Top StoriesBearish
71

SparkKitty Malware Targets Crypto Wallets via App Stores

A new malware campaign called SparkKitty has infiltrated Apple's App Store and Google Play, scanning photo libraries for crypto wallet seed phrases. Check Point reports that trojanized apps like 币coin and SOEX exfiltrated sensitive data, highlighting the danger of storing recovery phrases as screenshots.

DecryptJason Nelson

Quick Take

1

SparkKitty malware spread via Apple App Store, Google Play, and third-party stores.

2

iOS app "币coin" and Android app SOEX (10,000+ downloads) were trojanized.

3

Malware scans photo libraries directly for seed phrase screenshots.

4

Researchers urge offline storage and limiting photo permissions.

Market Impact Analysis

Bearish

Malware targeting crypto users via official app stores erodes trust and highlights security vulnerabilities, potentially leading to cautious behavior and negative sentiment.

Timeframeshort

Speculation Analysis

Factuality90/100
RumorsVerified
Speculation Trigger60/100
MinimalExtreme FOMO

Key Takeaways

  • SparkKitty malware infiltrated official app stores, scanning photo libraries for crypto wallet seed phrases.
  • iOS app “币coin” and Android app SOEX (10,000+ installs) were trojanized, exfiltrating screenshots.
  • Unlike clipboard grabbers, SparkKitty targets image storage directly, making seed phrase screenshots a critical risk.
  • Affected apps have been removed; researchers warn against storing recovery phrases as images.
Discovery Date June 2025 Kaspersky first spotted it
Android Installs 10,000+ SOEX on Google Play
Report July 2026 Check Point analysis
Vector App Stores Apple & Google official

What Happened

A stealthy malware campaign dubbed SparkKitty has been caught lurking inside Apple’s App Store and Google Play, turning legitimate-looking apps into seed phrase thieves. Disguised as crypto tools and messaging platforms, the trojanized apps requested photo library access and then scanned for images containing wallet recovery phrases. Check Point’s July 2026 report details how the malware, first uncovered by Kaspersky in June 2025, managed to bypass app store review processes. The offending apps — including “币coin” on iOS and SOEX on Android — have since been removed, but not before potentially exposing users who stored seed phrases as screenshots.

The Numbers

On Android alone, the SOEX app was downloaded more than 10,000 times from Google Play. The iOS app “币coin” cleared Apple’s review by hiding its malicious code, then silently requested photo access. SparkKitty’s technique is direct: it scans image files rather than monitoring clipboards or keystrokes, making screenshots of recovery phrases a prime target. The campaign’s multi-platform reach — official app stores plus third-party marketplaces — gave it a broad attack surface, though exact victim counts remain undisclosed.

Why It Happened

Crypto users often save seed phrases as screenshots for easy access, a practice that’s convenient but catastrophic when photo libraries are compromised. Attackers exploited users’ trust in official app stores, knowing that even security-conscious individuals may relax permissions for seemingly legitimate apps. SparkKitty’s developers embedded the image-scanning capability deep within trojanized apps, evading detection until flagged by security researchers. The incident reflects a growing trend: cybercriminals increasingly tailor attacks to crypto-specific vulnerabilities, and app stores remain a weak link despite their vetting processes.

Broader Impact

The breach of Apple’s and Google’s walled gardens underscores that no platform is immune. For crypto holders, it’s a wake-up call to treat seed phrases like physical gold — never stored digitally, especially as images. For the industry, it highlights an urgent need for app store operators to improve static and dynamic code analysis to catch such threats before they go live. The same technique could resurface in other apps, making it a blueprint for future attacks.

What to Watch Next

  • Additional app removals: Security teams may uncover more trojanized apps still hiding in stores.
  • Copycat campaigns: SparkKitty’s success could inspire similar image-scanning malware targeting other platforms.
  • App store defenses: Expect Apple and Google to tighten review processes in response to the breach.
Source: Decrypt

This article is for informational purposes only and does not constitute financial advice.

SourceRead the full article on Decrypt
Read full article

Always late to trends?

Join for the latest news, insights & more.

Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.

© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.

Read Next

Most Read

⚖️
Top StoriesNeutral
52

NYC Property Database Draws Backlash Over Wealthy Doxxing Risk

New York City's searchable property assessment database has sparked alarm among crypto leaders, who warn it creates a target list for violent attacks. Executives cite a 75% rise in crypto 'wrench attacks,' with recent kidnappings and home invasions underscoring the danger.

85% confidence
Jul 27, 2026, 9:05 PM UTC · Decrypt
SparkKitty Malware Hits App Stores, Steals Crypto Seed Phrases | Bytewit