Grafa
Ctrl Wallet to shut after security exploit
Image for illustrative purposes only. Not a real photo.

Ctrl Wallet to shut after security exploit

Share
  • Ctrl Wallet will cease operations on Aug. 3, 2026, following a security exploit affecting some Cardano wallets.
  • Users have been urged to withdraw their cryptocurrency before wallet functions are permanently disabled.
  • The closure follows the wallet's transition under Emurgo and a separate exploit involving the SecondFi platform.

Ctrl Wallet announced it will shut down on Aug. 3, 2026, after a June 23 security exploit affecting some Cardano (CRYPTO:ADA) wallets, urging users to withdraw their digital assets before services are discontinued.

The non-custodial wallet entered maintenance mode after reporting the exploit on June 23, and said sending, receiving, swapping and other wallet functions will be disabled from Aug. 3, leaving only recovery phrase exports available.

Ctrl Wallet said its application will be removed from app stores immediately, advised users to export their 12-word or 24-word recovery phrases to compatible wallets such as MetaMask, Trust Wallet or Phantom, and warned there will be no migration token or airdrop.

Users have until Aug. 3 to move their assets to another wallet or exchange, and no market reaction accompanied the announcement because Ctrl Wallet is privately owned.

Ctrl Wallet announced in April that its multichain technology would continue under Emurgo through the SecondFi wallet after transitioning from the XDEFI Wallet brand.

A vulnerability in SecondFi resulted in the loss of about 16 million ADA, worth approximately US$2.4 million at the time, before the platform said it secured roughly 129 million ADA to support the recovery process for affected users.

At the time of reporting, Cardano price was $0.1758.

Frequently asked questions

Grafa is not a financial advisor. You should seek independent, legal, financial, taxation or other advice that relate to your unique circumstances.

Grafa is not liable for any loss caused, whether due to negligence or otherwise arising from the use of or reliance on the information provided directly or indirectly, by use of this platform.