AWSIncident TeardownsRetrospectives

Tesla's Kubernetes Console Cryptojacked (Feb 2018): Exposed Dashboards, Exposed AWS Keys

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from February 2018, written in 2026 with the benefit of hindsight.

In February 2018, researchers at RedLock disclosed that attackers had broken into Tesla's cloud environment and used it to mine cryptocurrency.

How it happened

Tesla had a Kubernetes administration console that was not password-protected. Within the environment, the attackers found credentials for Tesla's AWS account. They used Tesla's computing resources to run cryptocurrency mining software. The RedLock team also noted that the exposed environment had access to an S3 bucket containing sensitive data, including vehicle telemetry.

How they stayed hidden

The attackers were careful:

  • They ran their own mining pool rather than a well-known one, avoiding IP-based blocklists.
  • They hid the pool's real IP address behind a content delivery network.
  • They limited CPU usage to avoid drawing attention through obvious performance or billing spikes.

Tesla said it fixed the issue within hours of being notified and found no evidence customer data or vehicle safety was affected.

Lessons in hindsight

  • Management interfaces must never be exposed without authentication. Kubernetes dashboards, Jenkins servers and admin consoles are prime targets.
  • Credentials inside clusters are a pivot point. Use workload identity rather than embedding cloud keys in containers.
  • Cryptojacking is often the first visible symptom of a compromise that could have been worse.
  • Monitor resource usage and egress, not just known-bad indicators.

Cryptojacking remained a common outcome of cloud compromises for years, especially through leaked access keys and exposed container services.

tesla cryptojacking2018

More on this story