XRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · GreedXRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · Greed
Home / Markets
● Markets

Malware Campaign Exploits Major App Stores to Steal Crypto Wallet Recovery Phrases

A sophisticated threat called SparkKitty bypassed security reviews on Apple and Google app stores to distribute malware that scanned users' photos for cryptocurrency wallet seed phrases.

JM
by Jacob Marquez · Markets Desk
Published July 27, 2026 · 2 min read

Widespread Distribution Through Trusted Platforms

According to cybersecurity firm Check Point, the SparkKitty malware operation successfully infiltrated both Apple’s App Store and Google Play, distributing trojaned applications disguised as legitimate cryptocurrency tools, messaging platforms, and entertainment services. Kaspersky initially identified the threat in June 2025, but Check Point’s analysis revealed the full scope of the campaign. The strategy of masquerading as trusted applications significantly increased the likelihood that unsuspecting users would install the malware before discovering its true nature.

How the Attack Targeted Wallet Security

Once installed, the malware requested permission to access users’ photo libraries and then systematically scanned stored images for wallet recovery phrases and other sensitive data. The harvested information was transmitted to attacker-controlled servers for exploitation. On iOS devices, SparkKitty was distributed through an app called “币coin,” which successfully evaded Apple’s review process by concealing its malicious code. Android users encountered the threat through SOEX, a messaging and cryptocurrency exchange application that accumulated more than 10,000 downloads from Google Play before removal. Additional versions spread through third-party app stores, counterfeit TikTok applications, gambling platforms, and sideloaded installation packages.

The malware’s approach of directly searching photo libraries distinguished it from conventional information-stealing techniques that rely on clipboard monitoring or keylogging, making visual documentation of seed phrases an especially vulnerable storage method.

Critical Lessons for Crypto Users

Security researchers emphasize that cryptocurrency holders should never store wallet recovery phrases as digital screenshots. Instead, users should maintain these phrases exclusively offline, restrict photo library access to essential applications only, and download software exclusively from reputable developers with verified track records. The SparkKitty campaign reflects a troubling pattern of escalating threats to cryptocurrency users beyond protocol-level vulnerabilities. Earlier in the year, the DarkSword exploit chain deployed Ghostblade malware capable of targeting major cryptocurrency exchanges and wallet applications while harvesting messages, passwords, and sensitive data from compromised iPhones. The FBI also investigated malicious games distributed through Steam, including titles such as “Chemia,” “PirateFi,” and “Tokenova,” which installed malware on user systems.

The incident underscores how security threats targeting cryptocurrency users now extend across multiple attack vectors, requiring vigilance at every level from device security to storage practices. This matters for the crypto market because compromised user assets reduce confidence in cryptocurrency adoption and highlight the importance of combining blockchain security with personal operational security.

Source: Check Point, via Decrypt. Not financial advice.

// DISCLAIMER: This article is for informational purposes only and is not financial, investment, or trading advice. Terminalcraft may earn a commission from affiliate links. Crypto is volatile and high-risk. Always do your own research.
JM

Jacob Marquez — Markets Desk

Jacob Marquez is the founder and editor of Terminalcraft, an independent XRP-first crypto news desk. An XRP holder and market watcher since 2016, he started Terminalcraft to deliver fast, factual crypto news without the hype.