Turnkey $500 Scam Kit Enables Fake $TSLA Token Presales to Drain Victim Wallets
Key Takeaways
- •A scam kit sold for $500 on a cybercrime forum allows individuals without coding skills to launch fraudulent $TSLA token presales designed to steal cryptocurrency from unsuspecting investors.
- •Tesla has never issued any cryptocurrency token, making any investment opportunity claiming affiliation with the company inherently fraudulent.
- •The kit includes a control panel that enables operators to monitor victims in real time, log X usernames and locations, harvest recovery phrases, and artificially inflate displayed account balances to encourage additional deposits.
- •The scam leverages psychological manipulation tactics including displaying the visitor's actual X profile picture, countdown timers, and fake funding progress bars to create urgency and fear of missing out.
- •The IRS and other authorities have documented a rise in related cryptocurrency scams, including physical mail phishing campaigns that target crypto holders with fake compliance portals and security updates.

A ready-made scam kit priced at $500 is being sold on a cybercrime forum, enabling buyers with minimal technical expertise to launch fraudulent $TSLA token presales and drain cryptocurrency wallets of anyone who participates. Tesla has not issued any cryptocurrency token, meaning any investment opportunity claiming otherwise is inherently fraudulent.
Hacker Markets Fraud as a Complete Product
The kit is attributed to a forum account using the handle "xrep," which has been active in the cybercrime underground since March 2026 and has received positive reviews from other forum members.
Researchers described the product as "a complete scam-in-a-box." The package includes hosting infrastructure, phishing pages, a fabricated investment dashboard, and victim-tracking capabilities. The commoditization of fraud tooling means that individuals no longer need coding skills or underground connections to launch sophisticated cryptocurrency scams, significantly expanding the pool of potential bad actors.
Security researchers at Malwarebytes discovered the scam on May 16. The fraudulent presale page displays the Tesla name and logo, presenting itself as an exclusive early investment opportunity targeted at X users. The site operates in multiple languages and is functional on both mobile devices and desktop computers. The use of token presales as a lure is particularly effective because legitimate crypto projects do conduct presale rounds, making fraudulent offerings harder for casual investors to distinguish from genuine opportunities.
How the Scam Works
The attack begins by requesting the visitor's X username under the guise of an "eligibility check." The page then displays the user's actual profile picture, creating the impression that the offer was specifically selected for them.
The scheme leverages FOMO — fear of missing out — through a progressively filling funding bar, a countdown timer, and warnings claiming an imminent price increase.
The first investment option advertises a 15% bonus for linking a wallet. A subsequent form then requests the user's 12-word recovery phrase, enabling the operator to drain the cryptocurrency wallets entirely. Legitimate cryptocurrency services never request a recovery phrase under any circumstances, as these phrases grant full and irreversible control over a wallet's contents.
An alternative "investment" option bypasses the wallet connection step and instead directs victims to send Bitcoin, Ethereum, USDT, or Dogecoin to an address controlled by the scam operator. Victims are subsequently shown a fake account balance.
Control Panel Enables Real-Time Victim Tracking
The included control panel significantly increases the kit's threat level. It allows operators to monitor victims as they navigate the site, log X usernames and geographic locations, and harvest recovery phrases entered on the phishing page. Operators can assess whether a wallet holds sufficient funds before targeting it.
The panel also enables operators to artificially inflate displayed balances on demand, leading victims to believe their investment is appreciating and encouraging additional deposits. If a user has already made a payment, the panel can generate a message requesting a supplementary network fee.
Related Crypto Scam Activity
On August 3, the IRS issued a warning that scammers were mailing physical letters to cryptocurrency holders directing them to a fraudulent "Digital Asset Compliance Portal" designed to mimic the official IRS[.]gov website, with the intent of stealing wallet credentials. The agency confirmed that no such portal exists.
In May, Cryptopolitan reported that scammers were sending printed letters to Ledger device owners promoting a fake "Quantum Resistance Security Update" that used QR codes to phish for 24-word recovery phrases. The convergence of physical-mail phishing with cryptocurrency targeting reflects an evolution beyond purely digital scams, broadening the attack surface to include investors who may be vigilant online but less suspicious of printed correspondence.