Hackers Steal Crypto Wallet Seed Phrases from Image Galleries

cryptonews.ru2026-07-27 tarihinde yayınlandı2026-07-27 tarihinde güncellendi

Özet

A new type of malware called SparkKitty is using optical character recognition (OCR) to steal cryptocurrency wallet seed phrases directly from photos and screenshots in a device's gallery, bypassing traditional keylogging defenses. Once installed from malicious apps posing as legitimate crypto services on the Apple App Store and Google Play, it requests photo access, scans images for confidential data like passwords and seeds, and sends it to hackers' servers. Control of a seed phrase gives attackers complete access to drain the wallet. Initially detected as SparkCat, the evolved SparkKitty was found in the iOS app 币coin (hiding in obfuscated code) and the Android app SOEX (downloaded over 10,000 times). This method allows theft even when sensitive data is never typed or copied. The report comes alongside news of other attacks, like a method to hijack Telegram Desktop sessions bypassing 2FA.

After installation, the infected program requests access to photos, scans images for confidential information, and sends the results to remote servers controlled by attackers. SparkKitty does not use traditional data interception methods, such as keylogging or clipboard tracking, but rather optical character recognition (OCR) technology to extract text directly from photos and screenshots. This allows it to bypass standard security systems and steal passwords, seed phrases, and other secret data, even if they are not entered via the keyboard or copied to the clipboard, explained Check Point analysts.

If attackers obtain a seed phrase, they gain full control of the crypto wallet and can empty it in a matter of minutes. The malicious program operates covertly in the background, so the device owner may not immediately notice the theft of funds—until they log into their crypto wallet.

The malicious program was first discovered by Kaspersky experts in early 2024 under the name SparkCat. But now the program has changed. The creators of SparkKitty have started distributing it more frequently in the Apple App Store and Google Play under the guise of applications mimicking legitimate cryptocurrency services, messengers, and entertainment services. This has significantly increased the likelihood of installation by unsuspecting users.

For iOS devices, the malicious program was embedded in the cryptocurrency app "币coin" and uploaded to the App Store. It remains unclear whether the developer account was hacked or if the developer is aware of the infection. The app managed to bypass Apple's security review by hiding malicious code within obfuscated frameworks AFNetworking and libswiftDarwin.dylib. These modules were crafted so that the app appeared legitimate, allowing SparkKitty to evade detection, explained Check Point specialists.

The Android version was distributed through the SOEX app, which was downloaded over 10,000 times from Google Play. The app posed as a messaging and cryptocurrency platform but allowed hackers to access multimedia storage on smartphones and other devices, track file changes, and steal data.

Recently, experts from SlowMist discovered a new method hackers use to intercept Telegram Desktop sessions, bypass two-factor authentication (2FA), and steal crypto wallet data. Recently, the CEO of the financial platform Robinhood, Vlad Tenev, was targeted—his X (formerly Twitter) account was hacked to promote the meme coin VLAD.

İlgili Sorular

QWhat is the name of the new malware that steals seed phrases from cryptocurrency wallets using OCR technology?

ASparkKitty

QWhat is the primary technique used by the SparkKitty malware to steal sensitive information, and why is it effective?

AIt uses Optical Character Recognition (OCR) to extract text directly from photos and screenshots. This is effective because it bypasses standard security systems by stealing data that is not typed on a keyboard or copied to the clipboard.

QWhich major app stores are mentioned as distribution channels for the disguised SparkKitty malware?

AApple App Store and Google Play

QWhat was the method used by the iOS version of SparkKitty to hide its malicious code and evade Apple's security checks?

AIt hid the malicious code in obfuscated frameworks, specifically AFNetworking and libswiftDarwin.dylib.

QWhat other recent attack vector, unrelated to SparkKitty, is mentioned where hackers bypassed Telegram Desktop's two-factor authentication?

AExperts from SlowMist discovered a new method hackers use to hijack Telegram Desktop sessions, bypassing two-factor authentication (2FA) to steal cryptocurrency wallet data.

İlgili Okumalar

Crypto.com, Backed by Citadel Securities, Transfers XYO and XL1 into Regulated Custody

Crypto.com, with backing from Citadel Securities, has placed XYO and XL1 tokens into regulated custody. This move provides eligible institutions and high-net-worth clients with a regulated mechanism for storing, managing, and exchanging these tokens without first having to transfer assets onto an exchange. The custody structure utilizes segregated MPC wallets managed by a bankruptcy-remote entity, with private keys secured via multi-party computation. Clients benefit from cold storage, audit trails, and direct access to Crypto.com's institutional liquidity while their assets are custodied, removing the operational step of pre-trade transfers. Company leadership positioned this as a strategic step to provide "unmatched security and seamless liquidity" for digital asset organizations, and to protect and scale the XYO ecosystem. The partnership builds on an existing relationship since XYO's initial listing on the exchange. This development follows Citadel Securities' $400 million investment in Crypto.com and comes as the company expands its regulatory standing, having received conditional approval to establish a national trust bank. For institutional investors, this custody agreement addresses a key barrier by demonstrating that smaller market-cap assets like XYO and XL1 can be held under the same regulatory and security standards as larger tokens. XYO operates a large DePIN network generating real-world data for AI and robotics, with XL1 handling its blockchain transactions and infrastructure.

cryptonews.ru1 saat önce

Crypto.com, Backed by Citadel Securities, Transfers XYO and XL1 into Regulated Custody

cryptonews.ru1 saat önce

Less Than Two Weeks Left — Bitcoin's BIP-110 Countdown Begins as Miner Support Grows Ahead of Decisive Moment

The BIP-110 activation process for Bitcoin, which proposes a temporary soft fork to limit specific data-heavy transaction types (like Ordinals inscriptions), is entering its critical final phase. As of July 27, 2026, there are roughly 1,790 blocks remaining until the mandatory signaling window begins at block 961,632 (estimated for August 9). Starting then, nodes enforcing BIP-110 will reject blocks not signaling for the proposal. While support from miners has grown from below 1% to around 3% recently, it remains concentrated among smaller pools and independent miners, with major pools like Foundry, Antpool, ViaBTC, and F2Pool largely not signaling. Foundry's stance is particularly decisive, as it holds a large share of the network's hashrate and has tied its signaling to a client vote. Without a major pool's shift, widespread activation is unlikely. If the current low signaling levels persist after the window opens, nodes enforcing BIP-110 will follow a slower, minority chain, potentially creating a chain split from the majority chain followed by legacy (e.g., Bitcoin Core) nodes. This activation mechanism differs from past soft forks like SegWit, resembling the 2017 UASF BIP-148 more closely. Proponents argue BIP-110 is necessary to curb spam-like data transactions that increase node costs and distort fee markets, framing opposition as a contentious hard fork. Critics, however, view the activation method as a radical overreaction to a minor issue. The final outcome in the coming two weeks hinges on whether a major pool switches support, if major exchanges clarify their chain preference, and how miners actually behave once the mandatory window is open.

cryptonews.ru1 saat önce

Less Than Two Weeks Left — Bitcoin's BIP-110 Countdown Begins as Miner Support Grows Ahead of Decisive Moment

cryptonews.ru1 saat önce

İşlemler

Spot
活动图片