- SparkKitty malware scans photos for crypto wallet recovery phrases.
- The malware was found in apps on both the App Store and Google Play.
- Users storing seed phrases as screenshots are at the highest risk.
Security researchers have uncovered SparkKitty, a new cross-platform malware family that targets cryptocurrency users by scanning photos stored on infected devices for wallet recovery phrases.
Unlike traditional malware that monitors keyboards or clipboards, SparkKitty uses optical character recognition (OCR) to search images for sensitive information, including seed phrases, passwords and QR codes. Any detected data is then sent to attacker-controlled servers.
Researchers found the malware hidden inside seemingly legitimate crypto, messaging and entertainment apps distributed through both Apple's App Store, Google Play, and third-party Android app stores. One infected Android application reportedly surpassed 10,000 downloads before being removed.
Security experts warn that users who save their wallet recovery phrases as screenshots or photos are the most vulnerable, since anyone with access to a seed phrase can fully control the associated crypto wallet.
To stay protected, users should store recovery phrases offline, avoid saving them in their photo gallery, only install apps from trusted developers, and carefully review app permissions before granting access to photos or other sensitive data.