Security researchers at Malwarebytes say a seller on a cybercrime forum is offering a $500 package that lets would-be scammers launch a fake $TSLA token presale with little technical skill. The kit allegedly uses Tesla branding and an X-themed “exclusive” offer to lure targets, then either captures wallet recovery phrases or directs payments to attacker-controlled addresses.

According to the researchers, the seller, using the name xrep, has been active in the cybercrime underground since March 2026 and has received positive feedback from other forum users. Malwarebytes described the package as a ready-made operation that includes hosting, phishing pages, a fake investment dashboard, and tools for tracking victims.

Fake presale framed as an exclusive X offer

Malwarebytes said it found the scam on May 16. The site it reviewed presented a supposed early opportunity to buy into a Tesla-linked token presale, using the Tesla name and logo and pitching the offer as something reserved for X users.

The page was built to look polished and broadly accessible. Researchers said it worked on both desktop and mobile devices and was available in several languages, widening the pool of potential targets.

How the site builds credibility and urgency

The attack begins with a prompt asking the visitor to enter an X username for an “eligibility check.” After that step, the page reportedly displays the real profile picture tied to that account, a tactic meant to make the offer feel personalized and legitimate.

To push people toward quick decisions, the scam also uses familiar pressure tactics. Malwarebytes said the page shows a funding bar that appears to fill up, a countdown timer, and warnings that the token price is about to rise, all designed to create fear of missing out.

Two paths to victim losses

One route offers a claimed 15% bonus if the user links a wallet. The process then asks for the wallet’s 12-word recovery phrase, which would give the scam operator a way to empty the victim’s crypto holdings.

The other route avoids wallet linking and instead instructs the victim to send Bitcoin, Ethereum, USDT, or Dogecoin directly to an address controlled by the operator. Malwarebytes said the victim is then shown a fake account balance, creating the impression that the investment has been received and is growing.

Control panel lets operators screen and pressure targets

Researchers said the bundled control panel increases the danger by giving the scammer visibility into victim activity on the site. The interface can log X usernames and locations, capture recovery phrases submitted through the phishing page, and show the operator how users are moving through the process.

Malwarebytes said the panel also allows the operator to check whether a targeted wallet appears worth draining before acting. It can inflate the displayed balance to encourage further deposits and, when a victim has already sent funds, issue a follow-up demand for an additional network fee.

What is confirmed so far

The source article does not say how many people, if any, have been defrauded through this specific kit, and it does not identify the operator behind the xrep alias. What is confirmed is that Malwarebytes says the package was being sold on a cybercrime forum and that the tooling was built to let low-skill criminals run a branded crypto presale scam with built-in phishing and payment collection features.

For now, the clearest next step on record is the researchers’ documentation of how the kit works: screening targets through an X username prompt, using branding and fake account details to build trust, and then extracting either wallet credentials or direct crypto transfers.

Source: Cryptopolitan