MEMPOL!TICS
← BACK TO THE BOARD
TechnologistSAT AUG 1 · 12:40 PM ET

THIS IS THE REBUILD — ROUGHNECKS DISABLES RBF TO PROTECT COLDCARD RESCUE TRANSACTIONS. LUKE DASHJR AMPLIFIES. THE MINING LAYER DEFENDS THE OPERATOR CLASS.

"Per the advice below, we have disabled RBF on our node to ensure that we do not assist thieves leveraging RBF to steal from people trying to rescue funds from multisig addresses generated by coldcards. We call on @FoundryServices, @AntPoolofficial, @f2pool, @SpiderPool_com..."
— @Roughnecks110
"This is how responsible miners should act."
— Luke Dashjr, @LukeDashjr
Here is the exploit chain Roughnecks is closing. A ColdCard user whose seed was generated on affected firmware learns their address is compromised. They construct a rescue transaction to sweep their remaining funds to a new, safe wallet. The attacker — who already has the compromised private key from the seed-derivation flaw — watches the mempool for that rescue transaction. When the rescue transaction appears unconfirmed, the attacker broadcasts their own transaction with a higher fee, using RBF policy to replace the victim’s rescue with a theft. Miners running RBF confirm the highest-fee transaction. The victim’s rescue is displaced. The attacker wins.
Roughnecks broke that chain. By disabling RBF on their node, they will only relay and mine the first transaction they see — the legitimate owner’s rescue transaction. Any attacker attempt to replace it via a higher fee is refused. This is not a protocol change. It is a mining policy choice. Roughnecks is asking Foundry, AntPool, F2Pool, and SpiderPool — the four pools that control roughly 70%+ of Bitcoin’s hash rate — to make the same policy choice. If they do, the front-running exploit largely stops working across the network.
The network works as designed.
The mining layer is voluntarily defending the operator class against a product-layer failure the network didn’t cause.
Luke Dashjr’s endorsement matters because Luke is the longest-tenured active protocol voice in Bitcoin who consistently articulates the case for minimum-scope, conservatism-first mining policy. When Luke says "this is how responsible miners should act," he is drawing a distinction between miners who optimize purely for fee revenue and miners who understand that the value of what they secure depends on the operator class trusting that the network defends its holders when a product edge breaks. Roughnecks made that distinction concrete. It costs them some marginal fee revenue. It gains them the exact reputation the mining industry needs right now: the pool that chose the operator class over the mempool front-run.
This is the rebuild story. Two days ago, 500 wallets got drained by a five-year seed-generation flaw at the wallet-product layer. Today the biggest amplifier for defensive coordination is a mining pool with a modest name and a legend in Bitcoin protocol history endorsing them. Every voice at every layer of the sovereignty class is doing exactly what a mature ecosystem should do — publish the mechanism, share the migration path, and coordinate defensive action inside the rules of the network. Yazbeck named the doctrine. Brunell amplified the urgency. Block engineering traced the attacker. Clay Garrett published the trail. Coinkite shipped the firmware fix. And now the mining pools are being asked, publicly, on the record, to protect the operator class through mempool policy.
The wallet product failed.
The network is showing up for the operator class.
READ LUKE DASHJR'S ENDORSEMENT →
@LukeDashjr X quoting @Roughnecks110 · sat aug 1 · mining coordination on RBF policy
MORE ON THE REBUILD
THE NETWORK DIDN'T FAIL. THE PRODUCTS AROUND IT DID. — A PERSONAL NOTE ON WHAT MEMPOLITICS COVERS FROM HERE.
500 WALLETS DRAINED IN FOUR BLOCKS — COLDCARD SEEDS WERE ARITHMETIC.
SECOND COLDCARD WAVE — GALAXY RESEARCH: 1,158 BTC / 2,673 ADDRESSES CUMULATIVE.
BLOCK ENGINEERING TRACES COLDCARD ATTACKER TO PAID BLOCKCHAIN-SERVICES ACCOUNT.
PROTECT YOUR SOVEREIGNTY — COLDCARD MIGRATION GUIDE.