MARA Strips Away the Entry Codes
MARA Holdings, the Nasdaq-listed bitcoin miner and synthetic intelligence (AI) infrastructure supplier, previously often known as Marathon Digital, constructed the Slipstream service so folks can ship bitcoin transactions straight to its mining pool as an alternative of broadcasting them to the general public community.
Most bitcoin transactions journey by means of a shared ready room referred to as the mempool, the place each node on the community can see a transaction earlier than it will get confirmed right into a block. Slipstream skips that ready room. A person submits a signed transaction on to MARA, and it stays hidden till MARA mines a block with it inside.
On August 3, 2026, MARA Basis posted the replace on X:
“MARA Slipstream is now obtainable as a permissionless public good with no shopper code requirement. Please watch out and conservative with charges to keep away from transactions getting caught within the Slipstream mempool within the occasion that aggressive charges spike. For the foreseeable future, we aren’t charging further charges for this service, however customers are liable for paying applicable Bitcoin transaction charges.”
That final level issues. MARA will not be including its personal surcharge. Customers nonetheless pay regular Bitcoin community charges, they simply ship the transaction by means of a personal channel as an alternative of the open one.
A {Hardware} Pockets Flaw Forces the Timing
The timing will not be a coincidence. On the finish of July, researchers disclosed a critical flaw in Coldcard {hardware} wallets, tracing again to a firmware coding error from March 2021. As an alternative of pulling randomness from the machine’s devoted {hardware} generator, affected Coldcard fashions fell again to a weaker software program course of when making a pockets’s 24-word seed phrase. That mistake reduce the efficient randomness from an anticipated 128 bits right down to roughly 40 bits on older fashions and 72 bits on newer ones. Fewer potential mixtures means an attacker with sufficient computing energy can guess the seed and unlock the pockets.
Hackers Race to Drain Weak Wallets
Attackers moved quick. Early tallies counted round 594 $BTC, near $38 million on the time, drained from roughly 500 addresses. Later estimates put the full nearer to $70 million to $88 million as extra compromised wallets got here to gentle. As of Aug. 4, it’s estimated that the hackers have stolen an estimated 1,816 $BTC, price about $116 million, from greater than 5,200 distinct wallets.
A firmware patch stops new wallets from inheriting the flaw, nevertheless it does nothing for seed phrases already generated underneath the damaged code. Anybody who arrange a Coldcard in the course of the affected years has to maneuver their cash to a brand new pockets.
Shifting Funds Publicly Creates Its Personal Lure
For folks utilizing multi-signature setups, frequent amongst Coldcard customers who cut up management of funds throughout a number of units, the migration itself carries danger. Broadcasting a transaction publicly reveals the pockets’s keys and spending circumstances. An attacker already holding an identical weak personal key can spot that transaction, construct a competing one with the next charge, and use a Bitcoin community characteristic referred to as Change-by-Charge (RBF) to leap the road and steal the funds earlier than the unique transaction confirms.
MARA’s Slipstream removes that window of publicity. As a result of the transaction by no means touches the general public mempool, an attacker by no means sees the keys or the spending particulars till MARA has already mined the cash right into a confirmed block.
Slipstream Predates the Disaster by Two Years
MARA first launched Slipstream on February 22, 2024, aiming to assist massive or uncommon transactions that many Bitcoin nodes decline to relay underneath normal coverage. CEO Fred Thiel framed it on the time as a strategy to put MARA’s mining infrastructure to work for superior bitcoin customers whereas staying inside the guidelines of the protocol. Entry had beforehand required a shopper code in periods of excessive demand or upkeep. That requirement is now gone.
Customers Nonetheless Carry the Belief and Timing Threat
Slipstream nonetheless is dependent upon MARA discovering blocks. A transaction sits in MARA’s personal queue till the pool mines one, so timing relies upon fully on MARA’s share of Bitcoin’s whole hashrate.

On the time of publication, MARA’s pool instructions over 5% of the combination hashpower powering Bitcoin. MARA is telling customers to maintain charges aggressive however not extreme, since a transaction caught in its personal queue throughout a charge spike may sit for some time earlier than confirming.
What Comes Subsequent for Coldcard Holders
The broader bitcoin group is treating Slipstream’s public relaunch as a sensible device for a safety disaster, not a everlasting shift in how most transactions ought to transfer. For on a regular basis transfers, the general public mempool stays the usual route. However for Coldcard customers nonetheless holding cash on compromised seeds, safety researchers and pockets builders have been pointing to Slipstream as one of many extra dependable methods to maneuver funds with out tipping off attackers first.
Look ahead to up to date loss estimates as extra compromised addresses floor, further steering from Coldcard on which firmware variations and serial ranges are affected, and whether or not different miners comply with MARA in providing the same personal submission path.

