Skip to main content
Sign in

Audit log

Every state-changing event for Ctrl Wallet — Security Exploit and Forced Shutdown: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-04 23:23:44Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    UJ4UHXqWCrXo…rfQgjYp5sha256 → base58
    verifying row…
    canonical bytes (26392 B) ▸
    {"actor":"system:backfill","investigation_id":"931907a8-d223-4aca-a200-3a427b25acf4","kind":"publish","page_slug":"ctrl-wallet-security-exploit-and-forced-shutdown","published_at":"2026-08-04T23:23:43.995Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Ctrl Wallet — Security Exploit and Forced Shutdown","sections":[{"content":"Ctrl Wallet originated as XDEFI Wallet, a multi-chain non-custodial crypto wallet founded in 2020. In July 2024, XDEFI rebranded to Ctrl Wallet, simultaneously initiating a token migration from $XDEFI to $CTRL at a 1:1 ratio. The wallet grew to support over 2,500 blockchain networks and approximately 650,000 monthly active users. On April 29, 2026, EMURGO — the commercial arm and a co-founding entity of the Cardano blockchain — completed an acquisition of Ctrl Wallet's technology infrastructure. EMURGO explicitly excluded the $CTRL token from the acquisition, acquiring only the wallet platform and its core multichain capabilities. EMURGO's stated intent was to integrate Ctrl Wallet's technology into SecondFi, a unified digital finance platform that had itself been rebranded from Yoroi Wallet in April 2026. The organizational structure at the time of the exploit therefore placed both Ctrl Wallet and SecondFi under EMURGO's operational umbrella.","heading":"Entity Background and Corporate History","severity":"low","sources":[{"credibility":2,"name":"XDEFI Rebrands to Non-custodial Wallet Dubbed Ctrl — Coinspeaker","type":"news_article","url":"https://www.coinspeaker.com/xdefi-non-custodial-wallet-ctrl/"},{"credibility":2,"name":"EMURGO Acquires Ctrl Wallet to Expand Cardano Reach — CoinTrust","type":"news_article","url":"https://www.cointrust.com/market-news/emurgo-acquires-ctrl-wallet-to-expand-cardano-reach"},{"credibility":2,"name":"EMURGO Expands Cardano Ecosystem by Acquiring Ctrl Wallet — CryptoNews","type":"news_article","url":"https://cryptonews.net/news/blockchain/32782127/"},{"credibility":2,"name":"Ctrl Wallet Begins $XDEFI to $CTRL Migration — The Defiant","type":"news_article","url":"https://thedefiant.io/news/press-releases/ctrl-wallet-begins-xdefi-to-ctrl-migration-and-enhances-tokenomics-to-complete-rebrand"}]},{"content":"Between June 21 and June 23, 2026, attackers executed a coordinated, multi-wave theft targeting Cardano wallets managed through the SecondFi platform, which shared infrastructure with Ctrl Wallet under EMURGO. The root cause was identified as a cryptographic flaw in SecondFi's transaction signing software: a value that should have been derived from secret information could, under certain conditions, be computed from publicly visible transaction data on the Cardano blockchain. This deterministic nonce derivation weakness allowed attackers to reconstruct private key material from on-chain public records alone, without ever obtaining seed phrases directly. The vulnerability existed at the address level and disproportionately affected default or first wallet addresses that had accumulated transaction history. Hardware wallet users were not affected. The Cardano network itself was not compromised. Approximately 16.1 million ADA — valued at approximately $2.4 to $2.6 million USD at the time — was stolen from 374 wallet addresses across three to four distinct automated attack waves. An independent forensic investigation by blockchain intelligence firm Groom Lake identified two separate attackers: Attacker A, responsible for draining 171 wallets across Waves 1 and 2; and Attacker B, responsible for 203 wallets in Wave 3. Groom Lake's analysis found that Attacker A exhibited indicators 'potentially consistent with state-aligned threat activity, including possible links to the DPRK-associated Lazarus Group,' though no confirmed official attribution has been made. A separate vulnerability path linked to an unauthorized copy of SecondFi's wallet generation code posted to a public GitHub repository was also identified as a contributing exposure vector. SlowMist, an independent blockchain security firm, estimated that total potential exposure across all at-risk wallets could have exceeded $20 million if emergency measures had not been taken. SecondFi's team secured approximately 129 million ADA through emergency containment and transferred those funds to an independent third-party custodian pending verified distribution.","heading":"The June 2026 Cryptographic Exploit","severity":"critical","sources":[{"credibility":1,"name":"SecondFi Security Incident Update — SecondFi Knowledge Base (official)","type":"official","url":"https://kb.secondfi.io/en/article/security-incident-update-dxv72a/"},{"credibility":1,"name":"Cardano wallet SecondFi hit by $2.4 million exploit, up to $20 million in user funds at risk — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/06/24/secondfi-loses-usd2-4-million-in-cardano-wallet-exploit-with-up-to-usd20-million-at-risk"},{"credibility":2,"name":"SecondFi Reveals Cryptographic Flaw Behind $2.6M ADA Theft — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/22/secondfi-reveals-cryptographic-flaw-behind-2-6m-ada-theft/"},{"credibility":2,"name":"SecondFi Exploit Drains 374 Cardano Wallets, Over 16 Million ADA Stolen in Coordinated Attack — Blockonomi","type":"news_article","url":"https://blockonomi.com/secondfi-exploit-drains-374-cardano-wallets-over-16-million-ada-stolen-in-coordinated-attack/"},{"credibility":2,"name":"SecondFi wallet vulnerability drains $2.4M in Cardano assets from 178 users — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/secondfi-wallet-vulnerability-cardano-drain/"}]},{"content":"Blockchain intelligence firm Groom Lake, retained by EMURGO to conduct independent forensic analysis of the exploit, identified indicators in Attacker A's behavior and tooling 'potentially consistent with state-aligned threat activity, including possible links to the DPRK-associated Lazarus Group.' The Lazarus Group is a North Korea-linked threat actor attributed by multiple governments and private intelligence firms to numerous large-scale cryptocurrency thefts. As of the time of reporting, this remains an unconfirmed alleged attribution; no official government body or law enforcement agency has publicly confirmed a DPRK link to this specific incident. A separate second attacker, identified as Attacker B, operated independently with no detected overlap with Attacker A, suggesting the two exploit campaigns may have been opportunistic and uncoordinated despite targeting the same underlying vulnerability.","heading":"Alleged State-Sponsored Attribution (Lazarus Group)","severity":"high","sources":[{"credibility":2,"name":"SecondFi Reveals Cryptographic Flaw Behind $2.6M ADA Theft — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/22/secondfi-reveals-cryptographic-flaw-behind-2-6m-ada-theft/"},{"credibility":1,"name":"SecondFi to shut down after $2.4 million ADA wallet theft — CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/07/22/secondfi-to-shut-down-after-usd2-4-million-ada-wallet-theft"},{"credibility":2,"name":"SecondFi Uncovers Two Attackers Linked to Massive 16M ADA Wallet Drain — LiveBitcoinNews","type":"news_article","url":"https://www.livebitcoinnews.com/secondfi-uncovers-two-attackers-linked-to-massive-16m-ada-wallet-drain/"}]},{"content":"On July 9, 2026, Ctrl Wallet announced a permanent shutdown effective August 3, 2026, citing an inability to recover operationally from the June exploit. The announcement gave users approximately three to four weeks to export recovery phrases and migrate funds. From the announcement date, the team disabled new downloads and began removing the app from the Apple App Store, Google Play, and all browser extension marketplaces. Until August 2, 2026, users retained the ability to transfer funds, perform swaps, and connect to dApps. After August 3, the only remaining function was recovery phrase export. Users who missed the August 3 deadline face significant barriers to accessing remaining funds, as the application was removed from all distribution channels before that date. Compatible destination wallets cited by Ctrl Wallet for fund migration included MetaMask, Trust Wallet, and Phantom. Ctrl Wallet explicitly stated that there would be no migration token, no $CTRL token swap, no airdrop, and no compensation program. The team warned that any social media posts, websites, or contacts promising such rewards — or requesting wallet connections or recovery phrases in exchange for compensation — should be treated as scams. Cardano founder Charles Hoskinson publicly acknowledged the incident, noting that while the dollar amount was modest relative to other large-scale crypto hacks, the impact on affected individuals was meaningful.","heading":"Permanent Shutdown and User Impact","severity":"critical","sources":[{"credibility":2,"name":"Ctrl Wallet shuts down after exploit, urges users to move funds — Crypto.News","type":"news_article","url":"https://crypto.news/ctrl-wallet-shuts-down-after-exploit-urges-move-funds/"},{"credibility":1,"name":"Ctrl Wallet Announces Shutdown Weeks after Security Exploit — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/ctrl-wallet-shutdown-security-exploit"},{"credibility":2,"name":"Ctrl Wallet to Shut Down Aug. 3, 2026 After Security Incident — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/ctrl-wallet-to-shut-down-aug-3-2026-after-security-incident"},{"credibility":2,"name":"Ctrl Wallet to shut down August 3 after security exploit — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/ctrl-wallet-shut-down-august-3-exploit/"},{"credibility":2,"name":"REALITY CHECK | A 650K-User Self-Custodial Wallet Shuts Down Following Exploit — BitKE","type":"news_article","url":"https://bitcoinke.io/2026/08/ctrl-wallet-shuts-down/"}]},{"content":"SecondFi and EMURGO outlined a multi-phase recovery plan for the 374 affected Cardano wallet addresses. Emergency containment secured approximately 129 million ADA — funds that had been at risk but not yet drained — and transferred them to an independent third-party custodian. An external accounting firm was engaged to verify holdings. EMURGO CEO Phillip Pon stated: 'Our commitment remains unequivocal: to support the return of assets of all affected wallet addresses from the 4 distinct wallet draining events.' A zero-knowledge proof-based recovery portal was announced for launch in late August 2026, designed to allow users to cryptographically prove wallet ownership and receive asset transfers without re-exposing compromised key material. A wallet export utility enabling migration of ADA, tokens, and NFTs to any user-selected Cardano wallet was scheduled for mid-August 2026. SecondFi also publicly disclosed the attacker wallet addresses and stake keys to facilitate community-level monitoring. Input Output Group and the Cardano Foundation were reported to be collaborating on the recovery roadmap, though their specific roles were not fully detailed in available sources as of the investigation date. The vulnerability in the signing code was patched; wallets created after the patch are not believed to carry the flaw. SecondFi and Yoroi wallet services are permanently ceasing operations regardless of the patch, as EMURGO determined the reputational and operational damage was unrecoverable.","heading":"SecondFi Recovery and Compensation Efforts","severity":"high","sources":[{"credibility":1,"name":"SecondFi Security Incident Update — SecondFi Knowledge Base (official)","type":"official","url":"https://kb.secondfi.io/en/article/security-incident-update-dxv72a/"},{"credibility":2,"name":"SecondFi Hack Compensation Plan and Recovery Roadmap — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/27/secondfi-hack-compensation/"},{"credibility":1,"name":"SecondFi Winds Down After $2.6M ADA Wallet Exploit — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/secondfi-shutdown-ada-theft-wallet-flaw"},{"credibility":2,"name":"16.1 Million Cardano (ADA) Exploit: SecondFi Maps Out How It Will Return Stolen Funds — U.Today","type":"news_article","url":"https://u.today/161-million-cardano-ada-exploit-secondfi-maps-out-how-it-will-return-stolen-funds"}]},{"content":"Ctrl Wallet and SecondFi both explicitly warned users that no migration token, token swap, airdrop, or compensation program would be issued in connection with the shutdown. The platforms advised that any offers promising such incentives — particularly those requesting wallet connections, recovery phrase submission, or personal information — should be treated as fraudulent. This category of post-collapse impersonation scam is well-documented in the crypto space: after a high-profile wallet closure, bad actors commonly register lookalike domains, create impersonator social media accounts, and solicit affected users under the guise of recovery or compensation. Users who lost funds in the exploit or missed the migration window are considered at elevated risk of targeting by such scams. No legitimate recovery mechanism from Ctrl Wallet requires users to provide seed phrases to a third party or connect wallets to unfamiliar applications.","heading":"Scam Risk: Post-Closure Impersonation","severity":"critical","sources":[{"credibility":2,"name":"Ctrl Wallet shuts down after exploit, urges users to move funds — Crypto.News","type":"news_article","url":"https://crypto.news/ctrl-wallet-shuts-down-after-exploit-urges-move-funds/"},{"credibility":2,"name":"Ctrl Wallet to shut down August 3 after security exploit — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/ctrl-wallet-shut-down-august-3-exploit/"}]},{"content":"The vulnerability's technical character — exploiting a deterministic nonce flaw in signing code to reconstruct private keys from public blockchain data — is classified as a critical cryptographic implementation failure. Such flaws are particularly dangerous because exploitation requires only passive observation of the public ledger; no server breach, phishing, or social engineering was necessary. Affected addresses are those where the vulnerable software generated the wallet and where at least one transaction was broadcast to the Cardano mainnet, making the exposure window deterministic and reconstructable by any party with knowledge of the flaw. Because the flaw was present in an unauthorized copy of the signing code also posted to a public GitHub repository, the timing of third-party discovery cannot be ruled out. Users who self-hosted or used developer builds derived from this repository may also face exposure beyond the 374 addresses directly attributed to the two identified attackers. Critically, transferring a seed phrase derived from the vulnerable software to a new wallet application does not mitigate the risk for already-generated addresses; the underlying private key material of those addresses remains exposed by their public transaction history. The SecondFi-developed zero-knowledge recovery portal is designed to address this by enabling asset movement without re-using the compromised key derivation path.","heading":"Technical Risk Assessment","severity":"critical","sources":[{"credibility":1,"name":"SecondFi Security Incident Update — SecondFi Knowledge Base (official)","type":"official","url":"https://kb.secondfi.io/en/article/security-incident-update-dxv72a/"},{"credibility":2,"name":"SecondFi Reveals Cryptographic Flaw Behind $2.6M ADA Theft — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/22/secondfi-reveals-cryptographic-flaw-behind-2-6m-ada-theft/"},{"credibility":2,"name":"SecondFi exploit drains over $20M from Cardano users as wallet key generation flaw exposed — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/secondfi-exploit-drains-cardano-users/"}]}],"sources_used":[{"credibility":2,"name":"Ctrl Wallet shuts down after exploit, urges users to move funds — Crypto.News","type":"news_article","url":"https://crypto.news/ctrl-wallet-shuts-down-after-exploit-urges-move-funds/"},{"credibility":1,"name":"Cardano wallet SecondFi hit by $2.4 million exploit, up to $20 million in user funds at risk — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/06/24/secondfi-loses-usd2-4-million-in-cardano-wallet-exploit-with-up-to-usd20-million-at-risk"},{"credibility":1,"name":"SecondFi to shut down after $2.4 million ADA wallet theft — CoinDesk","type":"news_article","url":"https://www.coindesk.com/web3/2026/07/22/secondfi-to-shut-down-after-usd2-4-million-ada-wallet-theft"},{"credibility":1,"name":"SecondFi Security Incident Update — SecondFi Knowledge Base (official)","type":"official","url":"https://kb.secondfi.io/en/article/security-incident-update-dxv72a/"},{"credibility":1,"name":"Ctrl Wallet Announces Shutdown Weeks after Security Exploit — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/ctrl-wallet-shutdown-security-exploit"},{"credibility":1,"name":"SecondFi Winds Down After $2.6M ADA Wallet Exploit — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/secondfi-shutdown-ada-theft-wallet-flaw"},{"credibility":2,"name":"Cardano Wallet Shuts Down: Signing Flaw Let Attackers Steal Keys From Public Blockchain — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/321317/20260722/cardano-wallet-shuts-down-signing-flaw-let-attackers-steal-keys-public-blockchain.htm"},{"credibility":2,"name":"Ctrl Wallet to Shut Down Aug. 3, 2026 After Security Incident — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/ctrl-wallet-to-shut-down-aug-3-2026-after-security-incident"},{"credibility":2,"name":"Ctrl Wallet to shut down August 3 after security exploit — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/ctrl-wallet-shut-down-august-3-exploit/"},{"credibility":2,"name":"SecondFi Reveals Cryptographic Flaw Behind $2.6M ADA Theft — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/22/secondfi-reveals-cryptographic-flaw-behind-2-6m-ada-theft/"},{"credibility":2,"name":"SecondFi Exploit Drains 374 Cardano Wallets, Over 16 Million ADA Stolen — Blockonomi","type":"news_article","url":"https://blockonomi.com/secondfi-exploit-drains-374-cardano-wallets-over-16-million-ada-stolen-in-coordinated-attack/"},{"credibility":2,"name":"SecondFi wallet vulnerability drains $2.4M in Cardano assets — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/secondfi-wallet-vulnerability-cardano-drain/"},{"credibility":2,"name":"SecondFi exploit drains over $20M from Cardano users as wallet key generation flaw exposed — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/secondfi-exploit-drains-cardano-users/"},{"credibility":2,"name":"EMURGO Acquires Ctrl Wallet to Expand Cardano Reach — CoinTrust","type":"news_article","url":"https://www.cointrust.com/market-news/emurgo-acquires-ctrl-wallet-to-expand-cardano-reach"},{"credibility":2,"name":"EMURGO Expands Cardano Ecosystem by Acquiring Ctrl Wallet — CryptoNews","type":"news_article","url":"https://cryptonews.net/news/blockchain/32782127/"},{"credibility":2,"name":"SecondFi Shuts Down After 16.1 Million ADA Theft — CoinLaw","type":"news_article","url":"https://coinlaw.io/secondfi-shuts-down-16-1-million-ada-theft/"},{"credibility":2,"name":"SecondFi Hack Compensation Plan and Recovery Roadmap — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/27/secondfi-hack-compensation/"},{"credibility":2,"name":"SecondFi Uncovers Two Attackers Linked to Massive 16M ADA Wallet Drain — LiveBitcoinNews","type":"news_article","url":"https://www.livebitcoinnews.com/secondfi-uncovers-two-attackers-linked-to-massive-16m-ada-wallet-drain/"},{"credibility":2,"name":"16.1 Million Cardano (ADA) Exploit: SecondFi Maps Out How It Will Return Stolen Funds — U.Today","type":"news_article","url":"https://u.today/161-million-cardano-ada-exploit-secondfi-maps-out-how-it-will-return-stolen-funds"},{"credibility":2,"name":"Is ADA underpricing the risk from SecondFi's $2.4 million exploit? — AMBCrypto","type":"news_article","url":"https://ambcrypto.com/is-ada-underpricing-the-risk-from-secondfis-2-4-million-exploit/"},{"credibility":2,"name":"XDEFI Rebrands to Non-custodial Wallet Dubbed Ctrl — Coinspeaker","type":"news_article","url":"https://www.coinspeaker.com/xdefi-non-custodial-wallet-ctrl/"},{"credibility":2,"name":"Ctrl Wallet Begins $XDEFI to $CTRL Migration — The Defiant","type":"news_article","url":"https://thedefiant.io/news/press-releases/ctrl-wallet-begins-xdefi-to-ctrl-migration-and-enhances-tokenomics-to-complete-rebrand"},{"credibility":2,"name":"REALITY CHECK: A 650K-User Self-Custodial Wallet Shuts Down Following Exploit — BitKE","type":"news_article","url":"https://bitcoinke.io/2026/08/ctrl-wallet-shuts-down/"},{"credibility":2,"name":"SecondFi Reveals Cause of $2.6M ADA Breach as ZK Recovery Tool Nears Launch — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/7de7e-secondfi-reveals-cause-of-2-6m-ada-breach-as-zk-recovery-tool-nears-launch"}],"summary":"Ctrl Wallet, a multi-chain self-custodial wallet formerly known as XDEFI Wallet and supporting over 2,500 blockchain networks with approximately 650,000 monthly active users, permanently ceased operations on August 3, 2026 following an unrecovered June 2026 cryptographic exploit. The exploit targeted the Cardano integration layer operated by SecondFi (formerly Yoroi Wallet), a platform under the same EMURGO parent, draining approximately 16.1 million ADA (roughly $2.4–$2.6 million USD) from 374 wallet addresses via a signing flaw that allowed private key material to be reconstructed from public blockchain data. Users who did not export recovery phrases before the August 3 deadline may face permanent loss of access to remaining funds.","timeline":[{"date":"2020-01-01","event":"XDEFI Wallet founded as a multi-chain self-custodial wallet.","source":"Coinspeaker","source_url":"https://www.coinspeaker.com/xdefi-non-custodial-wallet-ctrl/"},{"date":"2024-07-17","event":"XDEFI Wallet publicly rebrands to Ctrl Wallet, announcing enhanced multichain features and new user onboarding focus.","source":"Crypto Daily","source_url":"https://cryptodaily.co.uk/2024/07/xdefi-rebrands-as-ctrl-a-self-custody-wallet-aiming-to-onboard-new-users-easily"},{"date":"2024-10-17","event":"Ctrl Wallet initiates $XDEFI to $CTRL token migration at a 1:1 ratio, with the $XDEFI token scheduled to deprecate September 25, 2025.","source":"The Defiant","source_url":"https://thedefiant.io/news/press-releases/ctrl-wallet-begins-xdefi-to-ctrl-migration-and-enhances-tokenomics-to-complete-rebrand"},{"date":"2026-04-29","event":"EMURGO, commercial arm of Cardano, acquires Ctrl Wallet's technology infrastructure. The $CTRL token is explicitly excluded from the deal. EMURGO simultaneously rebrands Yoroi Wallet to SecondFi.","source":"CoinTrust","source_url":"https://www.cointrust.com/market-news/emurgo-acquires-ctrl-wallet-to-expand-cardano-reach"},{"date":"2026-06-21","event":"First wave of coordinated attacks begins against SecondFi Cardano wallets, exploiting a cryptographic signing flaw to reconstruct private keys from public transaction data.","source":"SecondFi Knowledge Base (official)","source_url":"https://kb.secondfi.io/en/article/security-incident-update-dxv72a/"},{"date":"2026-06-22","event":"SecondFi detects the breach and activates emergency response protocols. Platform placed in maintenance mode.","source":"SecondFi Knowledge Base (official)","source_url":"https://kb.secondfi.io/en/article/security-incident-update-dxv72a/"},{"date":"2026-06-23","event":"Ctrl Wallet publicly discloses a security vulnerability affecting Cardano-linked wallets. Additional attack waves continue. Total theft reaches approximately 16.1 million ADA across 374 addresses.","source":"Crypto.News","source_url":"https://crypto.news/ctrl-wallet-shuts-down-after-exploit-urges-move-funds/"},{"date":"2026-06-24","event":"CoinDesk reports the exploit publicly. SecondFi team states approximately 129 million ADA has been secured via emergency containment and transferred to an independent third-party custodian. SlowMist estimates total exposure could have exceeded $20 million.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2026/06/24/secondfi-loses-usd2-4-million-in-cardano-wallet-exploit-with-up-to-usd20-million-at-risk"},{"date":"2026-06-25","event":"Root cause of the cryptographic signing flaw identified and patched in the developer codebase. Final balance snapshot captured on June 26.","source":"SecondFi Knowledge Base (official)","source_url":"https://kb.secondfi.io/en/article/security-incident-update-dxv72a/"},{"date":"2026-07-09","event":"Ctrl Wallet announces permanent shutdown effective August 3, 2026. New downloads halted immediately. App removal from stores begins.","source":"CoinTelegraph","source_url":"https://cointelegraph.com/news/ctrl-wallet-shutdown-security-exploit"},{"date":"2026-07-22","event":"SecondFi publicly details the cryptographic flaw. Groom Lake's forensic report cites two distinct attackers; Attacker A flagged with possible DPRK/Lazarus Group indicators. SecondFi and Yoroi Wallet announce permanent shutdown.","source":"CoinDesk","source_url":"https://www.coindesk.com/web3/2026/07/22/secondfi-to-shut-down-after-usd2-4-million-ada-wallet-theft"},{"date":"2026-07-27","event":"SecondFi and EMURGO publish compensation plan developed alongside Input Output Group and the Cardano Foundation, centered on a zero-knowledge proof recovery portal.","source":"Cryptonomist","source_url":"https://en.cryptonomist.ch/2026/07/27/secondfi-hack-compensation/"},{"date":"2026-08-03","event":"Ctrl Wallet permanently ceases operations. All transfer, swap, and dApp functions disabled. Recovery phrase export functionality retained temporarily. App fully removed from Apple App Store, Google Play, and browser extension stores.","source":"Crypto.News","source_url":"https://crypto.news/ctrl-wallet-shuts-down-after-exploit-urges-move-funds/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision ac4ebf32-1d13-4eea-b8b4-261cdadd1925
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.