SparkKitty Malware Steals Seed Phrases via App Store and Google Play
Security

SparkKitty Malware Steals Seed Phrases via App Store and Google Play

July 28, 20265 min read

Check Point is an international cybersecurity firm that regularly publishes reports on new threats facing crypto users. Its researchers have now uncovered a large SparkKitty malware campaign hiding inside apps on the App Store and Google Play that scans photo libraries for crypto wallet seed phrases. The malware was first spotted back in June 2025, but a new report shows just how widely it has since spread.

What SparkKitty is, and why a seed phrase matters so much

A recovery phrase is a sequence of 12 to 24 words that grants full access to a wallet, so whoever obtains it can drain the funds without a password or two-factor check. Seed phrase theft remains one of the most common ways crypto holders lose money, since unlike a password it cannot simply be reset after the fact.

Once installed, the app requests access to the photo library, then scans every saved image looking for screenshots of recovery phrases and other sensitive data. Anything it finds gets uploaded to attacker-controlled servers automatically. After grabbing a photo of the phrase, attackers restore the wallet on their own device and drain it within minutes, so victims often find out about the theft only after the wallet is already empty.

Bottom line: SparkKitty scans photos for crypto wallet seed phrases and sends them to attacker servers, and it spread through the official App Store and Google Play.

How the malware got into the App Store and Google Play

Unlike typical info-stealers that monitor the clipboard or keystrokes, SparkKitty goes straight for the photo library. The logic is simple. Many users screenshot their seed phrase just in case and then forget about it, and those forgotten images end up being exactly what the malware is hunting for.

On iOS, the malware hid inside an app called "币coin," which translates roughly to "coin" in Chinese. The app passed Apple's review by concealing its malicious code, then requested photo library access only after installation. On Android, SparkKitty spread through an app called SOEX, which combined a messaging service with a crypto exchange and racked up more than 10,000 downloads on Google Play before being pulled. Malicious apps like these often hide risky behavior during the review stage itself, only switching it on after they pass inspection and reach real users.

Other versions of the malware spread through third-party app stores, fake TikTok apps, gambling apps, and sideloaded APK files installed outside official channels. Researchers note that being present in two major official stores at once significantly widens the pool of potential victims, since users tend to trust the App Store and Google Play more than third-party sources.

SparkKitty by the numbers
First discoveredJune 2025, Kaspersky
PlatformsiOS and Android
SOEX downloadsover 10,000
Scan targetphotos with seed phrases

"What makes SparkKitty particularly notable is its presence on both the Apple App Store and Google Play, giving it a wide attack surface."

- Check Point, from its report on the SparkKitty campaign

Why this is not the first case like it

SparkKitty is just one episode in a longer string of attacks on crypto users. In March, Google disclosed the DarkSword exploit chain along with Ghostblade malware that targeted wallets and exchanges and stole messages, passwords, and photos from vulnerable iPhones. That same month, the FBI opened an investigation after several games on Steam, including Chemia, PirateFi, and Tokenova, turned out to be infected with malicious code before players even noticed. In just the past few months, researchers have counted at least four separate campaigns aimed specifically at crypto wallet owners.

In May, AI startup Perplexity open-sourced Bumblebee, a tool for detecting compromised packages, browser extensions, and AI connector configurations. That followed a software supply-chain attack that hit more than 160 developer packages. In June, Kaspersky reported malicious Wallpaper Engine downloads spreading through Steam Workshop disguised as anime-themed wallpapers. Those files installed the Lumma and Vidar infostealers, which also hunt for crypto wallet data, just through different methods.

The regularity of these campaigns shows that wallet-targeting attacks have become their own category of cybercrime rather than isolated incidents. Attackers latch onto whatever is popular, whether that is crypto trading, gaming, or desktop aesthetics, to get victims to install the infected app themselves. The barrier to entry is low, since malware code gets sold and resold on underground forums, so new variants keep appearing faster than stores can pull them. For attackers it is close to a break-even business already, since a single stolen seed phrase can cover months of building and distributing the malware.

How to protect your crypto assets

This matters directly for crypto users who move funds to self-custody after trading. Many people transfer assets to a new wallet right after an exchange or an exchanger transaction, and that freshly created wallet is often exactly where the seed phrase SparkKitty hunts for first ends up stored. That applies especially to people who keep funds on an exchange only briefly before moving them into a personal wallet for long-term storage.

  • Never store your seed phrase as a screenshot: write it on paper or a metal plate and keep it offline
  • Limit photo library access to apps you genuinely trust
  • Install apps only from verified developers, even if they passed an official store's review
  • Consider a hardware wallet to keep your keys separate from your phone and photo library
  • Periodically review which apps have photo access and revoke permissions you no longer need

A general catalog of hardware wallets is a good starting point for anyone who wants to move a seed phrase away from a smartphone. Ledger, for instance, stores private keys inside its own secure chip and never exposes them to apps on the phone, even ones with photo library access. That kind of wallet signs transactions on a separate device, so even an infected phone never sees the actual key. The cost of such a device usually pays for itself after the first blocked fraud attempt.

SparkKitty is unlikely to be the last attempt to reach crypto wallets through a smartphone camera roll. As long as these attacks keep paying off, similar campaigns will keep appearing, and the next one will likely disguise itself as something just as ordinary. The most reliable defense is simple: never keep a seed phrase anywhere a third-party app could reach it, whether the wallet holds Bitcoin or any other asset. Each new wave will likely be a little cleverer than the last, so it is worth building the habit of checking app permissions now, rather than after the first loss of funds. The few minutes that takes are far cheaper than recovering a wallet that has already been drained.

Comments

Your email address will not be published. Required fields are marked *

or verify by email