Tesla ‘Crypto Presale’ Kit Fuels New Scam Wave

Biometric Update · Medium sophistication
Last updated August 12, 2026

The article describes real-world social engineering aimed at both consumers and financial firms, including phone-based attacks on hedge funds and a turnkey scam kit that impersonates Tesla to steal cryptocurrency. The kit uses a professional-looking fake presale website with urgency tactics (countdown timers and fake progress bars) to push victims into handing over their wallet recovery phrase or sending crypto directly to scammers.

Key findings

  • BioCatch reports impersonation scams targeting U.S. consumers “more than doubled between 2025 and 2026.”
  • Investment scams are described as the biggest driver of losses, using “spoofed websites and fake broker platforms to create a false sense of urgency.”
  • Reuters reports phone-based social engineering attempts against hedge funds and private equity firms, including Point72, Two Sigma, and Citadel.
  • Malwarebytes uncovered a $500 turnkey kit linked to threat actor “xrep” that impersonates Tesla in a fake cryptocurrency presale.
  • The Tesla-branded kit uses personalization (victims’ X profile pictures), fake progress bars, and countdown timers to pressure quick action.
  • Victims are funneled into either sharing their “12-word recovery phrase” (wallet takeover) or sending crypto to scammer-controlled addresses.

Who’s being targeted

  • Commonly targeted roles: Retail banking customers, Wealth management / investor relations, Hedge fund and private equity employees, Finance operations, IT helpdesk / service desk, Fraud prevention teams.
  • Affected industries: Banking, Hedge funds / private equity, Cryptocurrency investors / financial services consumers.
  • Attack channels: website, vishing.
  • Impersonated: Tesla, Internal IT/helpdesk or a trusted service provider (not specified in article).

Awareness takeaways

  • Train staff and customers to treat unsolicited investment opportunities as high-risk, especially when they create urgency with fake websites and dashboards.
  • Make it a hard rule: never share a crypto wallet recovery phrase, anyone asking for it is trying to take over the wallet.
  • Prepare employees for phone-based social engineering by requiring identity verification and call-back procedures before discussing access or account/security changes.
  • Assume scammers can buy professional ‘scam kits’ and will look legitimate; focus training on behavioral red flags, not just “poor spelling” cues.

Red flags to watch for

  • Any “investment” asking for a wallet recovery phrase is a takeover attempt
  • Urgency pressure via countdown timers / progress bars
  • Personalization designed to build trust (e.g., using your profile picture) without proof of legitimacy
  • Unsolicited phone requests tied to system access or urgent security issues
  • Caller pressure to bypass normal verification steps
  • Requests for sensitive information that would allow system access
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You see a slick Tesla crypto presale site, your X profile photo on it, countdown ticking down. Looks legit, right? Behind that page is a $500 turnkey scam kit, used to impersonate Tesla and push you into one of two things: typing your 12-word wallet recovery phrase, or sending crypto straight to their address. Here’s the catch: real investments never ask for a recovery phrase. That’s the master key. BioCatch says these impersonation scams have more than doubled, and scammers now buy pro-grade kits instead of making sloppy sites. If any “investment”, Tesla or otherwise, asks for your 12-word recovery phrase, stop. Close the site. Then report it to security.

Similar attacks

Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
Fake IT Helpdesk Calls Hit Wall Street Firms

Fake IT Helpdesk Calls Hit Wall Street Firms

A ransom-focused hacking group targeted major U.S. financial and other firms by calling employees on their personal phones while impersonating the company help desk. Victims were pushed to “update passkeys or multifactor authentication” and sent to look‑alike websites designed to steal passwords…

August 6, 2026
AI Search Results Turn Into Phishing Traps

AI Search Results Turn Into Phishing Traps

This bulletin describes multiple real-world scams where attackers make fake pages and messages look like routine, trusted experiences (search answers, Google login pop-ups, “giveaways,” and official-sounding calls). Examples include a fake Claude Max giveaway using a convincing fake Google sign-in…

September 24, 2026
Wall Street Hit by Helpdesk Impersonation Calls

Wall Street Hit by Helpdesk Impersonation Calls

A phone-first extortion campaign targeted dozens of major U.S. financial firms by calling employees and posing as corporate help-desk staff. Victims were pushed to “update” passkeys/MFA and sent to fake login pages; attackers captured passwords and MFA codes in real time to take over accounts and…

August 7, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Fake Recruiters Hit Job Seekers With Malware Files

Fake Recruiters Hit Job Seekers With Malware Files

An alleged North Korean operation called “WaterPlum” targeted job seekers by posing as AI and blockchain companies and using the interview process to trick applicants into downloading malicious files. Authorities say the campaign infected tens of thousands of devices worldwide and led to theft from…

September 18, 2026