If you're just now moving funds away from a compromised Coldcard, consider using Slipstream to submit your transactions.
When you spend from a multisig wallet, the transaction exposes all public keys and spending rules to anyone watching the mempool. If an attacker has already done the legwork of weak Coldcard keys from the entropy exploit, they can instantly spot a match.
If they hold enough of those keys, they race you, broadcasting a higher-fee transaction to steal the funds before yours confirms.
Slipstream from MARA fixes this by submitting your transaction privately to the miner. The attacker never sees the keys or the spend until the coins are already moved.
slipstream.mara.com
Login to reply
Replies (10)
i think you should stfu ๐ฆฒ๐ฆ
vibecoder security expert
I had someone racing me on a 2M sat utxo. CPFP FTW. ๏ฟผ
Or just tell miners to turn off RBF?
But getting "everyone im bitcoin to do the same thing" is not gonna happen. Amd that is the point.
I love you
So adversary would need at least the 3 of 5 seeds still, yes?
Yes.
Yes. @average_gary sent me 6.15 bitcoin to advertise this fund savings feature.