MARA Holdings — a Nasdaq-listed Bitcoin mining and Artificial Intelligence (AI) infrastructure company, previously known as Marathon Digital — has created the Slipstream service, allowing users to send Bitcoin transactions directly into their mining pool instead of broadcasting them to the public network.
Most Bitcoin transactions pass through a communal "waiting room" called the mempool, where every network node can see the transaction before it is confirmed in a block. Slipstream bypasses this "waiting room." A user sends a signed transaction directly to MARA, and it remains hidden until MARA mines a block containing that transaction.
On August 3, 2026, the MARA Foundation posted an update on X:
"MARA Slipstream is now available as a public resource with no access restrictions and no client code required. Please be careful and conservative with fee selection, lest transactions get stuck in the Slipstream mempool if competitive rates spike sharply. We are not charging any additional fee for this service for the foreseeable future, but users are responsible for paying the appropriate Bitcoin network transaction fees."
This last point is crucial. MARA does not charge its own surcharge. Users still pay standard Bitcoin network fees; they simply send the transaction via a private channel instead of an open one.
Hardware Wallet Vulnerability Dictates Timing
The timing is not coincidental. In late July, researchers disclosed a serious flaw in Coldcard hardware wallets related to a bug in firmware code dating back to March 2021. Instead of using random numbers generated by the device's dedicated hardware generator, vulnerable Coldcard models would switch to a less secure software process when creating the wallet's 24-word seed phrase. This bug reduced the effective randomness from an expected 128 bits to approximately 40 bits on older models and 72 bits on newer ones. Fewer possible combinations mean an attacker with sufficient computing power could guess the seed phrase and unlock the wallet.
Hackers Rushed to Drain Vulnerable Wallets
Malicious actors acted swiftly. Initial estimates suggested around 594 $BTC was stolen from roughly 500 addresses, worth nearly $38 million at the time. Later estimates put the total closer to $70–88 million as more wallet breaches were uncovered. As of August 4, hackers were estimated to have stolen approximately 1,816 $BTC worth about $116 million from over 5,200 different wallets.
A firmware patch prevents the vulnerability in new wallets but does not help with seed phrases already generated from the flawed code. Anyone who set up a Coldcard during the affected period must move their coins to a new wallet.
Publicly Broadcasting Funds Creates Its Own Trap
For users employing multisignature configurations — common among Coldcard owners who split control of funds across multiple devices — the moving process itself carries risk. Publicly broadcasting a transaction reveals wallet keys and spending conditions. An attacker who already possesses the corresponding vulnerable private key could spot this transaction, create a competing transaction with a higher fee, and use the Bitcoin network's "Replace-by-Fee" (RBF) feature to jump the queue and steal the funds before the original transaction confirms.
MARA's Slipstream function eliminates this vulnerability window. Because the transaction never enters the public mempool, an attacker sees neither the keys nor the spending details until MARA mines the coins into a confirmed block.
Slipstream Arrived Two Years Before the Crisis
MARA first launched Slipstream on February 22, 2024, aiming to assist large or unusual transactions that many Bitcoin nodes refuse to relay under standard policy. CEO Fred Thiel characterized it at the time as a way to leverage MARA's mining infrastructure for the benefit of advanced Bitcoin users while remaining within the protocol's rules. Previously, a client code was required for access during high-demand periods or maintenance. That requirement has now been lifted.
Users Still Bear Trust and Timing Risk
Slipstream still relies on MARA finding blocks. The transaction sits in MARA's private queue until the pool mines a block, so timing is entirely dependent on MARA's share of Bitcoin's total hashrate.

At the time of publication, the MARA pool controls over 5% of the total hashing power securing Bitcoin. MARA recommends users set fees at a competitive but not excessive level, as a transaction stuck in the private queue during a fee spike could sit for some time before being confirmed.
What Lies Ahead for Coldcard Holders
The broader Bitcoin community views the re-launch of Slipstream in open mode as a practical tool for navigating the security crisis, not a permanent change in how most transactions should occur. For everyday transfers, the open mempool remains the standard channel. However, for Coldcard users still storing coins on compromised seeds, security researchers and wallet developers point to Slipstream as one of the most reliable ways to move funds without tipping off attackers in advance.
Watch for updated loss estimates as new compromised addresses emerge, further guidance from Coldcard on which firmware versions and serial number ranges are affected, and whether other miners will follow MARA's lead and offer a similar private transaction submission channel.
end-content






