MARA Opens Slipstream to the Public as Coldcard Victims Race to Escape
MARA Holdings has opened its Slipstream service to the public without a signup code, effective August 3, 2026. Slipstream allows users to submit signed Bitcoin transactions directly to MARA’s mining pool, bypassing the public mempool where transactions are visible to all network nodes. This keeps transaction details hidden until MARA mines a block containing them.
The move comes as thousands of Coldcard hardware wallet users race to move funds after a critical firmware flaw was disclosed in late July. The vulnerability, stemming from a coding error introduced in March 2021, caused the device to use a weaker software-based random number generator instead of its dedicated hardware generator when creating 24-word seed phrases. This reduced effective randomness from 128 bits to as low as 40 bits on older models and 72 bits on newer ones, making seeds prone to brute-force attacks. Hackers have exploited the flaw, stealing an estimated 1,816 BTC (about $116 million) from more than 5,200 wallets as of August 4.
A firmware patch prevents the flaw in new wallets, but existing seed phrases remain vulnerable. Moving funds from compromised wallets requires broadcasting a new transaction to the network, but attackers can use Replace-by-Fee (RBF) to intercept the transaction if it passes through the public mempool. Slipstream eliminates this risk by keeping the transaction private until confirmed.
MARA first launched Slipstream in February 2024 for large or nonstandard transactions. Now open to all, the service carries no additional fees—users only pay standard Bitcoin transaction fees. However, transactions depend on MARA’s mining success; the pool currently controls over 5% of Bitcoin’s total hashrate. MARA advises users to set competitive fees to avoid delays.
While Slipstream offers a practical solution for the current crisis, security experts emphasize that the public mempool remains the standard for everyday transfers. The broader community awaits updated guidance from Coldcard on affected firmware versions and serial numbers, as well as potential loss estimates as more compromised addresses are identified.