Security researchers have uncovered SparkKitty, a malware strain that successfully infiltrated both Apple's App Store and Google Play to harvest cryptocurrency wallet seed phrases from infected devices. The malware operates by scanning photos stored on compromised iPhones and Android phones, searching for images containing recovery phrases.
The attack vector targets a common security practice among crypto holders. Many users photograph their seed phrases as a backup method, storing these critical credentials in their phone's photo library. SparkKitty exploits this behavior by systematically scanning image files and extracting text using optical character recognition or similar techniques to identify wallet recovery codes.
The malware's presence across both major app stores indicates a breach in the security screening processes at Apple and Google. Distribution through official channels rather than sideloading dramatically increases the attack surface, exposing millions of users to infection without obvious red flags. Legitimate-appearing applications masked the malicious functionality during the approval phase.
Wallet seed phrases represent the master keys to cryptocurrency holdings. A compromised seed phrase grants attackers full access to funds on that wallet across multiple blockchains. Unlike passwords, compromised seed phrases cannot be easily changed, making this attack vector particularly devastating for victims.
The discovery highlights the risks of storing sensitive recovery information on internet-connected devices. Security best practices recommend keeping seed phrases offline on paper or other non-digital storage media. Users who may have photographed their phrases on mobile devices should immediately move funds to new wallets generated on secure, offline hardware.
This incident compounds ongoing concerns about malware targeting the cryptocurrency ecosystem. Previous campaigns have disguised themselves as legitimate exchanges, wallet applications, and blockchain tools. The successful placement on mainstream app stores suggests sophisticated social engineering during the submission process, with attackers likely using fake developer accounts and legitimate-appearing app descriptions.
Device owners should audit their recently installed applications, particularly those requesting unusual permissions or claiming blockchain functionality. Security teams at Apple and Google have reportedly removed the malicious applications following the disclosure.
