MARA Opens Slipstream as Coldcard Victims Scramble to Escape Hackers
A critical flaw in Coldcard hardware wallets has led to thousands of bitcoin holders rushing to move their funds. The vulnerability, which affects about 500 wallets, allows hackers to drain up to $88 million from compromised addresses.
The MARA Foundation has opened its Slipstream service to the public, allowing users to send transactions directly to MARA's mining pool without broadcasting them on the public network. This private submission path removes the risk of an attacker spotting a transaction and stealing funds using Replace-by-Fee (RBF).
Coldcard firmware patching can prevent new wallets from inheriting the flaw, but it does not fix existing seed phrases generated under the broken code. Users with compromised seeds must move their coins to a new wallet.