Wallet safety / Updated 2026-08-20
The Screenshot You Forgot About: How Photo-Stealing Malware Reads a Seed Phrase Out of Your Camera Roll
Malware that reads text out of images has shipped inside App Store and Google Play apps, hunting photo galleries for recovery phrases. Why deleting the picture is not enough, and what to do instead.
How this guide is checked
Official sources first, no wallet connection, no guaranteed returns.
Reviewed on 2026-08-20 by WildWildCrypto Safety Desk. Method: Human editorial review with official-source checks, affiliate-disclosure checks, and no-financial-advice checks.
Publisher: WildWildCrypto Editorial. Corrections go through the contact page. We do not ask for seed phrases or tell you what to buy.
seed phrase screenshot malware matters because At some point, setting up a wallet under time pressure, a lot of people photograph the twelve or twenty-four words — just to be safe, just until the paper copy is written properly — and then life continues and the photo stays where it landed.
This guide explains why a phone gallery is a searchable text archive rather than a pile of pictures, shows the malware that has already been caught reading galleries inside both official app stores, and gives you a clear decision about a photo that already exists.
You will learn how optical character recognition turns a screenshot into a machine-readable secret, what the SparkCat and SparkKitty campaigns did and where they were distributed, why deletion does not undo exposure, the photo permission that actually narrows the risk, and the migration decision worth making calmly rather than after a loss.
Your photo library is a text archive, not a pile of pictures
Think about how you find an old photo now. You do not scroll; you type. Search your gallery for a word printed on a receipt, a street sign, or a whiteboard, and the picture surfaces. That works because the phone has already run optical character recognition across your images and indexed the words it found. It is a genuinely useful feature, and most people use it without ever thinking about what it implies: the text inside your photographs is not locked in the image, it has been extracted, and reading it requires no special skill or equipment.
That capability is not reserved for the operating system. The same optical character recognition libraries are freely available to any developer, and any app you grant photo access to can run them over everything it can see. So a screenshot of a recovery phrase is not really a picture of some words. It is a machine-readable secret, sitting in a store that dozens of ordinary apps routinely ask permission to read, usually mirrored to a cloud service within minutes of being taken. Written on paper, a phrase is a physical object in one place that a thief has to find. Photographed, it becomes a string that software can locate by searching for it — and software can search every image on the device in the time it takes to open a menu.
Checklist
- Modern phones already extract and index the text inside your photos.
- The same optical character recognition tools are available to any app.
- A photographed phrase is machine-searchable, not merely visible.
- Gallery images are usually mirrored to cloud storage automatically.
- Paper has one location; a photo has as many copies as your sync settings allow.
The malware that got into both official app stores
This is not a theoretical risk, and the reason to name the specific campaigns is that they answer the objection most people reach for. In early 2025, Kaspersky's researchers published an analysis of a malicious framework they called SparkCat, which had been embedded in apps distributed through Google Play and Apple's App Store. It used Google's ML Kit optical character recognition library to scan images in the device gallery, searching for words associated with wallet recovery phrases in Chinese, Japanese, Korean, English, Czech, French, Italian, Polish and Portuguese, and uploaded matching images to servers the attackers controlled. Infected apps on Google Play had accumulated more than 242,000 downloads. The carriers were ordinary software — a food delivery app, messaging apps — not crypto tools, so nothing about installing them felt like a crypto decision.
A related campaign, which Kaspersky named SparkKitty and linked to SparkCat through shared infected apps, identical Android frameworks and matching debug paths, was documented in mid-2025 and had been active since at least February 2024. It also reached both stores, using enterprise provisioning profiles on iOS to get around App Store restrictions, and one messaging app carrying it passed 10,000 installations on Google Play before removal. Some Android variants were selective rather than greedy: instead of exfiltrating every image, they used optical character recognition to keep only pictures containing blocks of text, which is a filter designed to find documents and screenshots in a camera roll full of holidays and food. Kaspersky recorded that the campaign primarily targeted users in Southeast Asia and China, and that regional focus is worth stating plainly rather than glossing — but the technique carries no geographic limit, and store review demonstrably did not stop it in either ecosystem.
Checklist
- SparkCat: optical character recognition stealer found in Google Play and the App Store.
- Over 242,000 downloads across infected Google Play apps.
- Recovery-phrase keywords targeted across nine languages.
- SparkKitty: linked campaign, active since at least February 2024, both stores again.
- Carriers were ordinary apps — delivery, messaging, games — not crypto apps.
- Some variants filtered for images containing text, to find documents efficiently.
- Kaspersky observed a Southeast Asia and China focus; the method is not region-locked.
Why deleting the photo does not undo it
The instinct on reading the above is to open the gallery and delete. Do that, but understand what it does and does not achieve. Deletion on a phone is usually delayed rather than immediate: the image typically moves to a recently-deleted album and lingers there for around a month. If the gallery syncs to a cloud service, a copy exists there and may persist through its own retention window. Device backups taken while the photo existed still contain it. If the phrase was ever sent to anyone — a partner, yourself, a note-taking app — a copy sits on the recipient's device and on the provider's servers, entirely outside your control. And an older phone in a drawer holds whatever it held on the day you stopped using it.
The deeper problem is not copies, though. It is that you cannot prove a negative. If a photograph of your phrase existed on a device for a period during which you installed apps, you have no way to establish that nothing read it, because a successful read leaves no trace on your side — no notification, no failed login, no unusual battery drain. Ordinary secrets survive this uncertainty because they can be rotated: a password that might have leaked is simply changed, and the old one becomes worthless. A recovery phrase has no equivalent. Ledger's own guidance is blunt about the phrase being the thing that controls the funds, and that is exactly why it cannot be reset — the words are not a credential checked by a company, they are the key itself. The only rotation available is to generate a new wallet and move the assets, which makes the old phrase harmless because it now controls nothing.
Checklist
- Deleted photos usually sit in a recently-deleted album for around 30 days.
- Cloud sync and device backups keep independent copies.
- Anything sent in a chat exists on the other device and the provider's servers.
- Old phones retain whatever they held when you stopped using them.
- A successful theft of the image leaves no visible symptom.
- Passwords can be rotated; a recovery phrase cannot.
- The only true rotation is a new wallet with the funds moved across.
The permission setting that actually narrows the door
Once the phrase is out of your gallery, the useful hardening is to stop granting apps a view of the whole library by default. Both platforms have built this in. Apple documents the controls under Settings, then Privacy and Security, where you can select a category such as Photos, see the list of apps that requested access, and change what each one has — including sharing only selected photos rather than the entire library. Android has moved the same way with its photo picker, which the developer documentation describes as a way to grant an app access to only selected images and videos, instead of the entire media library. Choosing selected access is the difference between an app being handed a filing cabinet and being handed one document.
It is worth being honest about the limits of this. The apps in these campaigns did not need to look suspicious, because a delivery app asking for photo access to attach a picture to a review is an entirely normal request, and users granted it for normal reasons. So the durable control is not learning to spot bad apps by intuition, which is a game you will eventually lose, but reducing what a granted permission is worth. Audit the list occasionally and ask a narrow question of each entry — does this app need my whole library, or does it need one picture at a time? Almost everything belongs in the second category. And the strongest version of this control does not depend on any setting at all: if no image of the phrase exists anywhere, then full library access reveals nothing worth taking.
Checklist
- iPhone: Settings, then Privacy and Security, then Photos, per app.
- Choose selected photos rather than full library access wherever offered.
- Android: the photo picker grants access to chosen items, not the whole library.
- Malicious carriers looked normal; permission requests looked reasonable.
- Audit granted photo access periodically and downgrade what does not need it.
- The best protection is having nothing in the library worth finding.
What to do if you have already photographed a phrase
Make this decision calmly now rather than under pressure later, and size it to what is actually at stake. If the phrase controls an amount you would find painful to lose, treat a photograph that existed on an internet-connected phone as an exposure and migrate to a new wallet. That is not a dramatic reaction; it is the only action that resolves the uncertainty, because every other option leaves you hoping. If the wallet holds a trivial amount and you would shrug at losing it, cleaning up and monitoring is a defensible choice — just make it deliberately, and do not let today's trivial wallet quietly become next year's main one.
The migration itself is ordinary work, done in order. Generate a new wallet on a device you trust, and record the new phrase offline on something durable — paper is fine to start, metal survives fire and water, and a purpose-made backup plate exists for exactly this job. Verify the backup before it matters, by restoring from it on the same device and confirming the addresses match. Send a small test amount to the new wallet and confirm it arrives and can be spent. Then move the rest, and only then treat the old phrase as retired. Afterwards, scrub the image everywhere it might live: the gallery, the recently-deleted album, cloud storage, old backups and any chat you sent it to. Two cautions worth carrying through this. Do not type the old phrase into any website, tool or app offering to check whether it is compromised, because that is itself one of the oldest thefts in the field. And if a message arrives offering help with your migration, from support you did not contact, that is the fake help desk pattern our guide on unsolicited support contacts covers — real support answers channels you opened. Finally, keep a note of what you moved and when, since transfers between wallets you own still matter for the records our crypto tax recordkeeping guide walks through.
Checklist
- Material amount plus a photo that existed on a connected phone: migrate.
- Trivial amount: clean up and monitor, but decide it deliberately.
- Generate the new phrase on a device you trust; record it offline.
- Verify the backup by restoring from it before funding anything.
- Send a small test amount, confirm receipt, then move the balance.
- Scrub the image from gallery, recently-deleted, cloud, backups and chats.
- Never type a phrase into a tool that offers to check it for compromise.
- Expect a fake support approach; real support does not contact you first.
- Log the transfers for your own records.
Authority sources used
Outbound links are included for verification and entity authority, not decoration.
- SparkCat: a stealer in the App Store and Google PlaySecurelist by Kaspersky
- SparkKitty: a new Trojan spy found in the App Store and Google PlaySecurelist by Kaspersky
- Control access to information in apps on iPhoneApple Support
- Photo pickerAndroid Developers
- What is a Secret Recovery Phrase and how to keep it safeLedger Academy
FAQ
Is it really unsafe to keep a photo of my recovery phrase in a private album?
Yes, and the reason is more mechanical than most warnings suggest. A private or hidden album is a display preference within the photo library rather than a separate encrypted store, so an app granted access to your photos can generally still see what is inside it. More importantly, the words in that image are not protected by being an image. Modern phones run optical character recognition across your gallery so you can search photos by the text in them, and the same libraries are available to any developer — Kaspersky documented malware using Google's ML Kit optical character recognition to scan galleries specifically for recovery-phrase wording across nine languages. That means a screenshot is not a picture of a secret; it is a machine-searchable copy of one, held in a location that ordinary apps routinely ask to read and that usually syncs to cloud storage automatically. A paper backup has one location and has to be physically found. A photographed phrase can be located by software that searches for it, which is a completely different risk profile and the reason the rule exists.
I deleted the screenshot. Am I safe now?
Deleting is worth doing, but it addresses only future access and not past access. On most phones deletion is delayed rather than immediate, with the image sitting in a recently-deleted album for roughly a month; if your gallery syncs to a cloud service, a copy lives there under its own retention rules; device backups taken while the photo existed still contain it; anything you sent to another person or to yourself in a chat exists on their device and on the provider's servers; and an old phone in a drawer holds whatever it held when you stopped using it. Beyond copies, there is the harder problem: a successful read of that image leaves no trace you can observe — no alert, no failed login, nothing unusual. You cannot demonstrate that nothing took it. An ordinary secret survives that uncertainty because you can rotate it, but a recovery phrase is not a credential a company checks, it is the key itself, so there is nothing to reset. The only genuine rotation is to generate a new wallet and move the funds, after which the old phrase controls nothing and its exposure stops mattering.
Does only installing apps from the App Store or Google Play protect me?
It reduces your exposure meaningfully, and it is not sufficient on its own, which is precisely what these cases demonstrate. Kaspersky's analysis of the SparkCat framework found it inside apps distributed through both Google Play and Apple's App Store, with infected Google Play apps accumulating more than 242,000 downloads between them. The related SparkKitty campaign reached both stores as well, using enterprise provisioning profiles on iOS to work around App Store restrictions, and one messaging app carrying it passed 10,000 installations on Google Play before it was removed. The apps involved were not crypto tools that a cautious person would scrutinise — a food delivery app, messaging apps, games, TikTok modifications — so installing them never felt like a decision about wallet security. Store review is a filter, not a guarantee, and treating it as a guarantee is what makes the gallery worth targeting. Keep installing from official stores, and stop relying on that alone by removing the thing worth stealing and narrowing what photo access is worth.
How do I stop apps from reading my entire photo library?
Both platforms let you scope this, and the setting is worth changing as a default rather than case by case. On iPhone, Apple documents the controls under Settings, then Privacy and Security, where you can open a category such as Photos, see every app that requested access, and adjust each one — including granting access to selected photos only rather than the whole library. On Android, the system photo picker serves the same purpose; the developer documentation describes it as a built-in way for users to grant an app access to only selected images and videos, instead of their entire media library. The practical habit is to audit that list occasionally and ask one question of each app: does it need the library, or does it need one picture at a time? Almost everything belongs in the second group. Bear in mind that the malicious apps in these campaigns did not look suspicious and their permission requests looked reasonable, so the point is not to get better at spotting bad apps but to make a granted permission worth less.
I photographed my phrase years ago and nothing has happened. Do I still need to move my funds?
Time without incident is weaker evidence than it feels, because there is no symptom to have noticed. Someone holding a copy of your phrase has no reason to act on a schedule, and images collected by these campaigns were uploaded to servers where they can sit indefinitely before anyone gets to them. So the honest framing is not whether anything has happened but whether you can accept the outstanding risk, and that turns on the amount. If the wallet holds a sum you would find painful to lose, migrating to a newly generated wallet is the only action that actually ends the uncertainty, and it costs you a transaction fee and an afternoon. If the balance is trivial and you would genuinely shrug at losing it, cleaning up and keeping an eye on it is defensible — but decide that consciously, and revisit it if the balance grows, because the most common version of this mistake is a wallet that was unimportant when the photo was taken and is not unimportant any more.