Go to app

How SparkKitty Steals Seed Phrases

Published 7/27/2026, 2:59:15 PM

Traders should be significantly concerned about SparkKitty, a sophisticated malware strain specifically designed to steal cryptocurrency seed phrases and private keys from device photo galleries. Discovered by security researchers in June 2025, the malware has successfully bypassed security filters on both the Apple App Store and Google Play Store, making it a high-priority threat for mobile-based traders [Source: https://www.kaspersky.com/blog/sparkkitty-malware-analysis/51545/].

How SparkKitty Steals Seed Phrases

SparkKitty utilizes automated tools to identify and exfiltrate sensitive financial data without manual intervention:

Risk Assessment for Traders

FeatureRisk LevelDetail
DistributionHighInfiltrated official stores; also spreads via trojanized TikTok mods and fake App Store clones [Source: https://www.kaspersky.com/blog/sparkkitty-malware-analysis/51545/].
TargetingCriticalSpecifically targets crypto users by infecting trading signal and tracker apps [Source: https://www.kaspersky.com/blog/sparkkitty-malware-analysis/51545/].
PersistenceHighUses enterprise provisioning profiles on iOS to bypass standard security restrictions [Source: https://www.kaspersky.com/blog/sparkkitty-malware-analysis/51545/].
DetectionMediumObfuscates malicious code within legitimate frameworks like AFNetworking and Alamofire [Source: https://www.kaspersky.com/blog/sparkkitty-malware-analysis/51545/].

Critical Safety Recommendations

  1. Zero-Tolerance for Screenshots: Never take a photo or screenshot of a seed phrase. This is the primary data source for SparkKitty.
  2. Audit Gallery Permissions: Revoke "All Photos" access for any app that does not strictly require it for its core function.
  3. Hardware Wallets: Use a hardware wallet (e.g., Ledger, Trezor) so that seed phrases never exist in digital form on a networked device.
  4. Verify Certificates: On iOS, be wary of apps asking you to "Trust" a developer certificate in Settings, as this is a common infection vector [Note: not independently confirmed - the specific certificate issuer name "SINOPEC SABIC Tianjin Petrochemical Co. Ltd." mentioned in research could not be verified through independent sources].

Conclusion: SparkKitty is a verified threat that automates the theft of seed phrases from photos. Traders should assume any digital image of a seed phrase on a mobile device is compromised if they have downloaded third-party crypto trackers or messaging mods. While the primary research comes from a single major security firm (Kaspersky), the technical details regarding OCR usage and App Store infiltration are highly specific and pose a credible risk.