Powered by
Mining

MARA Opens Slipstream to the Public as Coldcard Victims Race to Escape

MARA Foundation says its Slipstream service is now open to anyone, with no signup code required, at the same moment thousands of bitcoin holders are racing to move funds off a flawed hardware wallet.

WRITTEN BY
SHARE
MARA Opens Slipstream to the Public as Coldcard Victims Race to Escape

Key Takeaways

  • MARA Foundation opened Slipstream to the public on August 3, 2026, dropping its client code requirement.
  • A Coldcard firmware flaw from March 2021 let hackers drain up to $88 million from about 500 wallets.
  • Watch for updated Coldcard firmware guidance and further loss estimates as more addresses are checked.

MARA Strips Away the Access Codes

MARA Holdings, the Nasdaq-listed bitcoin miner and artificial intelligence (AI) infrastructure provider, formerly known as Marathon Digital, built the Slipstream service so people can send bitcoin transactions straight to its mining pool instead of broadcasting them to the public network.

Most bitcoin transactions travel through a shared waiting room called the mempool, where every node on the network can see a transaction before it gets confirmed into a block. Slipstream skips that waiting room. A user submits a signed transaction directly to MARA, and it stays hidden until MARA mines a block with it inside.

On August 3, 2026, MARA Foundation posted the update on X:

“MARA Slipstream is now available as a permissionless public good with no client code requirement. Please be careful and conservative with fees to avoid transactions getting stuck in the Slipstream mempool in the event that competitive rates spike. For the foreseeable future, we are not charging additional fees for this service, but users are responsible for paying appropriate Bitcoin transaction fees.”

That last point matters. MARA is not adding its own surcharge. Users still pay normal Bitcoin network fees, they just send the transaction through a private channel instead of the open one.

A Hardware Wallet Flaw Forces the Timing

The timing is not a coincidence. At the end of July, researchers disclosed a serious flaw in Coldcard hardware wallets, tracing back to a firmware coding error from March 2021. Instead of pulling randomness from the device’s dedicated hardware generator, affected Coldcard models fell back to a weaker software process when creating a wallet’s 24-word seed phrase. That mistake cut the effective randomness from an expected 128 bits down to roughly 40 bits on older models and 72 bits on newer ones. Fewer possible combinations means an attacker with enough computing power can guess the seed and unlock the wallet.

Hackers Race to Drain Weak Wallets

Attackers moved fast. Early tallies counted around 594 BTC, close to $38 million at the time, drained from roughly 500 addresses. Later estimates put the total closer to $70 million to $88 million as more compromised wallets came to light. As of Aug. 4, it is estimated that the hackers have stolen an estimated 1,816 BTC, worth about $116 million, from more than 5,200 distinct wallets.

A firmware patch stops new wallets from inheriting the flaw, but it does nothing for seed phrases already generated under the broken code. Anyone who set up a Coldcard during the affected years has to move their coins to a new wallet.

Moving Funds Publicly Creates Its Own Trap

For people using multi-signature setups, common among Coldcard users who split control of funds across several devices, the migration itself carries risk. Broadcasting a transaction publicly reveals the wallet’s keys and spending conditions. An attacker already holding a matching weak private key can spot that transaction, build a competing one with a higher fee, and use a Bitcoin network feature called Replace-by-Fee (RBF) to jump the line and steal the funds before the original transaction confirms.

MARA’s Slipstream removes that window of exposure. Because the transaction never touches the public mempool, an attacker never sees the keys or the spending details until MARA has already mined the coins into a confirmed block.

Slipstream Predates the Crisis by Two Years

MARA first launched Slipstream on February 22, 2024, aiming to help large or unusual transactions that many Bitcoin nodes decline to relay under standard policy. CEO Fred Thiel framed it at the time as a way to put MARA’s mining infrastructure to work for advanced bitcoin users while staying within the rules of the protocol. Access had previously required a client code during periods of high demand or maintenance. That requirement is now gone.

Users Still Carry the Trust and Timing Risk

Slipstream still depends on MARA finding blocks. A transaction sits in MARA’s private queue until the pool mines one, so timing depends entirely on MARA’s share of Bitcoin’s total hashrate.

Mining pool distribution on Aug. 4, 2026, via mempool.space. As of today, MARA commands 5.37%.

At the time of publication, MARA’s pool commands over 5% of the aggregate hashpower powering Bitcoin. MARA is telling users to keep fees competitive but not excessive, since a transaction stuck in its private queue during a fee spike could sit for a while before confirming.

What Comes Next for Coldcard Holders

The broader bitcoin community is treating Slipstream’s public relaunch as a practical tool for a security crisis, not a permanent shift in how most transactions should move. For everyday transfers, the public mempool remains the standard route. But for Coldcard users still holding coins on compromised seeds, security researchers and wallet developers have been pointing to Slipstream as one of the more reliable ways to move funds without tipping off attackers first.

Watch for updated loss estimates as more compromised addresses surface, additional guidance from Coldcard on which firmware versions and serial ranges are affected, and whether other miners follow MARA in offering a similar private submission path.