
CoinMarketCap’s July 28, 2026 warning underscores how SparkKitty’s image-scanning theft method can quietly expose self-custody wallets when users store recovery phrases in phone screenshots.
SparkKitty, a mobile malware campaign first disclosed by Kaspersky in June 2025, is drawing renewed scrutiny after CoinMarketCap on July 28, 2026 highlighted how the malware can steal cryptocurrency by scanning phone photo galleries for screenshots of wallet recovery phrases rather than attacking wallet apps directly. Earlier analysis from Check Point detailed how the spyware spread through Apple’s App Store, Google Play and third-party app stores in trojanized apps posing as crypto tools, messaging platforms and entertainment products, including the iOS app "币coin" and the Android messaging and crypto exchange app SOEX, which was downloaded more than 10,000 times from Google Play before removal. Once users granted photo-library access, SparkKitty could search stored images, use text recognition to identify phrase-like patterns and upload matches to attacker-controlled servers. Because a 12- or 24-word recovery phrase can fully restore a self-custody wallet, a screenshotted phrase can give an attacker complete control of the funds without further hacking. Researchers and security guidance tied to the warning say users should delete any existing phrase screenshots, empty deleted-image folders, check cloud backups, treat any photographed recovery phrase as compromised by rotating to a new wallet, and revoke unnecessary photo access for apps.