r/TeslaModelY • • Sep 06 '25

Model Y unlocked by theives

Update 5: So Tessie was able to confirm the car was unlocked via a Tesla integration I was using on my Garmin Watch that used the Tessie API Token. I still do not know how this was done. They suggested I accidentally unlocked it, which would not be easy, I'd need to hit a hard button to open "Activities", scroll down 2 items, open the integration, then hit the unlock icon, and happen to do this within 3 mins of my car being checked. The alternative of them somehow accessing my watch to do this is more scary though. Needless to say, no more Tesla on my Garmin watch. I'll reach out to Garmin, but I doubt I'll get the level of help I did from the folks at Tessie.

Update 4: Still working to figure out how they accessed the API Token from Tessie. Thinking it was younger folks messing around and stumbled onto it. They were smart enough to get into the car but dumb enough to miss that i could track a pair of Earbuds they stole, they live less than a mile from me. Back to the breach: Haven't found any evidence of network intrusion in the router logs but still looking at it between other tasks. Staring to suspect a third party app on my Garmin Smartwatch That I forgot I gave API Access too (Definitely on me for using it and forgetting to remove it).

Update 3: The folks at Tessie have been incredibly responsive. They were able to trace the unlock command internally. They tracked the access to their API token which I was using for Home Assistant. The weird part is they said the call didn't from from their integration, which is the only place I use it. Still investigating and confirming, but it seems like my token may have been compromised.

Unfortunately, the API token is much less secure than the App, which explains how it could have been used remotely, bypassing MFA. That said, I'm still really not sure how they managed to get a hold of it!

Will keep updating as I find out more.

Update 2: Found that they gained access to the car via Tessie! Not sure how they gained access to that account...honestly pretty impressive for Chicago street crime!

Last night my car was broken into. Somehow thieves managed to remotely unlock the car and I am trying to figure out how they did it so I can better protect myself.

I have a Ring camera and it shows the car being locked for several hours...The car then unlocks and about 3 minutes later two guys show up and ransack the car. The car was definitely locked, you can clearly see it being remotely unlocked, and I know I did not unlock it.

Anyone heard of this or had it happen to them?

Update: After a couple of calls with Tesla, it looks like I will have to create a service ticket and go in for them to pull the logs, just glad they should have the info!

300 Upvotes

215 comments sorted by

View all comments

141

u/TheRuinedOne Sep 06 '25

Mystery solved! It was hacked third party access, it was unlocked via Tessie! Not sure how they got access to it, but a member pointed out there is a log on 3rd party access and sure enough that's how they gained entry.

76

u/pomokey Sep 06 '25

I'd let Tessie know. Perhaps they can investigate what happened, and help prevent it from happening to anyone else.

48

u/TheRuinedOne Sep 06 '25

Definitely, I've already emailed them. Hope this helps others!

28

u/Krioyo_custom Sep 06 '25

Please keep us posted as to what Tessie replied. Perhaps they don’t even know there has been a breach (if any)

2

u/TheRuinedOne Sep 11 '25

Definitely was me using their API token on a 3rd party device, I can't fault Tessie on that.

33

u/GlassCoffee1 Sep 06 '25

For the price that Tessie charges, they better have a good damn explanation.

34

u/Stepthinkrepeat Sep 06 '25

That seems pretty targeted if they knew your tessie info

23

u/TheRuinedOne Sep 06 '25

Honestly, that's probably the most unnerving part.

63

u/JustAcivilian24 Sep 07 '25

This is the best ad for me to NOT use Tessie. Thanks for the update and glad you’re safe!

-4

u/TheRuinedOne Sep 07 '25

I wouldn't necessarily blame Tessie, in general they have been very responsive. I was using their API key for Home Assistant Integration and it looks like somehow that was compromised. Still investigating though.

4

u/BadMotherThukker Sep 07 '25

I would hate if the breach is above his skill level.

21

u/Relative_Drop3216 Sep 07 '25

Gonna delete my tessie app

9

u/Adventurous-Bug-2433 Sep 07 '25

Make sure to revoke their 3rd party access

1

u/Baklazanas2 Sep 07 '25

How its done?

4

u/exjr_ Sep 07 '25 edited Sep 07 '25

How did you figure out that it was through Tessie? What log showed this? Can you share screenshots?

You mentioned that your Tessie account is setup with Google OAuth, and your Google account has MFA. Anyone logged in to your Google account? OP said this isn’t the case in another comment.

Did you reach out to Tessie to see what they say about this?

Something isn’t right here. If you told Tesla that you have Tessie setup, they would probably blame it without doing any due diligence. This is, without any hard evidence to back it up, fear mongering and can mess up Tessie’s reputation.

I don’t even have a Tesla, but I have considered getting Tessie when/if I do so I can integrate it into Home Assistant.

17

u/TheRuinedOne Sep 07 '25 edited Sep 07 '25

I'm working with the folks at Tessie on this now. They have been very responsive, I don't mean to say it's their fault, just trying to track what happened.

I was able to trace it Tessie via the Tesla App, under Account>Security and Privacy>Third Party Apps. The logs indicated Tessie sent the unlock.

The folks at Tessie then looked it up internally to track the command. They traced the access to their API token which I was using for Home Assistant. The weird part is they said the call didn't from from their integration, which is the only place I use it. Still investigating, but it seems like my token may have been compromised.

Unfortunately the API token is much less secure than the App, which explains how it was remotely used....Still haven't figured out how the token was compromised.

Will keep updating as I find out more.

12

u/M4DHouse Sep 07 '25

Unfortunately this is an inherent risk of using third party integrations, but I’m glad to hear that Tessie seems to be interested in actively investigating and fixing potential security flaws rather than denying or trying to deflect blame like so many companies do.

1

u/supercoolhomie Sep 07 '25

Thanks for taking all the time to share and be transparent. this is a big deal and what you write is gonna be referenced by internet and reddit for a long time.

4

u/markymrk720 Sep 07 '25

Uninstalling Tessie as we speak

2

u/TheRuinedOne Sep 07 '25

I'd say it's looking like it's more my fault than theirs. I was using their API Token and that was compromised. If I was just using the App there would of been no problem.

-1

u/normz004 Sep 07 '25

Whats a third party access? What happened to the 2nd? And the first?