Dispatches

9K Bitcoin rescued out of Coldcard multisigs

A deep dive on how collaborative custody firm Unchained rescued client funds using MARA Slipstream, with cofounder Dhruv Bansal.

The Coldcard Exploit

On July 30, an attacker swept roughly 594 BTC from about 500 vulnerable Bitcoin hardware wallets in 46 minutes. The attack shook the self-custodial Bitcoin community, raising concerns about firmware vulnerabilities and the use of AI to exploit weaknesses in Bitcoin infrastructure code.

▶ INTERVIEW
A deep dive on how collaborative custodyfirm, Unchained, rescued client funds using MARA Slipstream, withcofounder Dhruv Bansal.

What happened

The cause was a firmware flaw. Coldcard firmware dating as far back as March 2021 generated wallet seeds with a faulty random number generator, leaving Bitcoin private keys created by these devices vulnerable to discovery.

On July 30, an attacker exploited this vulnerability to drain roughly 594 BTC from about 500 single-signature wallets. Coinkite, Coldcard's maker, says it did not know of the bug until that day. Estimates of the total affected have since climbed above 1,720 BTC across some 8,092 addresses, according to Galaxy Research, while attacks remain ongoing.

Galaxy Research flow of funds diagram mapping drained Bitcoin addresses and current wallet holdings.
Galaxy Research flow of funds diagram mapping drained Bitcoin addresses and current wallet holdings.

Why multisig owners faced a different problem

While single-signature wallets generated with faulty firmware had little protection, Coldcard Multisig users with at least one key generated by a non-Coldcard vendor were protected up to a point.

For instance, if you were a client of a concierge 2-of-3 multisig service (e.g. Unchained) and protected your wallet with Coldcard devices, your funds were likely safe unless or until you tried to spend those funds — at which point, enough information would be revealed about your wallet in Bitcoin's mempool to execute an effective attack.

Exposure of funds to the public mempool became the key vulnerability for Coldcard multisig wallets — one that could only be solved by a miner with enough hashpower to operate a private mempool.

Enter Slipstream

In the hours after the exploit, MARA saw an unusual increase in requests to use Slipstream — its private mempool service — enabling direct submission of Bitcoin transactions to MARA for confirmation without exposure to the public mempool.

Because Slipstream transactions are confirmed before information about these transactions is made available to the public, attack surface for vulnerable multisig wallets is substantively reduced.

Since the attacks started on July 30th, over 9,000 Bitcoin have moved out of vulnerable multisig wallets using Slipstream — or roughly $570M of primarily retail users' funds.

Mempool Research chart showing cumulative multisig Bitcoin spends broadcast with Slipstream over block height.
Mempool Research chart showing cumulative multisig Bitcoin spends broadcast with Slipstream over block height.

A partner in Unchained

The MARA Foundation is particularly grateful to the team at Unchained for enabling the largest piece of this rescue mission. Unchained spun up a wallet integration tool for its Coldcard multisig users — enabling direct submission to MARA's Slipstream private mempool service on the backend — within 24 hours of the first Coldcard attack.

Since then, the majority of multisig users executing recovery transactions through Slipstream have used this important tool.

Going forward

MARA Foundation will keep supporting Bitcoiners and the wider ecosystem where it can, and will share updates as the situation develops.

We have made access to Slipstream available as a public good for the foreseeable future, and will support integrations with wallet software companies wherever we are able.

Read more

Abstract halftone graphic showing a wireframe sphere with XYZ coordinate axes on a gold background.Abstract halftone graphic showing a wireframe sphere with XYZ coordinate axes on a gold background.
Dispatches

1st Quantum-Resistant Bitcoin Transaction Mined by MARA Slipstream

The transaction was published by StarkWare GM Avihu Levy and mined by MARA through its private mempool service, Slipstream.

This is some text inside of a div block.
MARA Foundation launch at Bitcoin 2026MARA Foundation launch at Bitcoin 2026
The Talk of the Town

MARA at Bitcoin 2026: Introducing the MARA Foundation

A foundation, a community vote, and a power plant: one operating posture, on display at Bitcoin 2026.

This is some text inside of a div block.

Get insights from Bitcoin leaders on governance, mining, security and tech.