According to Odaily, a recent report by Securelist has raised alarms about a potential new malware, SparkKitty, affecting the cryptocurrency 'Coin.' In response, the Coin team acknowledged integrating a third-party SDK from Bitdu Exchange but assured that high-risk features related to photo album access and image uploads were never activated, ensuring user data remained unaffected.
Coin revealed that in 2023, Bitdu planned to acquire Coin and requested the integration of its SDK to assess user activity. During testing, Coin's technical team identified suspicious behavior in the SDK, which attempted to enable album access and upload photos. The team promptly blocked the upload functionality through the interface to prevent any potential risks.
Coin has now initiated a comprehensive code security review and pledged to enhance the review process for third-party SDKs and conduct thorough background checks on partners to prevent similar incidents in the future.