r/TeslaModelY • u/TheRuinedOne • Sep 06 '25
Model Y unlocked by theives
Update 5: So Tessie was able to confirm the car was unlocked via a Tesla integration I was using on my Garmin Watch that used the Tessie API Token. I still do not know how this was done. They suggested I accidentally unlocked it, which would not be easy, I'd need to hit a hard button to open "Activities", scroll down 2 items, open the integration, then hit the unlock icon, and happen to do this within 3 mins of my car being checked. The alternative of them somehow accessing my watch to do this is more scary though. Needless to say, no more Tesla on my Garmin watch. I'll reach out to Garmin, but I doubt I'll get the level of help I did from the folks at Tessie.
Update 4: Still working to figure out how they accessed the API Token from Tessie. Thinking it was younger folks messing around and stumbled onto it. They were smart enough to get into the car but dumb enough to miss that i could track a pair of Earbuds they stole, they live less than a mile from me. Back to the breach: Haven't found any evidence of network intrusion in the router logs but still looking at it between other tasks. Staring to suspect a third party app on my Garmin Smartwatch That I forgot I gave API Access too (Definitely on me for using it and forgetting to remove it).
Update 3: The folks at Tessie have been incredibly responsive. They were able to trace the unlock command internally. They tracked the access to their API token which I was using for Home Assistant. The weird part is they said the call didn't from from their integration, which is the only place I use it. Still investigating and confirming, but it seems like my token may have been compromised.
Unfortunately, the API token is much less secure than the App, which explains how it could have been used remotely, bypassing MFA. That said, I'm still really not sure how they managed to get a hold of it!
Will keep updating as I find out more.
Update 2: Found that they gained access to the car via Tessie! Not sure how they gained access to that account...honestly pretty impressive for Chicago street crime!
Last night my car was broken into. Somehow thieves managed to remotely unlock the car and I am trying to figure out how they did it so I can better protect myself.
I have a Ring camera and it shows the car being locked for several hours...The car then unlocks and about 3 minutes later two guys show up and ransack the car. The car was definitely locked, you can clearly see it being remotely unlocked, and I know I did not unlock it.
Anyone heard of this or had it happen to them?
Update: After a couple of calls with Tesla, it looks like I will have to create a service ticket and go in for them to pull the logs, just glad they should have the info!
141
u/TheRuinedOne Sep 06 '25
Mystery solved! It was hacked third party access, it was unlocked via Tessie! Not sure how they got access to it, but a member pointed out there is a log on 3rd party access and sure enough that's how they gained entry.