Ctrl Wallet — Security Exploit and Forced Shutdown
Summary
Ctrl Wallet, a multi-chain self-custodial wallet formerly known as XDEFI Wallet and supporting over 2,500 blockchain networks with approximately 650,000 monthly active users, permanently ceased operations on August 3, 2026 following an unrecovered June 2026 cryptographic exploit. The exploit targeted the Cardano integration layer operated by SecondFi (formerly Yoroi Wallet), a platform under the same EMURGO parent, draining approximately 16.1 million ADA (roughly $2.4–$2.6 million USD) from 374 wallet addresses via a signing flaw that allowed private key material to be reconstructed from public blockchain data. Users who did not export recovery phrases before the August 3 deadline may face permanent loss of access to remaining funds.
Connected Entities
1 entities- + 3 more
Timeline(13 events)
2024-07-17
XDEFI Wallet publicly rebrands to Ctrl Wallet, announcing enhanced multichain features and new user onboarding focus.
Crypto Daily2024-10-17
Ctrl Wallet initiates $XDEFI to $CTRL token migration at a 1:1 ratio, with the $XDEFI token scheduled to deprecate September 25, 2025.
The Defiant2026-04-29
EMURGO, commercial arm of Cardano, acquires Ctrl Wallet's technology infrastructure. The $CTRL token is explicitly excluded from the deal. EMURGO simultaneously rebrands Yoroi Wallet to SecondFi.
CoinTrust2026-06-21
First wave of coordinated attacks begins against SecondFi Cardano wallets, exploiting a cryptographic signing flaw to reconstruct private keys from public transaction data.
SecondFi Knowledge Base (official)2026-06-22
SecondFi detects the breach and activates emergency response protocols. Platform placed in maintenance mode.
SecondFi Knowledge Base (official)2026-06-23
Ctrl Wallet publicly discloses a security vulnerability affecting Cardano-linked wallets. Additional attack waves continue. Total theft reaches approximately 16.1 million ADA across 374 addresses.
Crypto.News2026-06-24
CoinDesk reports the exploit publicly. SecondFi team states approximately 129 million ADA has been secured via emergency containment and transferred to an independent third-party custodian. SlowMist estimates total exposure could have exceeded $20 million.
CoinDesk2026-06-25
Root cause of the cryptographic signing flaw identified and patched in the developer codebase. Final balance snapshot captured on June 26.
SecondFi Knowledge Base (official)2026-07-09
Ctrl Wallet announces permanent shutdown effective August 3, 2026. New downloads halted immediately. App removal from stores begins.
CoinTelegraph2026-07-22
SecondFi publicly details the cryptographic flaw. Groom Lake's forensic report cites two distinct attackers; Attacker A flagged with possible DPRK/Lazarus Group indicators. SecondFi and Yoroi Wallet announce permanent shutdown.
CoinDesk2026-07-27
SecondFi and EMURGO publish compensation plan developed alongside Input Output Group and the Cardano Foundation, centered on a zero-knowledge proof recovery portal.
Cryptonomist2026-08-03
Ctrl Wallet permanently ceases operations. All transfer, swap, and dApp functions disabled. Recovery phrase export functionality retained temporarily. App fully removed from Apple App Store, Google Play, and browser extension stores.
Crypto.NewsDecision Log
- #1publish⛓ pending8/4/2026, 11:23:44 PMhash: UJ4UHXqWCrXoL2uRPdsmD1jp29peNtUZ49prfQgjYp5
22 of 24 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/4/2026, 11:23:31 PM
last updated: 8/5/2026, 10:00:50 AM
avoid.net — verified advice for a post-truth world