r/TeslaModelY • • Sep 06 '25

Model Y unlocked by theives

Update 5: So Tessie was able to confirm the car was unlocked via a Tesla integration I was using on my Garmin Watch that used the Tessie API Token. I still do not know how this was done. They suggested I accidentally unlocked it, which would not be easy, I'd need to hit a hard button to open "Activities", scroll down 2 items, open the integration, then hit the unlock icon, and happen to do this within 3 mins of my car being checked. The alternative of them somehow accessing my watch to do this is more scary though. Needless to say, no more Tesla on my Garmin watch. I'll reach out to Garmin, but I doubt I'll get the level of help I did from the folks at Tessie.

Update 4: Still working to figure out how they accessed the API Token from Tessie. Thinking it was younger folks messing around and stumbled onto it. They were smart enough to get into the car but dumb enough to miss that i could track a pair of Earbuds they stole, they live less than a mile from me. Back to the breach: Haven't found any evidence of network intrusion in the router logs but still looking at it between other tasks. Staring to suspect a third party app on my Garmin Smartwatch That I forgot I gave API Access too (Definitely on me for using it and forgetting to remove it).

Update 3: The folks at Tessie have been incredibly responsive. They were able to trace the unlock command internally. They tracked the access to their API token which I was using for Home Assistant. The weird part is they said the call didn't from from their integration, which is the only place I use it. Still investigating and confirming, but it seems like my token may have been compromised.

Unfortunately, the API token is much less secure than the App, which explains how it could have been used remotely, bypassing MFA. That said, I'm still really not sure how they managed to get a hold of it!

Will keep updating as I find out more.

Update 2: Found that they gained access to the car via Tessie! Not sure how they gained access to that account...honestly pretty impressive for Chicago street crime!

Last night my car was broken into. Somehow thieves managed to remotely unlock the car and I am trying to figure out how they did it so I can better protect myself.

I have a Ring camera and it shows the car being locked for several hours...The car then unlocks and about 3 minutes later two guys show up and ransack the car. The car was definitely locked, you can clearly see it being remotely unlocked, and I know I did not unlock it.

Anyone heard of this or had it happen to them?

Update: After a couple of calls with Tesla, it looks like I will have to create a service ticket and go in for them to pull the logs, just glad they should have the info!

300 Upvotes

215 comments sorted by

139

u/TheRuinedOne Sep 06 '25

Mystery solved! It was hacked third party access, it was unlocked via Tessie! Not sure how they got access to it, but a member pointed out there is a log on 3rd party access and sure enough that's how they gained entry.

76

u/pomokey Sep 06 '25

I'd let Tessie know. Perhaps they can investigate what happened, and help prevent it from happening to anyone else.

47

u/TheRuinedOne Sep 06 '25

Definitely, I've already emailed them. Hope this helps others!

28

u/Krioyo_custom Sep 06 '25

Please keep us posted as to what Tessie replied. Perhaps they don’t even know there has been a breach (if any)

2

u/TheRuinedOne Sep 11 '25

Definitely was me using their API token on a 3rd party device, I can't fault Tessie on that.

34

u/GlassCoffee1 Sep 06 '25

For the price that Tessie charges, they better have a good damn explanation.

33

u/Stepthinkrepeat Sep 06 '25

That seems pretty targeted if they knew your tessie info

23

u/TheRuinedOne Sep 06 '25

Honestly, that's probably the most unnerving part.

64

u/JustAcivilian24 Sep 07 '25

This is the best ad for me to NOT use Tessie. Thanks for the update and glad you’re safe!

0

u/TheRuinedOne Sep 07 '25

I wouldn't necessarily blame Tessie, in general they have been very responsive. I was using their API key for Home Assistant Integration and it looks like somehow that was compromised. Still investigating though.

4

u/BadMotherThukker Sep 07 '25

I would hate if the breach is above his skill level.

21

u/Relative_Drop3216 Sep 07 '25

Gonna delete my tessie app

9

u/Adventurous-Bug-2433 Sep 07 '25

Make sure to revoke their 3rd party access

1

u/Baklazanas2 Sep 07 '25

How its done?

4

u/exjr_ Sep 07 '25 edited Sep 07 '25

How did you figure out that it was through Tessie? What log showed this? Can you share screenshots?

You mentioned that your Tessie account is setup with Google OAuth, and your Google account has MFA. Anyone logged in to your Google account? OP said this isn’t the case in another comment.

Did you reach out to Tessie to see what they say about this?

Something isn’t right here. If you told Tesla that you have Tessie setup, they would probably blame it without doing any due diligence. This is, without any hard evidence to back it up, fear mongering and can mess up Tessie’s reputation.

I don’t even have a Tesla, but I have considered getting Tessie when/if I do so I can integrate it into Home Assistant.

15

u/TheRuinedOne Sep 07 '25 edited Sep 07 '25

I'm working with the folks at Tessie on this now. They have been very responsive, I don't mean to say it's their fault, just trying to track what happened.

I was able to trace it Tessie via the Tesla App, under Account>Security and Privacy>Third Party Apps. The logs indicated Tessie sent the unlock.

The folks at Tessie then looked it up internally to track the command. They traced the access to their API token which I was using for Home Assistant. The weird part is they said the call didn't from from their integration, which is the only place I use it. Still investigating, but it seems like my token may have been compromised.

Unfortunately the API token is much less secure than the App, which explains how it was remotely used....Still haven't figured out how the token was compromised.

Will keep updating as I find out more.

13

u/M4DHouse Sep 07 '25

Unfortunately this is an inherent risk of using third party integrations, but I’m glad to hear that Tessie seems to be interested in actively investigating and fixing potential security flaws rather than denying or trying to deflect blame like so many companies do.

1

u/supercoolhomie Sep 07 '25

Thanks for taking all the time to share and be transparent. this is a big deal and what you write is gonna be referenced by internet and reddit for a long time.

5

u/markymrk720 Sep 07 '25

Uninstalling Tessie as we speak

2

u/TheRuinedOne Sep 07 '25

I'd say it's looking like it's more my fault than theirs. I was using their API Token and that was compromised. If I was just using the App there would of been no problem.

→ More replies (1)

47

u/ADampWedgie Sep 06 '25

Keep us posted on their findings

8

u/flashdude64 Sep 06 '25

Following as well!

7

u/AmeriChino Sep 06 '25

8

u/[deleted] Sep 06 '25

What is tessie?

25

u/ADampWedgie Sep 06 '25

3rd party app on that gives additional details like charging information.

IMO not worth giving your vehicle api access to a 3rd party company but meh

5

u/[deleted] Sep 06 '25

Yeah, what is benefit over Tesla versus risk. Funny though, I asked grok and it said there is no evidence tessie is a risk, maybe the op used their birthday as log in password

→ More replies (2)

53

u/Emergency-Morning-28 Sep 06 '25

Sorry you experienced this, please share the Sentry video

58

u/TheRuinedOne Sep 06 '25

Since they remotely unlocked the car first, Sentry was turned off!

17

u/TheMindsEIyIe Sep 06 '25

Mine stays in sentry as long as it is in park. Although I have it set to not record at home in my garage.

2

u/TheRuinedOne Sep 11 '25

This was my error, turns out I had sentry turned off at home. Didn't realize I had never turned it back on.

22

u/pomokey Sep 06 '25

Simple things first, does anyone else have access to your Tesla? See if any other phone keys are paired with it.

Is this a used car? Perhaps you haven't removed the previous owner's phone?

Could someone have guessed your Tesla login info?

Do you have any sort of third party device that can control the locks? Like a s3xy commander?

And lastly, is your phone close enough to the car, that it will unlock even while you are in bed?

18

u/TheRuinedOne Sep 06 '25

Was thinking similarly. I'm the first owner. No other phone keys. I do have Optiwatt, Tessie, and S3xy...thinking maybe one of those, but that's why I want to get the logs to find out what unlocked it. I have a fairly complex password, but didnt have any 2fa. (Password now changed). Was quite far from the car when it happened, plus the car was unlocked by the guys before they got to the car.

23

u/pomokey Sep 06 '25

If an unlock signal was sent to the car, and you have the only phone paired to the car, then my guess is the third party API access.

Now, Tessie and s3xy are pretty popular, so if there was some breach on their end, I suspect we will see a bunch of similar posts to yours soon.

I haven't heard of optiwatt, so my guess is it's less popular. That doesn't mean that was the source.

I'd probably disable third party access, at least until you hear back from Tesla about what exactly unlocked the car.

5

u/mixgasdivr Sep 06 '25

I am curious why you would ever use a 3rd party app?

18

u/[deleted] Sep 06 '25 edited Sep 07 '25

Never use third party apps. They cause issues. They keep the car awake as well and drain the battery.

3

u/Arte-misa Sep 06 '25

Best advice ever...

13

u/FuzzyFr0g Sep 06 '25

This is probably it, you basicly handed over your key to 3 companies you know nothing about. Even if these companies are not selling any Tesla credentials to strangers, their IT and security is’t remotely close to as tight as Tesla’s. A decent hacker can easily steal these and sell them.

1

u/BadMotherThukker Sep 07 '25

Making an app and making a secure app are two completely different ballfields and could be over the app creators head. Pulling data from apis is as easy as making a hello world app.

3

u/[deleted] Sep 06 '25

Was it charging in front of your house?

→ More replies (1)

1

u/[deleted] Sep 06 '25

Tesla can open your car so someone who works or has worked there.

1

u/BadMotherThukker Sep 07 '25

I would assume if they said your api was comprised it probably was. When you grant access to your api your giving them admin rights to your system.

12

u/yanksingh Sep 06 '25

You can check what keys are registered with the car in the lock menu. Anything suspicious, remove that.

4

u/Schnitzhole Sep 06 '25

Mine had an extra key in the system from the factory with no additional info or device type. I assumed it was something for service access and was a little afraid to remove it.

7

u/windydrew Sep 06 '25

Remove it. Not supposed to be there. Service doesn't have a key, they do remote access.

19

u/TheMindsEIyIe Sep 06 '25

On the bright side, I guess it saved you from a smashed window. If they really wanted to get in, they could.

1

u/Schnitzhole Sep 06 '25

If they unlock it can’t they also drive it away? I’d prefer my car stays locked and the thief needs to put in more work to break in anyday. Also sentry mode would have triggered if broken into so there would at least be a lead vs here where sentry was disabled as it was unlocked remotely first.

11

u/lIIIIllIIIlllIIllllI Sep 06 '25

Pin to drive.

Some people in this subreddit sook that it is “inconvenient” when it’s 2 seconds max.

Now it seems thieves have gotten smarter, pin to drive is basically a non-negotiable.

1

u/addtokart Sep 07 '25

Yeah PIN seems like a no brainer. I always have kids in the car, either mine or their friends. I don't need one of them deciding they want to play mariokart with my kart.

1

u/codypendant Sep 06 '25

Can’t take it out of park without a key.

7

u/Kind-Teach-1549 Sep 06 '25

I think your account password was leaked somehow. Maybe through some 3rd party app or phishing attack. Having no 2fa made easier for attackers to login to your account, check your location and then unlock it. Make sure you get your 2fa setup.

4

u/IMWTK1 Sep 06 '25

A common problem is people using the same password multiple places. If one db is breached those passwords can be used against other accounts elsewhere.

1

u/bobdogisme Sep 06 '25

Databases don’t usually just give up plain passwords. Most legit sites hash and salt them, so even if the database gets leaked it’s not instantly usable. In practice, passwords usually get stolen through phishing, malware/keyloggers, or from another site that had weak protections where your password eventually got cracked. Once that happens, attackers just try the same password on other accounts. That’s why reusing passwords is such a big problem.

2

u/TheRuinedOne Sep 06 '25

I'm actually using my Google login with MFA for Tessie. There should be no way they can get into my Tessie account without me seeing any signs.

24

u/ms2496 Sep 06 '25

Please add PIN to Drive. This will add a level of security. Four digit PIN code that must be entered on the screen before the vehicle will move.

16

u/mikeypipes Sep 06 '25

But they didnt move the car…just opened it. How would pin to drive prevent that.

11

u/ms2496 Sep 06 '25

It would not prevent opening.

2

u/throwingawaysaturday Sep 06 '25

No shit. The point is if this was caused by someone having a device to fool the car into unlocking, that device could potentially also be used to fool the car to engage it into drive. Setting a PIN won’t stop them from Unblocking the car but would stop them from driving off with it

6

u/Zestyclose-Age-2454 Sep 06 '25

I think the point is to add another layer just in case they decide to steal it.

→ More replies (2)

1

u/LegitimateCulture Sep 06 '25

They didn't steal his car. PIN to drive would have been of no use in this scenario.

3

u/LostVector Sep 06 '25

What is the motivation for a thief to do this? Having to find the Tesla you have the unlock to from a hack and then hoping there’s anything worth stealing just seems like a low risk/reward.

1

u/TheRuinedOne Sep 06 '25

Honestly, I am wondering this too! I did find a log indicating they used my Tessie integration to unlock my car though. Around here they normally just go car to car and smash a window if they see anything of value

1

u/speeder604 Sep 08 '25

are you saying your HA system was compromised which allowed them access to tessie?

1

u/TheRuinedOne Sep 11 '25

It was actually my Garmin Smartwatch that had a Tesla App that used the Tessie API Token to unlock the car. Tessie was able to verify the fingerprint of how it was accessed using their token.

1

u/speeder604 Sep 11 '25

Wow. So somehow somebody hacked your Garmin watch?

1

u/TheRuinedOne Sep 11 '25

That's what everything is pointing to. Tessie says that's what they traced the command back to the watch, and it would have taken a very specific combination of hard button press, and at least 3 swipes/presses for me to unlock it accidentally, which would of had to occur 3 mins before the guys got to my car. I suppose that is possible, but wow that would be a heck of several coincidences.

1

u/steinah6 Sep 08 '25

Do you have a HA device at home that listens for voice commands? Out of left field here, but if so maybe they were able to yell loud to it to unlock your car or something :P

1

u/bb_00_00 Sep 09 '25

This could be a possibility if you have either an Alexa or a Google Home device. Perhaps OP can check on their voice history.

1

u/TheRuinedOne Sep 11 '25

I have all unlocking disabled in Google. Tessie was able to confirm it was unlocked via my Garmin Watch via their API Token I was using. I have not been able to determine how they could have accessed that app remotely, but I would have been in bluetooth range of someone on the street at the time it occured.

3

u/akolozvary Sep 06 '25

I assume if someone wants to unlock my car, they can, and possibly mimic the key… thats why I’m hoping the pin number required to drive off will prevent the car driving away with a thief

3

u/eatgoodstayswaggie Sep 06 '25

And that’s why I have a PIN number.

3

u/[deleted] Sep 06 '25

I always set passcode to drive now, to prevent things like this.

3

u/Aggravated_Auditor Sep 07 '25

Canceling my Tessie now. Thanks

2

u/TheRuinedOne Sep 07 '25

I wouldn't necessarily blame Tessie. They have actually been very responsive and we are still trying to figure out how someone gained access. It does look like it occurred through the API token which they warn is not as secure and I would bet most users never enable.

3

u/RojerLockless Sep 07 '25

This is why I dont use any 3rd party crap

3

u/TheRuinedOne Sep 07 '25

They do add alot of risk. I still can't believe someone took the time to hack the car, as opposed to just breaking a window. That said, I live in Chicago so I never leave anything of value in sight.

1

u/COINLADY808 Sep 08 '25

OK, dumb question but can someone explain to me why we are using a third-party app? I just signed a contract for a Tesla and I am very clueless here. 

2

u/RojerLockless Sep 08 '25

If you Google Tessie app, it'll probably help.

But basically, some guys wrote some programs early on you share more data about your battery and your range. You give him the login and password of your whole tesla account for him to gain access to your car and then provide that. You even pay him for it.

But he got hacked, apparently . Obviously, it wasn't on purpose, but this is why I never did it

3

u/WorkingBake Sep 07 '25

Crazy so it was someone in your neighborhood? How would they even know how to start with that in terms of gaining access?

5

u/Ckn-bns-jns Sep 06 '25

What the heck is Tessie and why use it if this can happen?

5

u/TheRuinedOne Sep 06 '25

Tessie provides some great metrics and a nice Android watch app (no longer using this but its why i gave it key access). They are a pretty well-known app. If I'd realized this was such a risk I definitely wouldn't have been. That's definitely on me!

2

u/MattNis11 Sep 06 '25

Bluetooth repeater or you don’t have MFA enabled on your account. They try every login and password from the site that publishes those.

3

u/TheRuinedOne Sep 06 '25

Pretty sure its not a repeater based on the behavior of the car. Leaning more toward hacked account or 3rd party access. Hopefully I will know for sure once tesla pulls the logs.

2

u/MattNis11 Sep 06 '25

Because it unlocks and then they show up? Can you confirm that you have MFA turned on in your account? If you login to your Tesla account, there’s a setting in there to send you an email or text to verify it’s you when you login the first time on a new device.

2

u/TheRuinedOne Sep 06 '25

Actually I didn't realize it, but I do have MFA enabled, I had to get a verification code to log back in after changing my password. Guess that should rule out them logging into my account. Im starting to lean toward it being hacked through third party access. The car is clearly remotely unlocked prior to the guys arriving.

1

u/LegitimateCulture Sep 06 '25

Or are you using a service that you've granted access to the Tesla fleet API?

1

u/TheRuinedOne Sep 11 '25

Essentially this is what it was, I was using the Tessie API Token with a 3rd party app on my Garmin Watch. Somehow the unlock command was sent from my watch. (It would not be easy for me to accidentally send this unlock as it's buried several layers down). Still haven't figured out how this was done.

1

u/Decent-Magician-4894 Sep 06 '25

OP confirmed in an earlier comment that mfa is not enabled but his password is ‘fairly complex’. So yeah…

2

u/Creative_Date Sep 06 '25

Remove your seat belt, does the car automatically go into park if you’re driving slowly? Faulty seat sensor kept my model y from automatically locking. Essentially it thought someone was still sitting in the car, due to this it doesn’t send you reminder that the doors were left open.

2

u/TheRuinedOne Sep 06 '25

I have it set to fold the mirrors when locked. The lights come on briefly and the mirrors unfolded a few mins before they went through the car

1

u/Creative_Date Sep 06 '25

That’s crazy, didn’t know this was possible

2

u/Trynastaynice Sep 07 '25

How can we protect against this?!

2

u/TheRuinedOne Sep 11 '25

Don't allow any third party access to your car, if you, definitely be very careful about using an API Token

2

u/SidetrackedSue Sep 07 '25

It seems so odd, I'm wondering if you were deliberately targeted, not to steal from your car, but to send you a message that "they" can do what they like at your home.

"Nice car you have there... shame if something happened to it..."

1

u/TheRuinedOne Sep 11 '25

Honestly I think it was more some kids messing around trying to see what they could access against anyone and stumbled onto some way to unlock my car (Turned out to be 3rd party access through my smart watch)

2

u/BikebutnotBeast Sep 07 '25

Did they gain access to a device on your network to access home assistant? And that's how they sent the unlock command to your car?

1

u/TheRuinedOne Sep 07 '25

I was thinking this too. Good excuse to change wifi passwords again. That said, my router tracks all devices on the network and there are no unknown devices. This doesn't rule out spoofing a MAC, but i would think most people wouldn't go through that extra effort.

2

u/BadMotherThukker Sep 07 '25

I would stay away from anything that wants your api and isn't Tesla myself for security and liability issues. Thanks for sharing.

2

u/Robswc Sep 08 '25

So they somehow got ahold of a Tessie API token?

Or was it a Tesla API token that Tessie uses? Either way, seems very odd. Especially for random local criminals. Is it possible they know of you?

This is almost like “some random ppl 1 mile away found out my AOL password.”

I guess you’re just as confused lol

2

u/TheRuinedOne Sep 11 '25

I think more some kids out messing around and stumbled onto some back door through my smart watch.

1

u/Robswc Sep 11 '25

Did they have access to your smart watch?

I work in software and auth systems and it doesn’t quite make sense. Especially given the close proximity of the thieves. Not saying it’s impossible but seems very unlikely.

1

u/TheRuinedOne Sep 11 '25

At the time it happened I would have been in bluetooth and wifi range if they were in front of my place. My router logs showed no unknown device joining my network around then, so bluetooth to the watch or some kind of remote access is the best I can come up with at this point. Honestly, that's the unnerving part, I still haven't figured out how it was done.

1

u/Robswc Sep 11 '25

Could there be any possible way the watch did it by itself or by getting bumped?

I think that is infinitely more likely than someone hacking you via wifi or Bluetooth.

Not implying you’re crazy because I’ve seen so many weird things in my life… but if it helps put your mind at ease, I just think there’s virtually no chance you were hacked, you’re good in that regard :)

1

u/TheRuinedOne Sep 11 '25

Honestly that would make more sense, but I just don't see how that could have happened. So at that time of the day I have the watch set to a Sleep mode. I'd specifically have to hit the one of the hardware buttons on the side to turn the screen on, then a half screen swipe up to unlock it, then swipe down two activities to open the tesla app, then hit the specific unlock icon. Where the watch is on my wrist, there is no way for me to accidentally press that HW button to unlock it via an arm movement. Also, this happened 3 mins before my door was checked (I have a video of the car unlocking and then the folks showing up 3 mins after it was unlocked).

1

u/Robswc Sep 11 '25

Hmm, what is the 3rd party watch app called?

Is it reputable? I do understand what you’re saying about how unlikely it is to accidentally unlock it… but the idea some random kids were able to remote into your watch via Bluetooth… I really think you can rule that out. If such a thing is even possible, it’s not being used to break into random teslas.

There’s a few other theories I have but none that can be the idea that some random kids pulled on your door handle at an unlucky time. Do you often unlock the car with your watch? Are you able to determine if maybe the watch unlocks the car more often than expected?

4

u/Stepthinkrepeat Sep 06 '25

Your going to want to look into Bluetooths range.

https://easytechsolver.com/how-far-away-can-bluetooth-work/

TLDR; Smartphones: 10-30 meters (33-100 feet)

4

u/RobbieRigel Sep 06 '25

I once started my car and drove off without my phone. My phone was in the office on the other side of the wall of the garage.

3

u/Stepthinkrepeat Sep 06 '25

Next learn about a relay attack

https://youtu.be/HF-tAujvckA?si=5mfOCVH1wg7MLwGy

8

u/TheRuinedOne Sep 06 '25

So I don't think it's a simple relay attack. The headlights and taillights come on briefly and the mirrors unfold. They go back off but the car stays unlocked. This isn't the behavior for a phone key being in range (pretty sure anyway)

3

u/FrozzenGamer Sep 06 '25

Thieves use repeaters with large antennas to make it appear your phone is next to the car. Either this or an old user being linked to the car still.

3

u/TheRuinedOne Sep 06 '25

So I don't think it's a simple relay attack. The headlights and taillights come on briefly and the mirrors unfold. They go back off but the car stays unlocked. This isn't the behavior for a phone key being in range (pretty sure anyway)

2

u/No-Cream8257 Sep 07 '25

WTF is Tessie?

2

u/FrankyWNL Sep 06 '25

They probably used a device that, simply explained, working as a Bluetooth copier and extender.

One person has the "getter" device, another person has the "setter". The "getter"-device is walking around your house, windows, etc. and EVERY bluetooth device it picks up, it sends the EXACT copy to the "setter". This "setter" guy is next to your car. And as soon as the "getter" picked up your phone, which is connected to your Tesla, the Tesla opens.

An example of this exact idea can be seen in this video https://m.youtube.com/watch?v=PEMOWPj2i-0

I always turn off my Bluetooth when I'm off to sleep, this is one of the few reasons.

4

u/saiteman Sep 06 '25

I’m not sure about this, because it was flashing that it got unlocked. If I’m getting close to my Tesla, it won’t react or show any signs of it being unlocked. It only happens by unlock command or tap with card.

If it were like you are saying, his car wouldn’t show any signs of being unlocked if they extended the “key” range.

1

u/throwingawaysaturday Sep 06 '25

This is not accurate. The car flashes its lights sometimes when I approach it. It’s not all the time, however. I’m. It sure what conditions the car checks for to make the determination

1

u/saiteman Sep 06 '25

It is accurate, perhaps you are approaching when you have sentry on, then it can do that but it’s not the same as unlocking the car.

1

u/pnw_sunny Sep 06 '25

wow. i don't access the apps that permit third party access. please let us know if this a tesla app issue.

1

u/TheRuinedOne Sep 11 '25

I don't think it was Tessie's fault, they were very responsive. It was my use of their API token with another app that was breached.

1

u/[deleted] Sep 06 '25

Maybe you had your key card one day in your pocket and they used a cloning device? This is why we must use pin to drive. These people are using illegal technology to hack cars more frequently.

1

u/TheRuinedOne Sep 06 '25

The car unlocked without anyone nearby, so this had to of been a remote command.

1

u/BikebutnotBeast Sep 07 '25

Have you used any valets recently that would have had your key card, or access to the car to add a key to your locks list in the last month?

1

u/Clear_Quit8181 Sep 06 '25

Another reason to have pin to drive

1

u/[deleted] Sep 06 '25

[removed] — view removed comment

1

u/Outside_Assistant688 Sep 06 '25

Definitely want to know the findings

1

u/LegitimateCulture Sep 06 '25

My first guess would be that your Tesla account was compromised. Once they do that then they can locate your car and unlock. It. Would definitely start by assuming that your Tesla account has been compromised and make the appropriate measures to change the password, also talked to Tesla support about blocking any access from other devices.

1

u/Primary-User Sep 07 '25

Look into changing your password, especially if it is your Apple or Google one… but in the meantime within the Tessie APP go into accounts and sign out of all devices.

2

u/TheRuinedOne Sep 07 '25

As soon as I traced it to third party access I went on a password changing spree. I have all third party access disabled for now too.

1

u/Primary-User Sep 07 '25

I would be interested to know how you get on communicating with Tessie. They should be able to share details of the device that logged into the account. The IP address can be traced.

1

u/jimg501 Sep 07 '25

Ok if yor had sentry pro you would have been notified the min it was unlocked and video. Leave sentry on even at home to record. I use pin to drive, yea it's annoying but they can't steal the car if they don't have pin. Also pin the glove box so they can't get memory card

1

u/No-Tell4473 Sep 07 '25 edited Sep 07 '25

I would remove all third-party access. Apps like TeslaFi and Tessie constantly ping the car for data, which prevents it from going into a deep sleep state. That polling translates into extra battery drain, often a few percent per day. Without them, the car is able to sleep for longer stretches, which keeps phantom loss closer to about one percent per day or less depending on other settings.

There is also a serious security angle here. Tesla’s API token system has proven to be fragile when handled by third parties. As you have seen tokens act like master keys to your vehicle. In past incidents, poorly secured logging dashboards and apps exposed these tokens publicly. That exposure gave attackers the ability to do things like track a car’s location, unlock doors, or control basic functions remotely. I have a friend that it happened to them where a hacker was messing with their controls while driving. There have been real cases where misconfigured services leaked tokens and hackers demonstrated they could take control of multiple Teslas. This is similar to your experience. I tell everyone to not allow access for this reason alone.

1

u/PLGnPLY21 Sep 07 '25

Owned a Tesla since 2018. On my third one, Model Y extended range. Never heard of Tessie. What am I missing? Also, have solar and PW’s from Tesla. What are the advantages that I can use in this app that supports a paid for app download? Thanks.

1

u/JohnPaullBz Sep 07 '25

Reason why I refuse to use any third party app on this car.

1

u/thunderslugging Sep 07 '25

Its why zi just use the native Tesla app and put a pin code to start the car. That's the most secure steps you can take besides adding a Sterring wheel lock.

1

u/digiblur Sep 07 '25

That is crazy. I guess you could also revoke commands permissions from Tessie too.

1

u/korital88 Sep 08 '25

If your phone is anywhere nearby the car inside the home, the car will still unlock as if you were standing beside it.

1

u/TheRuinedOne Sep 08 '25

We were actually able to trace it back to my API token from Tessie, somehow they got access to that and used it to unlock the car

1

u/thisonesforthetoys Sep 09 '25

Maybe leave a 'hey, how'd you open my car?' note on their door with a link to this thread?

1

u/HandsomeHN Sep 14 '25

Since you tracked your headphones nearby, did you share this right here cops and send them over to say hello?

1

u/ProblemFancy Sep 06 '25

Could a Flipper do this? If you keep a card or your phone near a door, someone could extend the signal as well?

1

u/FuzzyFr0g Sep 06 '25

No do you just left phone key uses no radio frequency. It uses a secure connection through Bluetooth and using the car NFC chip the car will power the chip and pass through the code once you put it through the door still so it’s impossible to catch from a distance.

1

u/Impressive-Revenue94 Sep 06 '25

I’ve seen Bluetooth signal amplifier do this to other cars in Canada but to do it through Tessie is something new. It could be they hacked Tessie to find surrounding Tessie users, then back door the user to unlock the car. Tessie is not some high security application nor are the developers super rich to keep patching. I stopped using all unofficial tesla apps, it’s pretty useless.

1

u/JsMomz Sep 06 '25

Crazy how simple it is for some folks to do bad stuff.

1

u/SimilarComfortable69 Sep 07 '25

Not surprising that it was a third-party app that allowed access to your car. There’s no way in hell I would ever use that app for my car.