Lookonchain APP

App Store

SparkKitty malware has infiltrated Apple and Google’s app stores, and is specifically designed to steal cryptocurrency wallet mnemonic phrases.

22 hours ago

According to Check Point, cross-platform malware named SparkKitty has spread through Apple App Store, Google Play, and third-party Android app stores. The malware uses OCR (Optical Character Recognition) technology to scan images in users’ photo albums, targeting sensitive data including cryptocurrency wallet mnemonics, passwords, and QR codes. The report notes that SparkKitty is an upgraded iteration of the earlier information-stealing program SparkCat, disguised as apps such as crypto services, communication tools, and entertainment platforms for distribution. Once installed, the app requests photo album access permission, continuously scans existing and new images, and uploads the extracted text plus device information to the attacker’s server. On iOS, the malicious code was embedded in a crypto application titled “Coin” (Chinese: 币), evading Apple’s app review via code obfuscation. On Android, researchers identified the malware in “SOEX”, a chat and crypto trading app; it was pulled from Google Play only after amassing over 10,000 total downloads. Attackers also spread SparkKitty through additional channels: third-party app stores, sideloaded APKs, modified versions of TikTok, and entertainment apps. Check Point warns that if users save wallet mnemonics as screenshots or photos, their corresponding crypto wallets can be fully controlled by attackers once the mnemonics are stolen. The security agency advises against storing mnemonics in mobile photo albums—instead, they should be kept offline, such as via paper backups or hardware wallet backups. It also recommends users exercise caution when granting photo album permissions to apps and only download applications from trusted sources.

Relevant content

Meta and BlackRock are partnering to invest approximately $14 billion in data center development, with the facilities set to have a computing capacity of 1 gigawatt.

Meta Platforms (META.O) announced a partnership with BlackRock on a new strategic project to develop data centers in El Paso. The two firms will jointly invest approximately $14 billion in development costs. The deal is expected to close in the coming days, with related capacity set to launch in 2028. Meta will contribute $2.3 billion in assets, while BlackRock will provide $4.9 billion in cash at closing. Meta will offer management services and act as the exclusive first user of the El Paso campus, which will have 1 gigawatt of computing capacity.

18 minutes ago

A newly created address withdrew 10,000 Ether from Bybit, worth approximately $18.81 million.

According to OnchainLens monitoring, crypto whales continue to accumulate Ethereum, with a newly created address withdrawing 10,000 ETH from Bybit, valued at approximately $18.81 million.

18 minutes ago

Morgan Stanley: After the recent pullback, the AI supply chain still boasts an attractive risk-reward ratio.

Morgan Stanley said that following a recent pullback, the artificial intelligence (AI) supply chain still delivers an attractive risk-reward ratio, adding that the sell-off was primarily driven by technical factors and profit-taking. The firm forecasts that AI computing demand will outpace supply in the coming years, and remains optimistic about AI capability upgrades, applications, and the growth of AI-related long-term capital expenditure.

18 minutes ago

Cumberland transferred 108,090 HYPE to centralized exchanges (CEX), valued at approximately $5.95 million.

According to monitoring by OnchainLens, Cumberland has deposited assets worth approximately $6.65 million into trading platforms. The holdings include 108,090 HYPE tokens valued at around $5.95 million transferred to Bybit, and 700,000 USDT transferred to Binance.

18 minutes ago

Across attacker returns 331.8 ETH to the protocol's multi-sig address, valued at approximately $623,900.

According to PeckShield monitoring, the address marked as the attacker of Across Protocol has returned 331.8 ETH, valued at approximately $623,900, to the multi-signature address of the Across Protocol Hub Pool Owner. Earlier, Across Protocol suffered an attack on Solana, resulting in the theft of around $3.6 million worth of crypto assets.

18 minutes ago

Upbit designates STORJ as a trading warning project.

South Korea’s largest cryptocurrency exchange Upbit has designated STORJ as a trading warning project and suspended deposits for the token. According to HTX market data, STORJ’s price has seen a continuous gradual decline following its bankruptcy announcement. Its parent company, Storj Labs, announced it has voluntarily filed for Chapter 11 bankruptcy reorganization under U.S. bankruptcy code to resolve historical debts and continue operations.

18 minutes ago