Mercuryo Executive Comments On SparkKitty Malware Attack
SparkKitty is a Trojan horse-type malware hack that targets crypto accounts. While the malware has been around for a couple of years, recent reports about its prevalence on both Google Play and the Apple Store are reminders that consumers must always be diligent – even when using a trusted platform.
As reported in April, attackers created clones of well-known wallets, including MetaMask, Ledger, Trust Wallet, Coinbase, TokenPocket, imToken, Bitpie and more.
In February, a report outlined that AI-powered security services stopped approximately 1.75 million nefarious applications from the Google Play Store. Google has also banned tens of thousands of “developers.”
In May, Apple itself reported that it had stopped more than $2.2 billion in fraudulent transactions during 2025, having rejected over 2 million app submissions. In the past six years, the total amount of potential fraud attempts was around $11.2 billion.
In 2025, Apple detected and blocked 28,000 nefarious apps on bogus storefronts, including malware, porn, gambling apps and attempts to dupe the platform with fake clones.
Check Point shares how SparkKitty hunts for photos stored on a smartphone that may have recovery phrases or other private information.
Ashna Vaghela, Chief Customer Officer at Mercuryo, says that SparkKitty once again highlights the risk for crypto holders when their own devices can be used against them. It does not matter that they have been advised for years not to store recovery phrases or other sensitive information in photo libraries or elsewhere that is not protected.
“If crypto payments and wallets are going to achieve mass adoption, safety has to be built around real behavior, not ideal behavior,” explains Vaghela.
“What is concerning here is the attack path. By using OCR to scan photo libraries for wallet recovery phrases, criminals are exploiting one of the biggest gaps in crypto: the distance between how security is designed and how people actually use their devices. When malicious apps can appear in trusted app store environments, the user is already at a disadvantage before they even make a transaction. Unfortunately, we’re seeing a trend where criminals use platforms that consumers implicitly trust as a means of launching attacks.”
What should be obvious to all is that security must stay ahead of the scammers and their ever-changing tactics to fleece the unsuspecting. Improved wallets, better permissions, real-time fraud monitoring and improved recovery models need to work in the background, says Vaghela.
“Platforms, wallets and payment providers need to build safety into the journey from the outset. That is how the industry reduces avoidable losses and gives consumers the confidence to use digital tokens in the same way that they use everyday financial products.”