Ctrl Wallet Shuts Down After Security Exploit, Users Told to Withdraw

Ctrl Wallet is shutting down. The non-custodial multichain crypto wallet told users Tuesday to pull their assets out within the next month. This comes weeks after a security exploit hit the platform.

On June 23, Ctrl Wallet flagged a security issue affecting some Cardano wallets. It went into maintenance mode to protect funds while engineers worked on a fix. Fast forward to today: the team announced that starting August 3, 2026, sending, receiving, and swapping funds will be disabled. The only thing that’ll still work is exporting your recovery phrase.

The app is getting pulled from app stores and browser extension stores immediately. After the August 3 cutoff, users can still import their recovery phrase into compatible wallets like MetaMask, Trust Wallet, or Phantom. The team’s strongly recommending people move their assets before then.

Don’t expect any migration tokens or airdrops. Ctrl Wallet explicitly said there won’t be any. They’re also warning people to watch out for fake social media posts promising otherwise.

Ctrl Wallet — formerly known as XDEFI Wallet — had between 11 and 50 employees and over 650,000 monthly users. It supported more than 2,500 blockchain networks, including Cardano and Midnight.

The shutdown follows a messy chain of events. In April, Ctrl Wallet moved under the Emurgo umbrella, with plans to continue inside the SecondFi wallet. Then on June 24, a vulnerability in SecondFi let attackers drain about 16 million ADA — roughly $2.4 million at the time. SecondFi later laid out a recovery plan to repay affected users across 374 wallet addresses and secured about 129 million ADA through emergency measures.

It’s been a rough few months for this corner of the crypto wallet space.