SparkKitty malware crypto wallets threat found in app stores
Check Point says SparkKitty scanned phone photos for wallet recovery phrases after spreading through Apple, Google and third-party app stores.
By Sofia Marchetti · Columnist
· 3 min read
Cybersecurity firm Check Point says SparkKitty malware crypto wallets attacks used infected mobile apps to search users’ photo libraries for wallet recovery phrases. For retail crypto holders, the takeaway is direct: a screenshot of a seed phrase can become a target if a malicious app gets photo access.
Check Point said SparkKitty appeared in apps distributed through Apple’s App Store, Google Play and third-party app stores. Kaspersky first identified the malware in June 2025, according to Check Point’s report.
The campaign focused on cryptocurrency users by scanning images stored on Android phones and iPhones for wallet recovery phrases and other sensitive information, Check Point said. A wallet recovery phrase, often called a seed phrase, is the backup phrase used to restore access to a crypto wallet. Researchers warned that keeping it as a screenshot can expose crypto assets to theft.
How did SparkKitty malware target crypto wallets?
Check Point said the malware started working after users gave the infected app permission to access their photo libraries. It then searched stored images for recovery phrases and other private data, and sent what it found to servers controlled by attackers.
That method stands out because many information-stealing malware campaigns rely on tools such as clipboard monitoring or keylogging, according to the report. Clipboard monitoring watches copied text, while keylogging records what a user types. SparkKitty instead looked directly through saved photos, making wallet backup screenshots an obvious risk.
On iOS, Check Point said SparkKitty was found in a cryptocurrency app called “币coin” that had been available through Apple’s App Store. The firm said the app hid its malicious code in an attempt to get through Apple’s review process, then asked users for photo library access.
On Android, Check Point said the malware appeared in SOEX, described as a messaging and cryptocurrency exchange app. The app was downloaded more than 10,000 times from Google Play before it was removed, according to the report.
Check Point also said other SparkKitty variants moved through third-party app stores, fake TikTok apps, gambling apps and sideloaded APKs. An APK is an Android app installation file, and sideloading means installing an app from outside an official app store.
What can crypto users do about seed phrase screenshots?
Check Point’s advice is to keep wallet recovery phrases offline rather than saving them as screenshots. The firm also recommends limiting photo access to trusted apps and downloading software only from reputable developers.
The report adds to a run of recent malware cases aimed at crypto users. In March, Google disclosed the DarkSword exploit chain, which deployed Ghostblade malware that could target major crypto exchanges and wallet apps while stealing messages, passwords, photos and other data from vulnerable iPhones.
Also in March, the FBI opened an investigation after games distributed through Valve’s Steam platform, including “Chemia,” “PirateFi” and “Tokenova,” were found to install malware. In May, Perplexity released Bumblebee as an open-source security tool for detecting compromised software packages, browser extensions and AI connector configurations without running potentially malicious code, after a software supply-chain attack affected more than 160 developer packages.
This story draws on original reporting from Decrypt.