SparkKitty Malware Hunts Crypto Seed Phrases in Photos

2–3 minutes

Last Updated:

July 28, 2026

Fact checked by

Two smartphones displaying a glowing orange binary cat malware symbol.

SparkKitty Malware Hunts Crypto Seed Phrases in Photos

Two smartphones displaying a glowing orange binary cat malware symbol.

SparkKitty Malware Hunts Crypto Seed Phrases in Photos

Check Point disclosed on July 26, 2026, that a cross-platform malware strain called SparkKitty had been scanning photo libraries on infected Android and iPhone devices for cryptocurrency wallet seed phrases. 

The malware hid inside apps disguised as crypto tools, messaging platforms, and entertainment software distributed through Apple’s App Store, Google Play, and third-party channels, then sent any recovered images to servers controlled by the attackers. One infected Android app, a messaging and crypto exchange platform called SOEX, was downloaded more than 10,000 times before Google removed it.

How SparkKitty Pulls Seed Phrases From a Camera Roll

Once a user granted photo access, SparkKitty used optical character recognition to scan both existing and newly added images for text matching seed phrase formats, then uploaded any matches, along with passwords and QR code data, to attacker-controlled infrastructure, according to Check Point’s report, as detailed by The Block.

On iOS, the malware operated inside a crypto-tracking app called “币coin” listed on the App Store, concealing its code inside legitimate-looking frameworks to pass Apple’s review process. Check Point said it could not determine whether the app’s developer knowingly built in the malicious functionality.

Beyond the official stores, SparkKitty also spread through sideloaded Android packages, modified TikTok clones, and gambling apps, according to Yahoo’s coverage of the campaign. Check Point described SparkKitty as an evolution of SparkCat, an earlier OCR-based stealer that Kaspersky first documented in June 2025.

The Screenshot Habit That Puts Wallets at Risk

Anyone who has ever saved a seed phrase as a photo for convenience is the exact target this campaign was built for, since a single recovered image can be enough to hand an attacker full control of a wallet. It fits a similar pattern of wallet-focused security scares that UTB’s latest crypto news has tracked recently, including the LayerZero incident

Whether Users Move Seed Phrases Off Their Camera Roll

Check Point’s July 26, 2026 report urged crypto holders to stop storing recovery phrases as screenshots and to keep them offline instead, on paper or in a hardware wallet backup. Whether that guidance changes habits will be the real test, since SparkKitty’s predecessor, SparkCat, used the same screenshot-scanning technique months earlier without slowing the practice.

What This Means for You

If a seed phrase has ever been screenshotted or saved to a phone’s photo gallery, it should be moved to an offline backup, such as a written copy or a hardware wallet, as soon as possible. Reviewing which apps currently have photo library access, and removing any that do not need it, closes off the exact opening SparkKitty relies on. 

Deleting an app after infection does not undo an already-uploaded seed phrase, so any wallet tied to a photographed recovery phrase should be treated as compromised and moved to a new one.

This article is for informational purposes only and does not constitute financial advice. Do your own research before making any investment decisions.

Join our growing community

Darlene Lleno

Author

Darlene Lleno is a crypto enthusiast and author who was first hooked on Axie Infinity, with SLP (Smooth Love Potion) being her entry point into the world of digital assets. While she still holds SLP, her focus has since expanded to include diverse trading in cryptocurrencies, memecoins, metals, and stocks. Passionate about exploring opportunities across various markets, Darlene shares her insights and experiences to help others navigate the dynamic financial landscape.