $38 million on the time, drained from roughly 500 addresses. Later estimates put the full nearer to $70 million to $88 million as extra compromised wallets got here to gentle. As of Aug. 4, it’s estimated that the hackers have stolen an estimated 1,816 BTC, price about $116 million, from greater than 5,200 distinct wallets.
A firmware patch stops new wallets from inheriting the flaw, but it surely does nothing for seed phrases already generated underneath the damaged code. Anybody who arrange a Coldcard through the affected years has to maneuver their cash to a brand new pockets.
Transferring Funds Publicly Creates Its Personal Lure
For folks utilizing multi-signature setups, widespread amongst Coldcard customers who break up management of funds throughout a number of gadgets, the migration itself carries threat. Broadcasting a transaction publicly reveals the pockets’s keys and spending situations. An attacker already holding an identical weak non-public key can spot that transaction, construct a competing one with the next price, and use a Bitcoin community characteristic referred to as Exchange-by-Price (RBF) to leap the road and steal the funds earlier than the unique transaction confirms.
MARA’s Slipstream removes that window of publicity. As a result of the transaction by no means touches the general public mempool, an attacker by no means sees the keys or the spending particulars till MARA has already mined the cash right into a confirmed block.
Slipstream Predates the Disaster by Two Years
MARA first launched Slipstream on February 22, 2024, aiming to assist massive or uncommon transactions that many Bitcoin nodes decline to relay underneath normal coverage. CEO Fred Thiel framed it on the time as a technique to put MARA’s mining infrastructure to work for superior bitcoin customers whereas staying throughout the guidelines of the protocol. Entry had beforehand required a shopper code in periods of excessive demand or upkeep. That requirement is now gone.
Customers Nonetheless Carry the Belief and Timing Danger
Slipstream nonetheless is determined by MARA discovering blocks. A transaction sits in MARA’s non-public queue till the pool mines one, so timing relies upon solely on MARA’s share of Bitcoin’s complete hashrate.
On the time of publication, MARA’s pool instructions over 5% of the combination hashpower powering Bitcoin. MARA is telling customers to maintain charges aggressive however not extreme, since a transaction caught in its non-public queue throughout a price spike may sit for some time earlier than confirming.
What Comes Subsequent for Coldcard Holders
The broader bitcoin neighborhood is treating Slipstream’s public relaunch as a sensible device for a safety disaster, not a everlasting shift in how most transactions ought to transfer. For on a regular basis transfers, the general public mempool stays the usual route. However for Coldcard customers nonetheless holding cash on compromised seeds, safety researchers and pockets builders have been pointing to Slipstream as one of many extra dependable methods to maneuver funds with out tipping off attackers first.
Look ahead to up to date loss estimates as extra compromised addresses floor, extra steering from Coldcard on which firmware variations and serial ranges are affected, and whether or not different miners comply with MARA in providing an analogous non-public submission path.
AI Assault Freezes Boltz, Rattles Lightning Community Customers
Boltz, an organization that lets folks transfer bitcoin between the principle blockchain, the Lightning Community, and the Liquid sidechain, shut…
AI Assault Freezes Boltz, Rattles Lightning Community Customers
Boltz, an organization that lets folks transfer bitcoin between the principle blockchain, the Lightning Community, and the Liquid sidechain, shut…
AI Assault Freezes Boltz, Rattles Lightning Community Customers
Boltz, an organization that lets folks transfer bitcoin between the principle blockchain, the Lightning Community, and the Liquid sidechain, shut…













