Dispatches
9K Bitcoin rescued out of Coldcard multisigs
A deep dive on how collaborative custody firm Unchained rescued client funds using MARA Slipstream, with cofounder Dhruv Bansal.
The Coldcard Exploit
On July 30, an attacker swept roughly 594 BTC from about 500 vulnerable Bitcoin hardware wallets in 46 minutes. The attack shook the self-custodial Bitcoin community, raising concerns about firmware vulnerabilities and the use of AI to exploit weaknesses in Bitcoin infrastructure code.
▶ INTERVIEW
A deep dive on how collaborative custodyfirm, Unchained, rescued client funds using MARA Slipstream, withcofounder Dhruv Bansal.
What happened
The cause was a firmware flaw. Coldcard firmware dating as far back as March 2021 generated wallet seeds with a faulty random number generator, leaving Bitcoin private keys created by these devices vulnerable to discovery.
On July 30, an attacker exploited this vulnerability to drain roughly 594 BTC from about 500 single-signature wallets. Coinkite, Coldcard's maker, says it did not know of the bug until that day. Estimates of the total affected have since climbed above 1,720 BTC across some 8,092 addresses, according to Galaxy Research, while attacks remain ongoing.

Why multisig owners faced a different problem
While single-signature wallets generated with faulty firmware had little protection, Coldcard Multisig users with at least one key generated by a non-Coldcard vendor were protected up to a point.
For instance, if you were a client of a concierge 2-of-3 multisig service (e.g. Unchained) and protected your wallet with Coldcard devices, your funds were likely safe unless or until you tried to spend those funds — at which point, enough information would be revealed about your wallet in Bitcoin's mempool to execute an effective attack.
Exposure of funds to the public mempool became the key vulnerability for Coldcard multisig wallets — one that could only be solved by a miner with enough hashpower to operate a private mempool.
Enter Slipstream
In the hours after the exploit, MARA saw an unusual increase in requests to use Slipstream — its private mempool service — enabling direct submission of Bitcoin transactions to MARA for confirmation without exposure to the public mempool.
Because Slipstream transactions are confirmed before information about these transactions is made available to the public, attack surface for vulnerable multisig wallets is substantively reduced.
Since the attacks started on July 30th, over 9,000 Bitcoin have moved out of vulnerable multisig wallets using Slipstream — or roughly $570M of primarily retail users' funds.

A partner in Unchained
The MARA Foundation is particularly grateful to the team at Unchained for enabling the largest piece of this rescue mission. Unchained spun up a wallet integration tool for its Coldcard multisig users — enabling direct submission to MARA's Slipstream private mempool service on the backend — within 24 hours of the first Coldcard attack.
Since then, the majority of multisig users executing recovery transactions through Slipstream have used this important tool.
Going forward
MARA Foundation will keep supporting Bitcoiners and the wider ecosystem where it can, and will share updates as the situation develops.
We have made access to Slipstream available as a public good for the foreseeable future, and will support integrations with wallet software companies wherever we are able.
Read more
Get insights from Bitcoin leaders on governance, mining, security and tech.














