July 28, 2026 ChainGPT

SparkKitty steals crypto seed phrases from phone photos — trojan apps hit App Store and Google Play

SparkKitty steals crypto seed phrases from phone photos — trojan apps hit App Store and Google Play
New malware campaign “SparkKitty” is targeting cryptocurrency users by scanning photos on infected phones for wallet recovery phrases and other sensitive data, researchers warn. What happened - Cybersecurity firm Check Point analyzed SparkKitty after it was first spotted by Kaspersky in June 2025. Check Point says the campaign reached users through Apple’s App Store, Google Play, and multiple third‑party stores — a rare cross‑platform presence that widened its attack surface. - The attackers pushed trojanized apps masquerading as legitimate crypto tools, messaging apps and even entertainment software to increase installation chances. “What makes SparkKitty particularly notable is its presence on both the Apple App Store and Google Play,” Check Point wrote. How SparkKitty works - Once installed and granted photo‑library access, SparkKitty scans images on the device for wallet recovery phrases (seed phrases), screenshots, and other sensitive information, then uploads harvested data to attacker‑controlled servers. - On iOS the malware was distributed via a cryptocurrency app named “币coin” that passed Apple’s review by concealing malicious code, then asked for photo permissions. On Android it was embedded in a messaging/crypto exchange app called SOEX, which was downloaded more than 10,000 times from Google Play before removal. - Other variants were installed through third‑party app stores, fake TikTok apps, gambling apps and sideloaded APKs. - SparkKitty’s photo‑scanning approach differs from many stealers that rely on clipboard monitoring or keylogging — it specifically targets screenshots of recovery phrases and other image‑based backups. Why this matters - Storing seed phrases as phone screenshots or in cloud‑synced photos creates a single point of failure: malicious apps with photo access can exfiltrate keys and drain wallets. - The campaign adds to a recent surge of threats aimed at crypto users across platforms, illustrating how diverse delivery methods (official app stores, game platforms, sideloading) are being abused. Context — other recent crypto‑targeting campaigns - In March, Google disclosed a DarkSword exploit chain that delivered Ghostblade malware capable of stealing messages, passwords, photos and crypto data from iPhones. - The FBI opened an investigation after several Steam games (including “Chemia,” “PirateFi,” and “Tokenova”) were found to install malware. - In May, AI firm Perplexity released Bumblebee, an open‑source tool to detect compromised packages and extensions after a supply‑chain attack hit hundreds of developer packages. - In June, Kaspersky reported malicious Wallpaper Engine downloads on Steam Workshop that deployed Lumma and Vidar infostealers to harvest browser credentials and wallet data. Practical advice for crypto users - Never store recovery phrases as phone screenshots or in cloud‑synced photo folders — keep seed phrases offline on paper or a hardware wallet. - Limit photo‑library permissions and only grant them to trusted apps. Revoke access when it’s not needed. - Download apps only from reputable developers and verify app authenticity (reviews, developer websites). Be cautious with sideloaded APKs and third‑party stores. - Use hardware wallets for significant holdings, enable two‑factor authentication where available, and keep devices and apps updated. - If you suspect compromise, move funds to a new wallet whose seed phrase was never stored digitally and scan devices with reputable mobile security tools. Takeaway SparkKitty demonstrates how simple habits — saving recovery phrases as images and granting broad photo permissions — can be exploited at scale. As attackers continue to adapt delivery methods, crypto users must treat seed phrases as the highest‑risk secret and use offline, hardware‑based protections whenever possible. Read more AI-generated news on: undefined/news