SparkKitty Malware Spreads in App Stores, Targeting Crypto Wallet Seed Phrases

SparkKitty Malware Found in App Stores Targets Crypto Wallet Seed Phrases
Security researchers have identified a piece of malware dubbed SparkKitty circulating through apps available in official app stores, with functionality aimed at stealing crypto wallet seed phrases.
Seed phrases (also called recovery phrases) are the master keys that allow anyone to restore and take control of a wallet on a new device. If a seed phrase is compromised, attackers can drain funds and the original owner typically has no way to reverse those transfers.
The presence of malware in app stores matters because these platforms are widely trusted distribution channels. Many users assume that apps listed in official stores have been vetted and are safe to install, making app-store distribution an effective way to reach crypto users at scale.
For the crypto ecosystem, incidents like this underscore a recurring security challenge: while blockchains can be resilient, end-user devices and applications remain common points of failure. As more people manage assets via mobile wallets and companion apps, attackers continue to focus on techniques that capture recovery information rather than trying to break cryptographic protections directly.
- What happened: SparkKitty malware was found distributed via app stores.
- What it targets: Crypto wallet seed phrases used to recover wallets.
- Why it matters: Seed phrase theft can result in irreversible loss of funds.
