A Crypto Wallet Shuts Down for Good After $2.4M Cardano Hack

Ctrl Wallet, one of the more established names in multichain crypto storage, is closing its doors entirely — and giving users a hard deadline of August 3, 2026, to move their funds out before the app stops working.

The trouble started small. On June 23, Ctrl Wallet flagged a security issue affecting a subset of its Cardano wallets and pushed the app into maintenance mode while engineers looked for a fix. That fix never really materialized. A day later, things got worse in a different but connected part of the business: SecondFi, a sister platform Ctrl Wallet's multichain technology had recently been folded into, got hit by its own exploit. Attackers drained roughly 16 million ADA — about $2.4 million at the time — after finding a flaw in how the wallet generated transaction signatures, a bug that could let someone work backward and reconstruct a user's private key.

Rather than patch things up and reopen, Ctrl Wallet's team decided to just end the product. Starting August 3, sending, receiving, swapping, and connecting to apps will all stop working. The only thing users will still be able to do is export their recovery phrase — the one piece of information that lets someone move their holdings into a different wallet entirely. The app has already been pulled from app stores and browser extension marketplaces, so no new users can even download it anymore, though anyone who already has it installed can keep using it normally until the deadline.

Ctrl Wallet was a fairly big deal before this — under its former name, XDEFI Wallet, it supported more than 2,500 blockchain networks and had over 650,000 monthly users, according to its own numbers. It came under the ownership of Emurgo, Cardano's commercial arm, back in April, at which point its underlying multichain technology was set to continue living on inside SecondFi. That plan didn't survive the month.

There's a stranger detail buried in the SecondFi side of this story. Alongside the roughly $2.4 million stolen by attackers, someone else moved a much larger amount — about 129 million ADA, worth around $18.5 million — into a separate, secured location, and Emurgo has described this as a protective move by what it's calling a "white hat" actor rather than a theft. Exactly who that person is remains unclear; Cardano founder Charles Hoskinson has publicly said Emurgo doesn't actually know who they are. Emurgo has since said SecondFi won't return to normal operations at all, even once a full audit is finished — the only work continuing on that platform now is a dedicated team focused purely on returning funds to the roughly 374 wallet addresses affected.

Ctrl Wallet has been explicit on one point: there's no token migration, no airdrop, and no compensation program tied to the shutdown. Any offer claiming otherwise — especially anything circulating on social media promising a bonus token or a refund — should be treated as a scam. For anyone still holding funds in the wallet, the advice is simple and time-sensitive: export your recovery phrase or move your assets to another wallet or exchange well before August 3, because after that, recovery phrase export is the only door still open.