A ready-made scam kit goes for $500 on a cybercrime forum. Anyone with almost no technical skill can set up a fake $TSLA token presale and empty the wallets of anyone who buys into it.
The kit is the work of a forum account going by xrep, active in the cybercrime underground since March 2026. It has received positive reviews from other criminals.
The product is “a complete scam-in-a-box,” researchers said. The bundle includes hosting, phishing pages, a fake investment dashboard, and victim-tracking tools.
Security researchers from Malwarebytes found the scam on May 16. It shows a presale page displaying the Tesla name and logo, presented as an exclusive early buy-in for X users. The website runs in several languages and works on phones as well as desktops.
At the start of the attack, the visitor’s X username is asked for an “eligibility check.” Next, the page shows the real profile picture of that account to make it look like the offer was chosen for the user.
The scam creates a sense of FOMO, or fear of missing out, by using a funding bar that starts to fill, a countdown clock, and warnings that claim the price is about to jump.
The first investment option offers a 15% bonus for linking a wallet. Then a form requests the 12-word recovery phrase to drain the crypto wallets completely.
The other “investment” option skips the wallet and asks the victim to send Bitcoin, Ethereum, USDT, or Dogecoin to an address controlled by the operator. The buyer ends up seeing a fake balance on their account.

The control panel makes the kit more dangerous. It allows the operator to see victims navigating the site, log X usernames and locations, and collect recovery phrases entered on the phishing page. The operator can verify if a wallet has something worth stealing before going after it.
He can also inflate the balance on demand so that the user believes their investment is paying off and pays even more. If the user has already paid, the panel issues a message requesting an additional network fee.
On August 3, the IRS warned that scammers were sending letters to crypto holders directing them to a fake “Digital Asset Compliance Portal” that looked like IRS[.]gov, aiming to steal wallet credentials. No such portal exists, the agency said.
In May, Cryptopolitan reported that scammers were sending printed letters to Ledger owners. These letters were about a fake “Quantum Resistance Security Update” using QR codes to phish 24-word recovery phrases.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.