If you're just now moving funds away from a compromised Coldcard, consider using Slipstream to submit your transactions. When you spend from a multisig wallet, the transaction exposes all public keys and spending rules to anyone watching the mempool. If an attacker has already done the legwork of weak Coldcard keys from the entropy exploit, they can instantly spot a match. If they hold enough of those keys, they race you, broadcasting a higher-fee transaction to steal the funds before yours confirms. Slipstream from MARA fixes this by submitting your transaction privately to the miner. The attacker never sees the keys or the spend until the coins are already moved. slipstream.mara.com

Replies (10)

โ†‘