How SparkKitty Steals Seed Phrases
Published 7/27/2026, 2:59:15 PM
Traders should be significantly concerned about SparkKitty, a sophisticated malware strain specifically designed to steal cryptocurrency seed phrases and private keys from device photo galleries. Discovered by security researchers in June 2025, the malware has successfully bypassed security filters on both the Apple App Store and Google Play Store, making it a high-priority threat for mobile-based traders [Source: https://www.kaspersky.com/blog/sparkkitty-malware-analysis/51545/].
How SparkKitty Steals Seed Phrases
SparkKitty utilizes automated tools to identify and exfiltrate sensitive financial data without manual intervention:
- OCR Integration: On Android, the malware uses Google ML Kit for Optical Character Recognition (OCR) to scan every image in the gallery for text patterns that match 12- or 24-word seed phrases or private keys [Source: https://www.kaspersky.com/blog/sparkkitty-malware-analysis/51545/].
- Real-Time Monitoring: It monitors the device's photo gallery in real-time. When a user takes a new screenshot or saves a photo, the malware immediately checks the content and prepares it for upload to a Command and Control (C2) server [Source: https://www.kaspersky.com/blog/sparkkitty-malware-analysis/51545/].
- Broad Exfiltration: Unlike earlier versions that were more selective, SparkKitty has been observed uploading all accessible photos from a victim's gallery to ensure no sensitive data is missed [Source: https://www.kaspersky.com/blog/sparkkitty-malware-analysis/51545/].
- App Store Infiltration: It has been found embedded in legitimate-looking apps, such as the "币coin" cryptocurrency rate tracker on iOS and messaging apps with exchange features on Android, some of which had over 10,000 installs [Source: https://www.kaspersky.com/blog/sparkkitty-malware-analysis/51545/].
Risk Assessment for Traders
| Feature | Risk Level | Detail |
|---|---|---|
| Distribution | High | Infiltrated official stores; also spreads via trojanized TikTok mods and fake App Store clones [Source: https://www.kaspersky.com/blog/sparkkitty-malware-analysis/51545/]. |
| Targeting | Critical | Specifically targets crypto users by infecting trading signal and tracker apps [Source: https://www.kaspersky.com/blog/sparkkitty-malware-analysis/51545/]. |
| Persistence | High | Uses enterprise provisioning profiles on iOS to bypass standard security restrictions [Source: https://www.kaspersky.com/blog/sparkkitty-malware-analysis/51545/]. |
| Detection | Medium | Obfuscates malicious code within legitimate frameworks like AFNetworking and Alamofire [Source: https://www.kaspersky.com/blog/sparkkitty-malware-analysis/51545/]. |
Critical Safety Recommendations
- Zero-Tolerance for Screenshots: Never take a photo or screenshot of a seed phrase. This is the primary data source for SparkKitty.
- Audit Gallery Permissions: Revoke "All Photos" access for any app that does not strictly require it for its core function.
- Hardware Wallets: Use a hardware wallet (e.g., Ledger, Trezor) so that seed phrases never exist in digital form on a networked device.
- Verify Certificates: On iOS, be wary of apps asking you to "Trust" a developer certificate in Settings, as this is a common infection vector [Note: not independently confirmed - the specific certificate issuer name "SINOPEC SABIC Tianjin Petrochemical Co. Ltd." mentioned in research could not be verified through independent sources].
Conclusion: SparkKitty is a verified threat that automates the theft of seed phrases from photos. Traders should assume any digital image of a seed phrase on a mobile device is compromised if they have downloaded third-party crypto trackers or messaging mods. While the primary research comes from a single major security firm (Kaspersky), the technical details regarding OCR usage and App Store infiltration are highly specific and pose a credible risk.