Check Point disclosed on July 26, 2026, that a cross-platform malware strain called SparkKitty had been scanning photo libraries on infected Android and iPhone devices for cryptocurrency wallet seed phrases.
The malware hid inside apps disguised as crypto tools, messaging platforms, and entertainment software distributed through Apple’s App Store, Google Play, and third-party channels, then sent any recovered images to servers controlled by the attackers. One infected Android app, a messaging and crypto exchange platform called SOEX, was downloaded more than 10,000 times before Google removed it.
How SparkKitty Pulls Seed Phrases From a Camera Roll
Once a user granted photo access, SparkKitty used optical character recognition to scan both existing and newly added images for text matching seed phrase formats, then uploaded any matches, along with passwords and QR code data, to attacker-controlled infrastructure, according to Check Point’s report, as detailed by The Block.
On iOS, the malware operated inside a crypto-tracking app called “币coin” listed on the App Store, concealing its code inside legitimate-looking frameworks to pass Apple’s review process. Check Point said it could not determine whether the app’s developer knowingly built in the malicious functionality.
Beyond the official stores, SparkKitty also spread through sideloaded Android packages, modified TikTok clones, and gambling apps, according to Yahoo’s coverage of the campaign. Check Point described SparkKitty as an evolution of SparkCat, an earlier OCR-based stealer that Kaspersky first documented in June 2025.
The Screenshot Habit That Puts Wallets at Risk
Anyone who has ever saved a seed phrase as a photo for convenience is the exact target this campaign was built for, since a single recovered image can be enough to hand an attacker full control of a wallet. It fits a similar pattern of wallet-focused security scares that UTB’s latest crypto news has tracked recently, including the LayerZero incident
Whether Users Move Seed Phrases Off Their Camera Roll
Check Point’s July 26, 2026 report urged crypto holders to stop storing recovery phrases as screenshots and to keep them offline instead, on paper or in a hardware wallet backup. Whether that guidance changes habits will be the real test, since SparkKitty’s predecessor, SparkCat, used the same screenshot-scanning technique months earlier without slowing the practice.
What This Means for You
If a seed phrase has ever been screenshotted or saved to a phone’s photo gallery, it should be moved to an offline backup, such as a written copy or a hardware wallet, as soon as possible. Reviewing which apps currently have photo library access, and removing any that do not need it, closes off the exact opening SparkKitty relies on.
Deleting an app after infection does not undo an already-uploaded seed phrase, so any wallet tied to a photographed recovery phrase should be treated as compromised and moved to a new one.
This article is for informational purposes only and does not constitute financial advice. Do your own research before making any investment decisions.


