Security Hub

SparkKitty Malware Scans Phone Galleries for Seed Phrase Screenshots

Published: Jul 28, 2026By Aleksandar Dukic

Key Analysis

A new malware strain called SparkKitty scans crypto holders' photo galleries for seed phrase screenshots. Here is how it works and how to shut it out.

SparkKitty Malware Scans Phone Galleries for Seed Phrase Screenshots

Listen To This Article

SparkKitty Malware Scans Phone Galleries for Seed Phrase Screenshots

4m 24s audio

AI narration. Useful for scanning on the move. Names and tickers may be mispronounced.

Security researchers have flagged a new malware strain called SparkKitty that goes after crypto holders in an unusually direct way. Instead of trying to break into a wallet app, it scans the images saved on a victim's phone, looking for screenshots of wallet recovery phrases. The warning was shared by CoinMarketCap on July 28, 2026, citing researchers tracking the campaign.

The approach works because of a habit that is far more common than most people admit. When someone sets up a self-custody wallet, the app shows a 12 or 24 word recovery phrase and tells the user to write it down. Writing it down is slower than tapping the screenshot button, so a large share of users just capture the screen and move on. That screenshot then sits in the camera roll indefinitely, syncing to cloud backups and staying readable to any app granted photo access.

The attack skips the wallet entirely

Most wallet-draining malware tries to intercept transactions, swap clipboard addresses, or phish a login. SparkKitty does none of that. It treats the photo gallery as the vault. A recovery phrase is the master key to a self-custody wallet: anyone who holds those words can restore the wallet on their own device and move every asset out, no password or app access required. If that phrase is sitting in a screenshot, the malware does not need to defeat any security at all. It just needs to read your pictures.

Image-scanning is also harder to notice than active transaction tampering. Photo library permission is something people grant to dozens of apps without thinking, from messengers to shopping tools. Once granted, the malware can quietly comb through images, run text recognition to spot phrase-like patterns, and ship matches to a remote server. Nothing on screen suggests a wallet is under threat until the funds are already gone.

Screenshots turn a strength into a weakness

Self-custody is meant to remove the counterparty risk that comes with leaving funds on an exchange or with a custodial provider. The trade-off is that you become fully responsible for the keys. A screenshot quietly undoes that trade-off. It converts an offline secret, meant to live on paper in a drawer, into a networked file that travels through cloud sync and sits behind whatever permissions your phone hands out.

The same logic applies to photos of anything sensitive: exchange 2FA backup codes, private keys exported as QR images, or a note-app entry with a password. SparkKitty is built to hunt recovery phrases, but the underlying lesson covers any secret you have ever captured with a camera. This is one area where spending from your own wallet demands more discipline than a custodial setup, where the provider holds the keys and there is no phrase for malware to steal in the first place.

Closing the gap

The defensive steps are unglamorous and effective. Delete any existing screenshots of a recovery phrase, then empty the deleted-items folder and check whether the image already synced to a cloud backup. If a phrase has ever been screenshotted, treat it as compromised: create a new wallet, move funds to it, and write the fresh phrase on paper only. Audit which apps have photo library access and revoke it for anything that does not genuinely need it.

For new wallets, break the habit at the source. Write the phrase down by hand, store a second copy in a separate physical location, and never let the words touch a camera, a cloud note, or a messaging app. Hardware wallets and phones with a dedicated secure element raise the bar further, but they do not help if the phrase already leaked into a photo gallery years ago.

SparkKitty is a reminder that attackers follow the path of least resistance. The weakest point in most self-custody setups is not the cryptography. It is the copy of the keys the user made for convenience and then forgot about.

Overview

SparkKitty is a malware strain that scans phone photo galleries for screenshots of crypto wallet seed phrases rather than attacking wallet apps directly, per a July 28, 2026 warning from CoinMarketCap. A screenshotted recovery phrase gives an attacker full control of a self-custody wallet with no further hacking needed. The fix is to delete any phrase screenshots, treat them as compromised by rotating to a new wallet, revoke unnecessary photo permissions, and store recovery phrases on paper only.

DisclaimerThis article is provided for informational purposes only and does not constitute financial advice. All fee, limit, and reward data is based on issuer-published documentation as of the date of verification.

Have a question or update?

Discuss this analysis with the community on X.

Discuss on X

Comments

Comments are moderated and may take a moment to appear.