TLDR
SparkKitty is a mobile spyware campaign that scans your phone photos for wallet recovery phrases using image recognition, making seed screenshots a direct threat to your crypto.
- SparkKitty infects iOS and Android through trojanized apps in major app stores, then uses optical character recognition to scan galleries for wallet seeds, passwords, and QR codes.
- Anyone who has ever stored a recovery phrase as a screenshot or photo is at high risk, because a stolen seed gives attackers full control over the wallet.
- The best defenses are simple: never photograph your seed, tighten photo permissions, avoid untrusted crypto apps, and migrate funds if you suspect your seed has been exposed.
Deep Dive
1. How SparkKitty Operates
Security researchers report that SparkKitty is cross-platform malware distributed via fake or trojanized apps on Apple's App Store, Google Play, and third-party Android stores, including crypto tools and messaging apps such as ?coin and SOEX with over 10,000 downloads before removal. Analyses from Check Point and others show it requests gallery access, then continuously scans existing and new images for text using optical character recognition, exfiltrating wallet recovery phrases, passwords, QR codes and identity documents to attacker-controlled servers. Recent coverage notes SparkKitty as an evolution of earlier OCR-based stealers like SparkCat, with campaigns active since at least 2024 in regions such as Southeast Asia and China. You can see details in this SparkKitty technical summary and this malware report.
Confidence: high because multiple reputable security firms and media have independently analyzed and documented SparkKitty's behavior.
2. Why Seed Screenshots Are So Dangerous
Reports emphasize that SparkKitty's focus on photo libraries specifically targets a common bad habit: storing wallet recovery phrases as screenshots or camera photos. Possession of a seed phrase is equivalent to owning the wallet's private keys, so once malware extracts that phrase from a gallery image, attackers can recreate the wallet on their own device and drain all assets without further interaction from the victim. Unlike keyloggers or clipboard stealers, SparkKitty does not need you to type or copy the seed today; an old screenshot from years ago is enough, which makes long-lived photo archives uniquely risky.
3. Practical Security Moves
- Never store recovery phrases digitally as screenshots, photos, notes, or cloud files; use offline mediums such as paper or metal and keep them physically secure.
- Review app permissions and restrict photo-library access to a minimal set of trusted apps; remove access for messaging, entertainment, or unknown crypto tools.
- If you suspect a seed may have been captured (for example by a malware-infected app), create a new wallet, move funds there, and treat the old seed as permanently compromised.
Even if you use reputable wallets, a single compromised mobile app with gallery access can undermine your entire self-custody setup, so tightening permissions and seed-handling habits is critical.
Conclusion
SparkKitty shows that modern crypto-targeting malware no longer relies only on keystrokes or clipboard monitoring but can mine years of photos for recovery phrases using image recognition. For crypto users, the key takeaway is that mobile convenience and gallery habits can quietly defeat strong wallet technology. Treat your seed phrase as the single point of failure, keep it strictly offline, and regularly audit which apps have access to your photos and files.
