Fake Tesla Token Presale Kit Steals Crypto

Help Net Security · Medium sophistication
Last updated August 12, 2026

Researchers found a turnkey scam kit sold on a cybercrime forum that lets criminals quickly stand up a fake crypto “presale” website styled to look like Tesla. The site uses pressure tactics and a fake investment dashboard to trick people into either handing over their wallet recovery phrase or sending cryptocurrency directly to the scammer. An admin panel tracks victims and can inflate fake balances to encourage additional payments.

Key findings

  • A $500 “scam-in-a-box” kit is being sold on a cybercrime forum, including phishing functionality, a fake investment dashboard, and victim tracking/admin controls.
  • The kit builds a fake “$TSLA” token presale page made to look like Tesla and supports multiple languages and mobile/desktop.
  • The site uses urgency tactics (countdown clock, auto-progress bar, warnings about price increases) to push quick decisions.
  • Victims are tricked into either entering a 12-word wallet recovery phrase (allowing full wallet takeover) or sending crypto directly to scammer-controlled addresses.
  • An admin panel can collect victim details (including recovery phrases), evaluate whether wallets are worth draining, inflate fake balances to prompt more deposits, and message victims to demand extra ‘network fees’.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Executives, Anyone who uses personal or corporate cryptocurrency.
  • Affected industries: Cryptocurrency users/investors, Consumer financial services, Retail investing.
  • Attack channels: website.
  • Impersonated: Tesla (fake token presale), Fake presale support/admin (within the scam site).

Awareness takeaways

  • Never enter or share a crypto wallet recovery phrase, treat it like the master key to all funds.
  • Be suspicious of investment offers that create urgency with countdowns, auto-progress bars, or ‘price about to rise’ warnings.
  • Don’t trust website ‘balances’ or dashboards as proof of an investment, scammers can fake gains to push additional deposits.
  • Watch for “pay an extra fee to release funds” follow-on scams after an initial payment, stop and verify through trusted channels.

Red flags to watch for

  • Asks for a 12-word recovery phrase (a legitimate service will never ask for this).
  • High-pressure urgency cues like countdown clocks and warnings about imminent price increases.
  • Brand impersonation (Tesla) tied to an unofficial token presale and ‘bonus’ claims.
  • Requests an additional fee after payment has already been sent.
  • Unverifiable “delay” excuse combined with pressure to pay again quickly.
  • No legitimate proof of purchase; only a website-displayed balance.
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this pops up in your browser: “You’re eligible for the $TSLA presale, check with your X username.” Looks like a slick Tesla token sale. Behind that page is a $500 scam-in-a-box kit: fake Tesla branding, a countdown clock, a progress bar that climbs on its own, and a dashboard showing your “balance” shooting up to push you to send more crypto. Here’s the trap: a form pops up asking for your 12-word recovery phrase to “claim a bonus,” or a crypto address to join the sale. Those 12 words are the master key, whoever gets them can empty your wallet, then hit you again with a fake “extra network fee” message. If any site, Tesla-branded or not, asks for your 12-word phrase, stop right there and close the page. That phrase never gets typed into a website. Ever.

Similar attacks

AI Search Results Turn Into Phishing Traps

AI Search Results Turn Into Phishing Traps

This bulletin describes multiple real-world scams where attackers make fake pages and messages look like routine, trusted experiences (search answers, Google login pop-ups, “giveaways,” and official-sounding calls). Examples include a fake Claude Max giveaway using a convincing fake Google sign-in…

September 24, 2026
Revolut Smishing Uses Fake Identity Check

Revolut Smishing Uses Fake Identity Check

Following a Revolut data breach, scammers sent text messages that appeared to come from the same message thread as legitimate Revolut texts. The texts pushed victims to click a link for a fake identity “liveness check,” request camera access, and then capture passwords, information that could be…

September 21, 2026
Revolut Users Hit With SMS Phish After Breach

Revolut Users Hit With SMS Phish After Breach

Days after Revolut disclosed that customer records were shared with an unauthorized party, some customers reported receiving phishing texts that appeared in the same SMS thread as real Revolut messages. The link led to a fake site that asked for camera access to mimic Revolut’s identity “liveness”…

September 17, 2026
Brevo Breach Fuels Crypto Newsletter Phishing

Brevo Breach Fuels Crypto Newsletter Phishing

Attackers abused access to Brevo (an email marketing platform) to send highly convincing phishing emails from legitimate cryptocurrency company domains to newsletter subscribers. The lures claimed urgent security issues (hardware vulnerability or data breach) and pushed victims to click links,…

September 11, 2026
Fake Claude Max Promo Steals Google Logins

Fake Claude Max Promo Steals Google Logins

Researchers found a real phishing campaign offering a “free” Claude Max upgrade to trick people into signing in with Google. The site uses a fake, draggable Google login pop-up (“browser-in-the-browser”) that looks legitimate and captures credentials. A stolen Google account can expose email and…

September 23, 2026
Fake Claude Max Promo Steals Google Logins

Fake Claude Max Promo Steals Google Logins

Researchers found a phishing campaign offering a “free” upgrade to Claude Max to trick people into signing in with Google. The page uses a convincing fake, draggable Google login window (“browser-in-the-browser”) to capture credentials, potentially giving criminals access to email, documents, and…

September 23, 2026