Turnkey “$TSLA Token” Kit Phishes Crypto Wallets

Malwarebytes · Medium sophistication
Last updated August 11, 2026

Researchers found a ready-made “scam-in-a-box” kit being sold on a cybercrime forum that impersonates Tesla and offers an exclusive “$TSLA token presale” for X (Twitter) users. The site uses personalization, urgency (countdown timers/progress bars), and a fake dashboard to trick victims into either entering their crypto wallet recovery phrase or sending cryptocurrency directly to scammers. The kit also includes an admin panel to track victims, collect seed phrases, and pressure victims for extra “fees.”

How the attack worked

A threat actor known as "xrep" sold a ready-made scam kit for $500 that impersonates Tesla and advertises an exclusive $TSLA token presale for X users. The kit starts with a fake eligibility check that asks visitors for their X username, then pulls their real profile picture and generates a personalized token allocation. This personalization step is designed to make an otherwise generic scam feel individually targeted.

Once a victim believes they qualify, the site pushes them toward one of two outcomes. In the first, victims are told to connect a wallet to receive a 15% bonus, but instead are prompted to enter their 12-word recovery or seed phrase. That phrase functions as the master key to a cryptocurrency wallet, so anyone who obtains it can access the funds inside. In the second path, victims are shown a dashboard and instructed to manually send Bitcoin, Ethereum, USDT, or Dogecoin to a wallet address controlled by the scammer to "buy more tokens." No real tokens are ever purchased; the site simply displays a fake balance.

Why it succeeded

The kit combines several proven social engineering elements. It borrows credibility from a recognized brand and platform, personalizes the offer using data pulled from the victim's own social account, and applies urgency through countdown timers and a constantly increasing fundraising progress bar. Together these signals create the impression of a real, time-limited, individually offered opportunity rather than a mass scam.

What to watch for

  • Any offer described as an exclusive presale or investment opportunity that claims you were personally selected
  • Requests to enter a wallet's 12-word recovery or seed phrase under any circumstance
  • Countdown timers, progress bars, or warnings that a price is about to increase
  • Instructions to manually send cryptocurrency to a wallet address shown on a website
  • Follow-up messages claiming a transaction is delayed and demanding an extra network fee

Building resistance

The kit also includes an admin panel that lets scammers track victims by username and location, collect submitted seed phrases, and send personalized follow-up messages pressuring victims for additional fees. This shows the scam is designed for repeat monetization, not a single payment. Employees who hold or manage cryptocurrency, including finance staff and executives, should treat unsolicited investment offers with skepticism, never share a recovery phrase with any website or contact, and verify any crypto transaction request through channels independent of the site making the request.

Key findings

  • A threat actor (“xrep”) sold a $500 turnkey kit that impersonates Tesla and advertises an exclusive “$TSLA token presale” for X users.
  • The scam personalizes the lure by asking for an X username, pulling the victim’s real profile picture, and showing a fake allocation.
  • Victims are pushed with urgency signals (countdown timer, increasing progress bar) to act quickly.
  • Two primary monetization paths: (1) steal the wallet by requesting the 12-word recovery/seed phrase, and (2) direct crypto payment to scammer-controlled addresses while showing a fake token balance.
  • An admin panel lets scammers track victims (usernames, locations, activity), collect recovery phrases, and message victims to demand extra ‘network fees.’

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, Employees who use cryptocurrency.
  • Affected industries: Consumers / retail investors (cryptocurrency), Financial services (crypto wallets/exchanges ecosystem).
  • Attack channels: website.
  • Impersonated: Tesla (brand/logo) and an “exclusive X users” token presale, A legitimate-looking “$TSLA token” presale dashboard, Presale support/notifications from the token platform.

Red flags to watch for

  • Any request for a crypto wallet “12-word recovery phrase/seed phrase”
  • Countdown timers/progress bars designed to create urgency (FOMO)
  • A personalized ‘allocation’ generated after entering a social handle
  • Manual transfer to a single wallet address to ‘buy tokens’
  • A dashboard showing balances that can’t be verified independently
  • Pressure to add more funds after an initial payment
  • Unexpected ‘extra fee’ to release or complete a transaction
  • Messages coming from the same scam platform that already took funds
  • No official, verifiable support channel outside the site
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the $TSLA token presale scam?

It is a fake investment lure built from a turnkey scam kit sold for $500 that impersonates Tesla and offers X (Twitter) users an exclusive presale for a fictitious $TSLA token.

How do scammers steal funds in this attack?

Victims are asked to connect a crypto wallet and enter their 12-word recovery phrase, or they are told to manually send cryptocurrency like Bitcoin, Ethereum, USDT, or Dogecoin to a scammer-controlled address.

Why does the scam ask for an X username first?

Entering an X username triggers a fake eligibility check that pulls the victim's real profile picture and generates a personalized fake token allocation, making the offer feel legitimate and tailored to them.

What happens after a victim pays once?

An admin panel lets scammers track the victim and send follow-up messages claiming the transaction is delayed and that an additional network fee is required to complete it.

Read the video transcript

You’re scrolling X and hit a slick site: “Exclusive $TSLA token presale for X users.” Tesla logo, your handle, even your profile pic on the page. It runs a fake eligibility check, shows you a “personal allocation,” then a countdown timer and progress bar start screaming FOMO. To get a 15% bonus, it tells you: connect your wallet and type your 12-word recovery phrase. Here’s the trick: this turnkey “$TSLA token” kit, sold by a user called xrep, just steals wallets. If you type that phrase, they own your crypto. If you send Bitcoin, Ethereum, USDT, or Dogecoin to their address, the site shows a fake dashboard and fake balance, no real tokens exist. Remember this: a real site never needs your 12-word recovery phrase. If any site, Tesla-branded or not, asks for it, close the page immediately and report it to security.

Similar attacks

Tesla ‘Crypto Presale’ Kit Fuels New Scam Wave

Tesla ‘Crypto Presale’ Kit Fuels New Scam Wave

The article describes real-world social engineering aimed at both consumers and financial firms, including phone-based attacks on hedge funds and a turnkey scam kit that impersonates Tesla to steal cryptocurrency. The kit uses a professional-looking fake presale website with urgency tactics…

August 12, 2026
Fake Tesla Token Presale Kit Steals Crypto

Fake Tesla Token Presale Kit Steals Crypto

Researchers found a turnkey scam kit sold on a cybercrime forum that lets criminals quickly stand up a fake crypto “presale” website styled to look like Tesla. The site uses pressure tactics and a fake investment dashboard to trick people into either handing over their wallet recovery phrase or…

August 12, 2026
Fake iPhone Crypto Wallet Stole $1.8M

Fake iPhone Crypto Wallet Stole $1.8M

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users into entering their wallet recovery phrase, then criminals used it to drain about $1.8 million in Bitcoin. The case highlights how…

July 29, 2026
Scammers Shift Lures to Email, Text, and Social

Scammers Shift Lures to Email, Text, and Social

Malwarebytes reports that scammers are increasingly tailoring different scams to the platforms where they work best, like unpaid-toll lures via email/SMS, romance scams via social media, and IRS scams via phone calls. The report highlights heavy brand and celebrity impersonation (including MrBeast)…

September 2, 2026
Vishing + Phishing Drive Major Data Theft Claims

Vishing + Phishing Drive Major Data Theft Claims

This weekly threat bulletin highlights multiple real-world incidents, including a healthcare data breach claim where attackers reportedly used phone-based social engineering (vishing) to compromise identity accounts and access cloud apps. It also describes a large-scale “debt relief” email phishing…

August 31, 2026
Fake Microsoft Scan Pushes AV Uninstall Scam

Fake Microsoft Scan Pushes AV Uninstall Scam

Scammers are running Microsoft-branded “SysScan” websites that display a fake security scan and falsely claim Windows no longer supports third‑party antivirus. Victims are pressured to uninstall their antivirus, submit personal and banking details, and prepare for a “refund manager” phone call,…

August 24, 2026