Hackers Steal Crypto Wallet Seed Phrases from Image Galleries

cryptonews.ruPublicado em 2026-07-27Última atualização em 2026-07-27

Resumo

A new type of malware called SparkKitty is using optical character recognition (OCR) to steal cryptocurrency wallet seed phrases directly from photos and screenshots in a device's gallery, bypassing traditional keylogging defenses. Once installed from malicious apps posing as legitimate crypto services on the Apple App Store and Google Play, it requests photo access, scans images for confidential data like passwords and seeds, and sends it to hackers' servers. Control of a seed phrase gives attackers complete access to drain the wallet. Initially detected as SparkCat, the evolved SparkKitty was found in the iOS app 币coin (hiding in obfuscated code) and the Android app SOEX (downloaded over 10,000 times). This method allows theft even when sensitive data is never typed or copied. The report comes alongside news of other attacks, like a method to hijack Telegram Desktop sessions bypassing 2FA.

After installation, the infected program requests access to photos, scans images for confidential information, and sends the results to remote servers controlled by attackers. SparkKitty does not use traditional data interception methods, such as keylogging or clipboard tracking, but rather optical character recognition (OCR) technology to extract text directly from photos and screenshots. This allows it to bypass standard security systems and steal passwords, seed phrases, and other secret data, even if they are not entered via the keyboard or copied to the clipboard, explained Check Point analysts.

If attackers obtain a seed phrase, they gain full control of the crypto wallet and can empty it in a matter of minutes. The malicious program operates covertly in the background, so the device owner may not immediately notice the theft of funds—until they log into their crypto wallet.

The malicious program was first discovered by Kaspersky experts in early 2024 under the name SparkCat. But now the program has changed. The creators of SparkKitty have started distributing it more frequently in the Apple App Store and Google Play under the guise of applications mimicking legitimate cryptocurrency services, messengers, and entertainment services. This has significantly increased the likelihood of installation by unsuspecting users.

For iOS devices, the malicious program was embedded in the cryptocurrency app "币coin" and uploaded to the App Store. It remains unclear whether the developer account was hacked or if the developer is aware of the infection. The app managed to bypass Apple's security review by hiding malicious code within obfuscated frameworks AFNetworking and libswiftDarwin.dylib. These modules were crafted so that the app appeared legitimate, allowing SparkKitty to evade detection, explained Check Point specialists.

The Android version was distributed through the SOEX app, which was downloaded over 10,000 times from Google Play. The app posed as a messaging and cryptocurrency platform but allowed hackers to access multimedia storage on smartphones and other devices, track file changes, and steal data.

Recently, experts from SlowMist discovered a new method hackers use to intercept Telegram Desktop sessions, bypass two-factor authentication (2FA), and steal crypto wallet data. Recently, the CEO of the financial platform Robinhood, Vlad Tenev, was targeted—his X (formerly Twitter) account was hacked to promote the meme coin VLAD.

Perguntas relacionadas

QWhat is the name of the new malware that steals seed phrases from cryptocurrency wallets using OCR technology?

ASparkKitty

QWhat is the primary technique used by the SparkKitty malware to steal sensitive information, and why is it effective?

AIt uses Optical Character Recognition (OCR) to extract text directly from photos and screenshots. This is effective because it bypasses standard security systems by stealing data that is not typed on a keyboard or copied to the clipboard.

QWhich major app stores are mentioned as distribution channels for the disguised SparkKitty malware?

AApple App Store and Google Play

QWhat was the method used by the iOS version of SparkKitty to hide its malicious code and evade Apple's security checks?

AIt hid the malicious code in obfuscated frameworks, specifically AFNetworking and libswiftDarwin.dylib.

QWhat other recent attack vector, unrelated to SparkKitty, is mentioned where hackers bypassed Telegram Desktop's two-factor authentication?

AExperts from SlowMist discovered a new method hackers use to hijack Telegram Desktop sessions, bypassing two-factor authentication (2FA) to steal cryptocurrency wallet data.

Leituras Relacionadas

In Conversation with Ray Dalio: We Are Currently in an AI Bubble, with 1% of My Portfolio in Bitcoin

Ray Dalio, founder of Bridgewater Associates, warns in an interview that the current AI boom shows classic bubble characteristics, which could lead to significant economic downturns as seen in past cycles like 1929 or 2000. He explains that speculative enthusiasm, fueled by debt and overvaluation, often precedes a crash when rising rates or taxation force asset sales, causing widespread losses and recession. Dalio also outlines his "Big Cycle" theory, describing an approximate 80-year pattern where widening wealth gaps, massive government deficits, and shifting geopolitical power (like China's rise) create internal conflict and global instability. He emphasizes that we are in a late-cycle, transitional phase where traditional powers like the US and UK face decline. For personal wealth protection, Dalio advises diversification beyond cash into assets like stocks, bonds, real estate, and particularly gold, which he prefers over Bitcoin. While he holds about 1% of his portfolio in Bitcoin as a non-printable hard asset, he views gold as more secure from technological or governmental threats. Regarding AI's impact, Dalio believes it will disproportionately benefit capital owners, worsening inequality by replacing both physical and cognitive labor. He suggests that human intuition and emotional intelligence, combined with AI, will be key for future workers. On taxation, Dalio argues that wealth taxes are impractical and risk triggering asset sell-offs, reducing productive investment. He points to the UK as a cautionary example of debt, low productivity, and political strife. Geopolitically, Dalio foresees a more regionalized world, with the US showing weakness in prolonged conflicts like with Iran, akin to past imperial declines. The ideal outcome, he suggests, is coexisting powerful blocs (e.g., Americas, China-Asia Pacific) without major war.

marsbitHá 3h

In Conversation with Ray Dalio: We Are Currently in an AI Bubble, with 1% of My Portfolio in Bitcoin

marsbitHá 3h

Daily 7.2 Trillion KRW: Foreign Capital's Record Net Buying on Friday! Wall Street Says Headwinds for Korean Stock Fund Flows Have Subsided

South Korean stock market sees a dramatic shift in fund flows. On July 31, foreign investors made a record net purchase of approximately KRW 7.2 trillion in KOSPI stocks, marking a fundamental reversal from the persistent large-scale net outflows seen in previous months. This contributed to a significant narrowing of foreign net selling in July to KRW 9.8 trillion, down sharply from KRW 48.4 trillion in June and KRW 44.5 trillion in May. Simultaneously, domestic institutional pressure eased. South Korean pension funds and asset managers turned to a net buying position in July, purchasing KRW 1.0 trillion worth of KOSPI shares, contrasting with net sales in May and June. Market volatility is expected to be dampened by new financial regulations. Effective July 31, the Financial Services Commission tightened access for retail investors to single-stock leveraged ETFs by raising the minimum cash deposit requirement. Trading volumes for these products subsequently dropped to about 50% of their monthly average. Citigroup Research maintains its year-end KOSPI target of 10,000 points. The firm cites several supportive factors: the substantial easing of headwinds from capital outflows, a robust fundamental outlook for the semiconductor sector, historically low market valuations, strong economic fundamentals, and the potential for policy support from financial authorities if needed.

marsbitHá 3h

Daily 7.2 Trillion KRW: Foreign Capital's Record Net Buying on Friday! Wall Street Says Headwinds for Korean Stock Fund Flows Have Subsided

marsbitHá 3h

Thanks to Dice Rolls, Bitcoin Keys Are Stored Offline, But Not Everyone Will Do It

The article discusses using dice rolls to generate secure Bitcoin wallet seeds, providing entropy independent of potentially flawed hardware random number generators. It explains that each fair dice roll offers about 2.585 bits of entropy, with around 50 rolls needed for a standard 12-word seed phrase and 99+ recommended for higher security. This method gained attention after a vulnerability was revealed in some Coldcard hardware wallets, where a faulty firmware RNG (dating back to 2021) compromised generated keys. The analysis notes that while a dice-generated main seed was safe from this specific flaw, other Coldcard functions (like creating paper wallets, backup keys, or passwords) could still be vulnerable if they used the defective RNG. The piece argues that while dice-based entropy is technically robust, the manual process is error-prone, tedious, and unrealistic for most new users, who might make mistakes in recording or inputting rolls. It concludes that while manual entropy generation should remain an option for advanced users, the long-term goal is to develop reliable, user-friendly hardware and software that securely generates randomness without requiring specialized knowledge. Coldcard users are advised to check their firmware version and replace any secondary secrets (like paper wallet keys) created with vulnerable devices, while also considering multi-signature setups with devices from different manufacturers for added security.

cryptonews.ruHá 8h

Thanks to Dice Rolls, Bitcoin Keys Are Stored Offline, But Not Everyone Will Do It

cryptonews.ruHá 8h

Trading

Spot
活动图片