$500 scam kit builds a fake $TSLA presale and screens wallets before draining them

- A forum seller offers a $500 turnkey kit that builds a fake $TSLA presale site impersonating Tesla.
- The kit phishes 12-word recovery phrases behind a 15% bonus offer, or crypto takes payments.
- Its admin panel tracks victims and checks whether their wallets hold anything worth stealing.
A ready-made scam kit goes for $500 on a cybercrime forum. Anyone with almost no technical skill can set up a fake $TSLA token presale and empty the wallets of anyone who buys into it.
Hacker sells fraud as a finished product
The kit is the work of a forum account going by xrep, active in the cybercrime underground since March 2026. It has received positive reviews from other criminals.
The product is “a complete scam-in-a-box,” researchers said. The bundle includes hosting, phishing pages, a fake investment dashboard, and victim-tracking tools.
Security researchers from Malwarebytes found the scam on May 16. It shows a presale page displaying the Tesla name and logo, presented as an exclusive early buy-in for X users. The website runs in several languages and works on phones as well as desktops.
At the start of the attack, the visitor’s X username is asked for an “eligibility check.” Next, the page shows the real profile picture of that account to make it look like the offer was chosen for the user.
The scam creates a sense of FOMO, or fear of missing out, by using a funding bar that starts to fill, a countdown clock, and warnings that claim the price is about to jump.
The first investment option offers a 15% bonus for linking a wallet. Then a form requests the 12-word recovery phrase to drain the crypto wallets completely.
The other “investment” option skips the wallet and asks the victim to send Bitcoin, Ethereum, USDT, or Dogecoin to an address controlled by the operator. The buyer ends up seeing a fake balance on their account.

The scam kit steals locations and recovery phrases
The control panel makes the kit more dangerous. It allows the operator to see victims navigating the site, log X usernames and locations, and collect recovery phrases entered on the phishing page. The operator can verify if a wallet has something worth stealing before going after it.
He can also inflate the balance on demand so that the user believes their investment is paying off and pays even more. If the user has already paid, the panel issues a message requesting an additional network fee.
On August 3, the IRS warned that scammers were sending letters to crypto holders directing them to a fake “Digital Asset Compliance Portal” that looked like IRS[.]gov, aiming to steal wallet credentials. No such portal exists, the agency said.
In May, Cryptopolitan reported that scammers were sending printed letters to Ledger owners. These letters were about a fake “Quantum Resistance Security Update” using QR codes to phish 24-word recovery phrases.
If you're reading this, you’re already ahead. Stay there with our newsletter.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Randa Moses
Randa Moses is an editor and reporter at Cryptopolitan covering tech, AI, robotics, crypto, scams, and hacks. She has worked in the crypto space since 2017. She held roles at Forward Protocol, AmaZix, and Cryptosomniac. Randa holds a degree in Electrical and Electronics Engineering from the University of Bradford.
















