turbonfts

Where digital art meets market reality.

A column by Silas Beckett

News

This malware searches for and steals your crypto recovery phrase

Floor price gets the headlines. SparkKitty gets your wallet. As of this week, a piece of malware first flagged by Check Point has been quietly combing through photo galleries on both iOS and Android…

Silas Beckett, On-Chain Critic & Market Columnist·updated August 02, 2026

This malware searches for and steals your crypto recovery phrase

Floor price gets the headlines. SparkKitty gets your wallet. As of this week, a piece of malware first flagged by Check Point has been quietly combing through photo galleries on both iOS and Android, using OCR to hunt for the one image that empties a collector out: a screenshot of a 12- or 24-word seed phrase. The infection rode into Google Play inside an app called SOEX — a "messaging and trading" wrapper that pulled in more than 10,000 downloads before it was yanked. Apple's App Store hosted its own variant, dressed up as a crypto tracker called coin. Both stores, both platforms, both pipelines straight to the same drain.

The mechanic is embarrassingly simple

SparkKitty doesn't need you to type anything in. Grant it photo access once at install and it scans every existing image on the device, plus anything new you snap, looking for recovery phrases, passwords, and QR codes. It ships the match back to attacker-controlled servers along with basic device metadata. You don't even have to open the app again. The thing just keeps chewing.

That's the whole trick. No clipboard hijack, no fake transaction popup, no clever phish. It automates what any human thief with access to your camera roll would do by hand — except it never sleeps. And for anyone who screenshotted a seed phrase in 2021 because the wallet UI made it inconvenient to write down and never bothered to delete it, that old photo is still sitting there like a loaded gun.

The distribution is the real tell

Sideloaded TikTok clones. Gambling apps. Random "crypto tools" pushed outside the official stores. This is the threat surface we've been warning about since hardware wallets became a meme: the app layer is the soft underbelly of self-custody. You can run a Ledger, you can sign everything through a squeaky-clean hot wallet, and still lose the lot because three years ago you saved a screenshot of your seed to iCloud and forgot.

There is no on-device scanner for SparkKitty yet. The practical signals worth watching: unfamiliar apps holding broad photo permissions, unexplained battery drain, wallet balances that move without your signature. Any one of those is a red.

What we actually do

Audit your camera roll right now. Delete every seed phrase screenshot, every wallet backup image, every QR of a private key — and check your cloud backups too, because iCloud and Google Photos will cheerfully sync that screenshot to every device you own. Move the phrase itself to a hardware wallet or a piece of paper you keep somewhere physical, not digital, and never photographed.

Revoke photo access from any installed app that doesn't genuinely need it. Stick to established names for crypto, messaging, and trading tooling. Skip sideloads. If a balance moves without explanation, take the device offline immediately, sweep the remaining funds to a clean device, and rotate every password tied to the affected wallet.

One footnote for the long game: collecting is one thing, but the only wealth that survives contact with actors like these is wealth you actually intend to protect. Real functional wealth starts with custody discipline — the boring infrastructure that keeps the interesting parts standing.