📈 Get daily crypto insights that make you smarter about your money

SparkKitty Malware Slithers Through App Stores to Harvest Crypto Wallet Seed Phrases

SparkKitty, a sophisticated malware strain that infiltrated both Apple’s App Store and Google Play, has been caught silently scanning users’ photo libraries for cryptocurrency wallet seed phrases — and researchers warn the campaign may be far larger than initially thought.

A Trojan Horse Disguised as a Crypto Tool

If you have ever screenshotted your wallet recovery phrase for “safekeeping,” this story should make you rethink that habit immediately.

Cybersecurity firm Check Point published a report this week detailing the full scope of SparkKitty, a cross-platform information-stealing Trojan that specifically targets cryptocurrency users on both iOS and Android devices. First discovered by Kaspersky researchers in June 2025, the malware has now been confirmed to have spread through official app stores — including Apple’s tightly guarded App Store — disguised as legitimate cryptocurrency tracking and messaging applications.

The implications are staggering. With BTC trading at $63,421, ETH at $1,875, and SOL at $73.12 at press time, the crypto market is already under pressure from macroeconomic headwinds including a red trading day and the upcoming Federal Reserve meeting. The last thing holders need is a malware campaign silently draining their wallets.

How SparkKitty Works

Unlike traditional information stealers that rely on clipboard hijacking or keylogging, SparkKitty takes a more insidious approach: it directly accesses users’ photo libraries and scans every image for wallet recovery phrases, passwords, and other sensitive information captured in screenshots.

Once a user grants the malicious app permission to access their photo gallery — a request that seems innocuous coming from a crypto tracking or messaging app — SparkKitty systematically analyzes stored images using optical character recognition (OCR) technology. Any detected seed phrases or sensitive data are then uploaded to attacker-controlled servers.

On iOS, the malware was distributed through an app called “币coin,” listed on Apple’s App Store as a cryptocurrency price tracker and trading signal platform. The app concealed its malicious functionality during Apple’s review process, only revealing its true capabilities after installation. This marks one of the rare instances where malware successfully bypassed Apple’s notoriously strict App Store review — and the second time Kaspersky has documented such a breach following the earlier SparkCat campaign.

On Android, the malware was embedded in a messaging and cryptocurrency exchange app called SOEX, which racked up more than 10,000 downloads on Google Play before being removed. Additional variants were distributed through third-party app stores, fake TikTok mods, gambling applications, and sideloaded APK files, significantly expanding the attack surface.

The Threat Landscape for Altcoin Holders

What makes SparkKitty particularly dangerous for the altcoin community is its targeting model. The malware does not discriminate between Bitcoin maximalists and altcoin traders — it simply harvests every seed phrase it can find. For users managing multiple altcoin wallets across different blockchain ecosystems, a single compromised screenshot could mean the total loss of their portfolio.

The timing could not be worse. Markets are already deep in the red, with major altcoins posting significant losses amid broader risk-off sentiment. Prediction market traders on Polymarket have sharply raised the implied odds of a Federal Reserve rate hike ahead of the FOMC meeting concluding July 29, with the probability of a 25-basis-point increase jumping nearly 10 percentage points to 26.65% in the past 24 hours. A rate hike would put additional downward pressure on risk assets, including cryptocurrencies.

For altcoin holders already watching their portfolios shrink, the prospect of losing remaining funds to a malware attack adds insult to injury — and underscores the urgent need for better operational security across the crypto ecosystem.

A Pattern of Escalating Crypto-Targeted Malware

SparkKitty does not exist in isolation. It is part of a broader escalation in malware campaigns specifically designed to target cryptocurrency users. In March 2026, Google disclosed the DarkSword exploit chain, which deployed Ghostblade malware capable of targeting major cryptocurrency exchanges and wallet applications on vulnerable iPhones. That same month, the FBI launched an investigation after several games distributed through Valve’s Steam platform were found installing malware that harvested crypto credentials.

In June, Kaspersky reported that attackers were using Steam Workshop to distribute malicious Wallpaper Engine downloads disguised as anime-themed desktop wallpapers. Those payloads deployed Lumma and Vidar infostealers — malware families commonly used to steal browser credentials and cryptocurrency wallet data. The campaign demonstrated how attackers are increasingly abusing trusted distribution platforms to reach cryptocurrency users.

The SparkKitty campaign follows the same playbook but adds a frightening new dimension: it successfully infiltrated both major mobile ecosystems simultaneously, creating a wide attack surface that spans the entire smartphone market.

What This Means for the Crypto Community

The security implications extend beyond individual users losing funds. Every successful malware campaign erodes trust in mobile cryptocurrency applications more broadly — and that trust is already fragile. Mobile wallets, decentralized exchange apps, and portfolio trackers are critical infrastructure for the altcoin ecosystem. If users become afraid to install any crypto-related application, adoption slows.

There is also a regulatory dimension. The fact that malware successfully bypassed Apple’s App Store review process — for the second time — will inevitably draw scrutiny from lawmakers already concerned about cryptocurrency security. The U.S. Senate recently delayed the CLARITY Act, a major crypto market-structure bill, but security incidents like this only increase the pressure for stricter oversight of crypto-adjacent applications.

For developers in the altcoin space, SparkKitty serves as a wake-up call to implement additional security measures. Hardware wallet integration, biometric authentication, and secure enclaves for seed phrase storage are no longer optional features — they are baseline requirements for any application handling cryptocurrency assets.

How to Protect Your Assets

Researchers from both Check Point and Kaspersky recommend several immediate steps for cryptocurrency users:

  • Never store wallet recovery phrases as screenshots. This is the single most important precaution. SparkKitty and similar malware specifically target photo libraries for this reason. Write seed phrases on paper and store them in a secure physical location.
  • Audit photo library permissions. Review which apps have access to your photo gallery and revoke permissions for any application that does not have a clear, legitimate need.
  • Use hardware wallets. For significant cryptocurrency holdings, hardware wallets remain the gold standard. They keep private keys offline and immune to software-based attacks.
  • Download only from reputable developers. Stick to well-known applications with established track records. Be especially cautious of apps that combine multiple functions — like messaging and crypto trading — as SparkKitty demonstrated this is a favored infiltration vector.
  • Enable two-factor authentication. On all exchange accounts and wallet services, use 2FA through an authenticator app rather than SMS.

The Bottom Line

SparkKitty represents a new tier of threat for cryptocurrency users. By successfully infiltrating both the Apple App Store and Google Play, the malware campaign demonstrated that even the most curated software ecosystems are not immune to sophisticated attacks. The targeting of photo libraries for seed phrase extraction is particularly clever — it exploits one of the most common (and worst) security practices among crypto holders.

With crypto markets already under pressure from macroeconomic uncertainty and the upcoming Federal Reserve decision, the last thing investors need is a security breach draining their wallets. The tools to protect yourself are simple and accessible. The question is whether the community will adopt them before the next campaign — because SparkKitty will not be the last.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research and consult with qualified professionals before making investment or security decisions. Cryptocurrency investments are subject to high market risk.

6 thoughts on “SparkKitty Malware Slithers Through App Stores to Harvest Crypto Wallet Seed Phrases”

  1. the fact that this got through App Store review is wild. Apple charges devs $99/yr and reviews everything but still misses actual malware lol

    1. Check Point and Kaspersky both flagged this months apart. how many people downloaded the app between their first report and the store takedown? thats the real number nobody is giving us

  2. screenshot_ghost

    the OCR scanning photo libraries angle is nasty. everyone tells newbies to screenshot their seed phrase instead of writing it down. well now thats the attack vector

  3. got through the App Store review process too. Apple charges devs 99/yr but cant catch malware scanning your photos for 12 words

  4. screenshotted my seed phrase back in 2021 and instantly deleted it but who knows if icloud kept a cache. genuinely scary stuff

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$63,046.00-3.0%ETH$1,870.63-3.9%SOL$72.68-4.6%BNB$564.93-1.1%XRP$1.05-4.7%ADA$0.1561-4.2%DOGE$0.0695-3.6%DOT$0.7558-5.4%AVAX$6.41-3.0%LINK$8.24-5.2%UNI$3.87-0.3%ATOM$1.29-5.9%LTC$46.03-1.9%ARB$0.0780-3.4%NEAR$1.64-8.9%FIL$0.6935-5.6%SUI$0.6797-3.8%BTC$63,046.00-3.0%ETH$1,870.63-3.9%SOL$72.68-4.6%BNB$564.93-1.1%XRP$1.05-4.7%ADA$0.1561-4.2%DOGE$0.0695-3.6%DOT$0.7558-5.4%AVAX$6.41-3.0%LINK$8.24-5.2%UNI$3.87-0.3%ATOM$1.29-5.9%LTC$46.03-1.9%ARB$0.0780-3.4%NEAR$1.64-8.9%FIL$0.6935-5.6%SUI$0.6797-3.8%
Scroll to Top