Loading market data...

SparkKitty Malware Found in Apple and Google App Stores, Steals Crypto Seed Phrases from Photos

SparkKitty Malware Found in Apple and Google App Stores, Steals Crypto Seed Phrases from Photos

Security researchers have identified a new malware strain called SparkKitty lurking in both Apple's App Store and Google Play. The malicious apps target cryptocurrency users by scanning device photos for wallet seed phrases — the strings of words used to recover crypto wallets. The discovery highlights a growing trend of malware exploiting the way users store sensitive crypto information on their phones.

How SparkKitty operates

The malware gains access to the device's photo library and uses optical character recognition to extract seed phrases from images. Once obtained, the phrases are exfiltrated to a remote server, allowing attackers to drain the associated wallets. The apps themselves appear legitimate, often disguised as utility tools or games, to bypass app store security checks.

Why seed phrases are a prime target

Seed phrases are the master keys to cryptocurrency wallets. Anyone with the phrase can restore the wallet and control the funds. Many users take screenshots of their seed phrases for safekeeping — a practice that is widely discouraged. SparkKitty exploits this exact behavior, turning a convenience into a vulnerability.

What users can do

The best defense is to never store seed phrases digitally. Use a hardware wallet or write them down on paper and store them securely. Users should also review their installed apps and remove any that seem suspicious or request unnecessary permissions, especially access to photos. Both Apple and Google have been notified, and the malicious apps are being removed from the stores.

The full scope of SparkKitty's distribution is still under investigation. Users are advised to remain vigilant and avoid granting photo library access to apps that don't need it.