
Ctrl Wallet has announced the permanent shutdown of its services after a recent security exploit, giving users until August 3 to move their crypto assets before core wallet functions go offline. According to the company's blog post published on July 7, Ctrl Wallet pulled the app from major app stores the same day and will disable sending, receiving, swapping and all other wallet functions from August 3. The company has confirmed it will immediately stop new downloads and remove the application from browser extension and mobile app stores as part of the shutdown process. However, the platform has clarified that users who have already installed the app can continue normal use until August 2, including sending, receiving, and swapping tokens, as well as exporting their recovery phrase. The move follows a recent exploit affecting some Cardano wallets, with the company placing parts of its platform into temporary maintenance mode on June 23 while engineers investigated the issue and worked to protect user assets. As per multiple reports, the exploit specifically targeted a subset of Cardano wallets within the Ctrl ecosystem, prompting the decisive decision to wind down the entire operation rather than attempt to patch the vulnerability.
Ahead of the shutdown deadline, Ctrl Wallet has strongly advised customers to move their funds to another wallet or exchange instead of waiting until services are disabled. Users who do not transfer assets before August 3 will still be able to access their funds by importing their 12-word or 24-word recovery phrase into another compatible wallet. The company has identified MetaMask, Trust Wallet and Phantom as compatible alternatives for importing recovery phrases, stressing that users should securely back up their seed phrases before attempting any migration. Ctrl Wallet has emphasized that "We strongly recommend exporting your recovery phrase as soon as possible, as we cannot guarantee how long the app will remain accessible on your device." The company has also warned that there will be no migration token, token swap, or airdrop tied to the closure, and told customers to treat any posts or sites promising compensation as likely scams. The company has explicitly stated that any offers of migration tools or phishing links promising to rescue stranded funds are fraudulent, with bad actors inevitably swooping in when wallets shut down. With 650,000 monthly users affected by the closure, the platform has issued urgent warnings about the narrow window available for asset recovery.
The shutdown decision comes just weeks after Ctrl Wallet disclosed a security incident affecting some Cardano wallets on June 23. According to the wallet provider, it had placed parts of its platform into temporary maintenance mode while engineers investigated the issue and worked to protect user assets. The latest shutdown follows a transition announced on April 29, when Ctrl Wallet said it had come under the Emurgo umbrella and that its multichain technology would continue through the SecondFi wallet. However, the security challenges continued when attackers exploited a vulnerability in SecondFi on June 24, stealing about 16 million ADA worth roughly $2.4 million at the time. SecondFi later secured about 129 million ADA and moved those funds to an independent third-party custodian. The June 23 security exploit occurred alongside a broader security issue within the Cardano ecosystem, particularly affecting wallets at SecondFi, which led to the significant financial losses. Formerly known as XDEFI Wallet, Ctrl Wallet rebranded from XDEFI in July 2024, positioning itself as a streamlined, multi-chain solution supporting over 2,500 blockchain networks at its peak.
The closure reflects broader security challenges facing Cardano-native wallets, with ADA experiencing 4.94% decline over 24 hours to $0.1742 as of the latest reports. The token's 24-hour volume stands at $339.53 million with nearest support at $0.1659. The shutdown is part of a broader wave of crypto project closures affecting the industry in 2026, with 79 crypto projects closing, entering bankruptcy, or going dark through 2026, spanning wallets, DeFi protocols, NFT platforms, and more. The timing coincides with repeated security failures across the sector, including the $6 million exploit against Summer.fi and the $4.7 million loss by Axelar in bridged assets. What remains unclear is how long the app will stay usable after August 3, as Ctrl Wallet cannot guarantee continued access beyond that date. The immediate practical concern is obvious: if you have assets in Ctrl Wallet, move them now - export your seed phrase, import it into another wallet, or transfer your tokens to a hardware wallet, as the company has explicitly stated that "If your assets are still sitting in a Ctrl Wallet on August 4, you're on your own."