Coldcard Vulnerability Triggers Largest BTC Exodus Since FTX, MARA Opens Slipstream

2 hour ago 2 sources negative

Key takeaways:

  • Coldcard's breach could accelerate a shift from self-custody to regulated custody solutions.
  • MARA's Slipstream service underscores miners' growing influence over Bitcoin transaction ordering.
  • Spike in BTC exchange inflows after the exploit signals potential near-term selling pressure.

In early August 2026, the Bitcoin ecosystem was rattled by a security flaw in Coldcard hardware wallets that led to the theft of approximately 1,367 BTC (worth around $88.6 million) across 4,585 addresses, according to on-chain data from Galaxy Research and CryptoQuant. The vulnerability, which affected Coldcard Mk3 devices running firmware versions released between March 2021 and mid-2026, stemmed from insufficient entropy in the random number generator used for recovery seed phrases, allowing attackers to reconstruct private keys offline.

The breach was executed in a 41-minute window on July 30, 2026, when an attacker drained 1,082.65 BTC from 1,196 addresses in a single burst. Subsequent investigations revealed additional compromised addresses, raising the total. As the incident unfolded, thousands of Bitcoin holders rushed to migrate funds, pushing sub-1 BTC transfers to 39,600 BTC in a single day—the highest level since November 16, 2022, when 39,900 BTC moved amid the FTX collapse. Unlike that earlier exodus, this time many users moved coins away from self-custody toward exchanges or freshly generated wallets.

Amid the chaos, mining company MARA Holdings enabled public, permissionless access to its Slipstream service, providing a direct transaction submission channel to MARA’s mining infrastructure. This allowed users to bypass the public mempool, reducing exposure to Replace-By-Fee (RBF) attacks that could intercept vulnerable transactions. Custody integrators like Unchained also incorporated the Slipstream API, aiding clients with multisig setups that had keys generated on affected Coldcard devices. MARA emphasized conservative fee usage to prevent delays, while Coinkite (Coldcard’s manufacturer) released a patched firmware version on July 31, 2026. The incident reignited the debate over self-custody versus regulated services, with CryptoQuant’s research head Julio Moreno praising the rapid user response as proactive.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.