Share
CONSUMER ALERT - INVESTMENT FRAUD

Can you still buy pre-IPO SpaceX shares? No, and the offers saying otherwise are a scam

SpaceX has traded publicly on Nasdaq as SPCX since June 12, 2026, which means the pre-IPO window closed before most of these offers were even sent. Netcraft documented the campaign on July 15, 2026: sites impersonating SpaceX and Elon Musk, on domains that also borrow the Fidelity, Robinhood and Adani names, which hand you a counterfeit W-8BEN tax form, ask which investment tier you want, and finish at a cryptocurrency deposit address.

SafeBrowz Threat Research Security ResearchJuly 24, 202612 min read

Verdict:

No, you cannot buy pre-IPO SpaceX shares, because there is no longer a pre-IPO window to buy into. SpaceX listed on Nasdaq under the ticker SPCX on June 12, 2026 at an offer price of $135 a share, so the only way to own it now is to buy SPCX at the market price in an ordinary brokerage account. Now that SPCX is listed, any unsolicited offer of a special SpaceX allocation is fraud. Before the listing there were genuine, tightly regulated secondary channels for accredited investors, and a real one is verified through the platform or broker-dealer running it, never by acting on the email itself. Netcraft documented the campaign on July 15, 2026: portals impersonating SpaceX and Elon Musk, on domains that also borrow the Fidelity, Robinhood and Adani names, walk you through a counterfeit W-8BEN tax form and an investment tier selector, then ask for a Bitcoin, Ethereum or USDT deposit. No regulated brokerage funds a share allocation by having you send crypto to a wallet address it emailed you.

Not sure about a link? SafeBrowz checks it before the page can load. Add to Chrome, free Get the free Android app or scan a URL now →

The IPO was real, which is exactly why the scam works

SpaceX went public. That part is not in dispute, and it is the foundation the fraud is built on. The stock began trading on Nasdaq as SPCX on June 12, 2026 after pricing at $135 a share, and it closed its first session near $161, in what was widely reported as the largest initial public offering on record. Record retail demand was one of the headlines of the week, and many ordinary buyers still ended up holding only a fraction of the shares they had asked for.

That put a lot of first-time buyers in one place at one time, sharing one specific gap in their knowledge: nobody had told them how an IPO actually reaches a retail investor. Netcraft put its finger on the mechanism in its July 15, 2026 report, From Fake W-8BEN Forms to Crypto Deposits: Scammers Exploit SpaceX IPO Hype by Ivan Khamenka. The lure works, the researchers wrote, because IPO participation "is often complex and broker-mediated." A newcomer reasonably expects eligibility checks, tax paperwork and funding instructions. So when a website presents exactly those steps in exactly that order, it feels like process rather than theft.

Then there is the timing. These pages were still advertising access to the SpaceX IPO weeks after the stock had already listed and started trading. If an offer is dated after June 12, 2026 and still uses the words "pre-IPO" or "IPO allocation," you can stop reading right there. The event it claims to give you access to has already happened, in public, on an exchange, at a price anyone can look up.

What the fake allocation portal actually does

Netcraft's write-up lays out an end-to-end funnel, and reading it in order shows how deliberately the money ask is held back until last.

It opens with an email pointing to a fake onboarding page or a W-8BEN-style tax form. Next comes the paperwork, which is the psychological heart of the scheme and is covered in its own section below. Then the site asks you to pick a "target investment tier," or otherwise state how much you intend to put in. Netcraft notes this serves two purposes at once: it nudges you into thinking of the interaction as a real investment decision, and it lets the operators sort their inbound traffic so the highest bidders get the most attention.

Only after all of that does the deposit page appear. On spacexshares[.]xyz, Netcraft found a funding page listing wallet addresses for Bitcoin, Ethereum and USDT, with the Ethereum and USDT addresses identical because USDT is an ERC-20 token on the same chain. At the time the researchers wrote it up, the campaign's Bitcoin address had received 0.14174492 BTC, worth roughly $8,700. That is one address, in one snapshot, from one cluster of sites.

The crypto request is the terminal red flag and it needs no expertise to read. Buying a listed stock is a brokerage transaction settled in dollars from a bank account. There is no version of that process in which Fidelity, Robinhood, or SpaceX itself asks you to send Bitcoin to a wallet address. The moment a share purchase turns into a crypto transfer, the transaction has stopped being an investment and become a donation, because those transfers are irreversible in a way bank payments are not. It is the same one-way door that makes pig-butchering investment cons so destructive.

The counterfeit W-8BEN is the trust device

The form at the center of this campaign is not invented. A W-8BEN is a genuine United States tax form that non-US persons use to certify their foreign status for certain US-source income, and real brokers genuinely do collect it. That authenticity is the entire point: a document you can look up and confirm is real makes the site around it feel real too.

What changes is the context. A legitimate broker asks for a W-8BEN through its own onboarding or document flow, as part of an application you started yourself. It does not email the form to a stranger as a key that unlocks an allocation, and it certainly does not follow the form with a wallet address. Paperwork that arrives before you ever approached the firm, and that terminates in a crypto deposit, is the tell.

This lure has a track record. Proofpoint has tracked a credential-phishing actor it calls TA2730 since June 2025, and one of its most-used themes is a W-8BEN update request sent in the name of an investment firm, with counterfeit portals built for brands including Swissquote and Questrade. We broke down that flavor of the attack in our post on the Questrade broker account phishing email.

Netcraft flags the SpaceX campaign as thematically consistent with that activity but different where it counts: TA2730 harvests investment-account credentials in order to take over the account, whereas these SpaceX portals skip the account entirely and solicit a cryptocurrency deposit directly. Same trust device, shorter path to your money. Recognizing the W-8BEN pattern protects you from both.

Block it at the deposit page, while the money is still yours

SafeBrowz is a free browser extension for Chrome, Firefox and Edge, with Safari pending, plus an Android app. When a link opens a broker-branded investment portal on a domain that firm does not own, SafeBrowz raises a warning before you fill in a tax form or copy a wallet address. Every scam domain named in this article returns a danger verdict in our scanner today, and you can test any of them yourself by clicking the red names in this post. The AI deep scan (Premium, $14.99/year) reads brand-new allocation pages the day they are registered, which matters when a campaign rotates through throwaway domains faster than blocklists refresh.

Chrome Add to Chrome Firefox Add to Firefox Edge Add to Edge Google Play Get it on Google Play

The domain names give the whole thing away

Netcraft published 17 domain indicators for this campaign in a public repository, split into two clusters that tell you something about how the operation is run.

The first cluster is ten long, pseudo-random strings on the .live top-level domain, the kind of throwaway hostname that exists to absorb takedowns and get replaced by morning. The second cluster is the one aimed at humans, and every name in it welds a trusted brand to the event:

  • spacexshares[.]xyz
  • fidelityspacex[.]site and fidelityspacexipo[.]site
  • robinhoodspacex[.]com
  • adanispacex[.]com
  • muskspacexipo[.]vip and muskspacexipo[.]com

Read those the way an investigator does and the pattern is obvious. A brand welded to an event, on a domain the brand does not own. Fidelity's investor site is fidelity.com. Robinhood's is robinhood.com. SpaceX lives at spacex.com. Large regulated financial firms do not launch a separate campaign domain to market someone else's share offering, because their compliance departments would not survive it.

Note carefully what is doing the work there, because it is not the top-level domain. Four of these names lean on a cheap registry, but three of them sit on plain .com: robinhoodspacex[.]com, adanispacex[.]com and muskspacexipo[.]com. A .com costs about the same as a coffee and confers nothing. The reliable tell is the welding, a real firm's name fused to a second company or to the word "IPO" on a domain that firm does not own, and the cheap registry is only a bonus signal when it happens to be there.

There is one more detail worth keeping. Netcraft found that muskspacexipo[.]vip and muskspacexipo[.]com pointed their mail records at mail.musksapcex[.]space, which misspells the company as "sapcex" rather than "spacex." The front door was proofread; the plumbing behind it was not. Small inconsistencies like that are usually where a campaign's real infrastructure shows, and our guide to checking whether a website is a scam walks through the rest of them.

One caveat keeps this rule honest. A company can perfectly well register an event-themed domain in its own name, and SpaceX did exactly that: it ran the offering's retail-facing site at spacexipo.com, an address printed 13 times in the free writing prospectus SpaceX filed with the SEC, and it now redirects to the investor-relations site under spacex.com. So the test is never simply that a domain contains the word "ipo." The test is whether the company itself publishes that address in a place you can check, and whether the name has to borrow a second company's brand to do its persuading. A real firm's own domain does not need Fidelity's name welded onto it.

The last thing this pattern tells you is that it is reusable. Netcraft's own conclusion is that the technique is "not unique to SpaceX" and should be read as "a repeatable fraud model." Swap the company, keep the kit. The next heavily covered listing will get the same treatment, from names assembled out of the same two parts: a real broker and a real company, welded together on a domain that belongs to neither.

How access to a company's shares actually works

The scam runs on a knowledge gap, so here is the part it depends on you not knowing.

Now that SPCX is listed, owning SpaceX is unremarkable. You open or use a normal brokerage account, search the ticker, and buy at whatever the market is charging that minute. There is no allocation to be granted, no portal to be admitted to, no form to unlock, and no cryptocurrency involved anywhere in the process. Anyone insisting otherwise is describing a process that does not exist.

Before a company lists, its shares are unregistered securities and access is genuinely restricted. The SEC's Office of Investor Education and Advocacy is blunt about it in its Pre-IPO Investment Scams investor alert of June 7, 2024: "pre-IPO offerings are not registered with the SEC," and unregistered offerings are prohibited under federal securities law unless an exemption applies. Since many of those exemptions do not let a company offer its shares broadly to the public, the alert reaches a conclusion worth reading twice: "many pre-IPO offerings targeted at the general public may be illegal." It adds a warning that fits this campaign exactly, that "fraudsters may not even own the pre-IPO shares that they are offering."

Nobody behind spacexshares[.]xyz was holding SpaceX stock in escrow for their depositors. There were no shares. There was a wallet address.

The alert also gives you a test you can apply in seconds. Be wary, it says, of any offering that is unregistered and has "no investment limits or net worth or income requirements for investing." Legitimate private placements screen the buyer, because the exemptions they rely on demand it. A mass email that will sell to anyone with a wallet has, by definition, skipped the screening that legitimacy requires. You can read the full alert at investor.gov, and look up any person or firm pitching you through the public databases at sec.gov.

Seven red flags in a share allocation offer

None of these needs a finance background. Any one of them is enough to walk away.

  • It found you. The offer arrived unsolicited, by email, direct message or an advert, rather than from a broker you already use.
  • The domain welds a brand to an event. A real firm's name fused to another company or to the word "IPO" is a manufactured name, not a corporate one. A cheap registry like .site, .vip, .xyz or .live makes it more obvious, but plenty of these sit on ordinary .com, so never let the .com reassure you.
  • A tax form arrives before you ever applied for anything. A W-8BEN emailed to you as the key to an allocation is inverted: real brokers collect it inside an onboarding process you started yourself.
  • It asks your budget before it gives you facts. An "investment tier" selector early in the flow exists to grade you as a target, not to serve you.
  • Funding is crypto. Bitcoin, Ethereum or USDT to a wallet address for a stock purchase is not an unusual payment method, it is the whole scam.
  • Nobody checks whether you should be buying. No income question, no net worth question, no suitability check, no named registered representative you can look up.
  • The clock is running. A closing window, a limited allocation, a tier that is filling up. Urgency exists to stop you from making the checks above.

If you already sent money

The honest answer first: cryptocurrency sent to a wallet controlled by a stranger is normally unrecoverable. There is no chargeback, no reversal, and no support desk with the authority to undo it. Anyone who promises otherwise for a fee is running the second half of the same fraud.

What is still worth doing, in this order:

  • Send nothing further. Expect a follow-up demanding a release fee, a withholding tax, or a verification deposit to free your balance. Every one of those is another theft, and the pattern is the same one we documented in the FBI warning on crypto investment scams.
  • Preserve the evidence. Screenshot the site and the emails, and save the exact URL, the wallet addresses and every transaction hash. That is what investigators can actually trace.
  • Report it. In the United States, file with the SEC at sec.gov/tcr, the FTC at reportfraud.ftc.gov, and the FBI's Internet Crime Complaint Center at ic3.gov. Outside the US, report to your national securities regulator and police cybercrime unit.
  • Tell the exchange. If you bought and sent the crypto through an exchange, report the destination address to them. Exchanges can sometimes flag or freeze funds that arrive on their platform.
  • Assume the contact details are now in circulation. Victim lists get resold, so expect approaches from people offering to recover your funds. Our first 24 hours after a scam guide covers what to lock down.

How SafeBrowz flags a fake share allocation page

SafeBrowz runs a 3-layer detection architecture: Local + APIs + AI. The email lands in your inbox no matter what, but the theft needs a browser, and that is the step SafeBrowz stands in front of.

  • Layer 1 - Local detection: 60+ URL patterns and a 550+ brand database, checking the hostname before the page renders. Robinhood is one of the tracked brands, and a clearly delimited mashup like robinhood-spacex[.]com hard-flags on the brand rule. A run-together name like robinhoodspacex[.]com is deliberately not hard-flagged here, and that restraint is the point. A bare substring match on a brand name hits innocent bystanders: robinhood.org contains the tracked string and belongs to the Robin Hood Foundation, a New York anti-poverty charity with no connection to the brokerage. Rather than guess, this layer hands the ambiguous name down as a signal instead of a verdict.
  • Layer 2 - API checks: the domain is cross-referenced server-side against Google Safe Browsing, PhishTank, URLhaus and ScamAdviser feeds, plus a 30+ scam TLD watchlist that already covers the .site, .xyz and .live registries this campaign leans on. Our own indicator list sits alongside them and absorbs published research like Netcraft's, which is how every domain named in this post returns a danger verdict rather than only the ones tied to a tracked brand. A domain registered days ago that is asking for money is a weighted signal on its own.
  • Layer 3 - AI deep scan (Premium): AI content analysis via our proxy reads the page the way an analyst would. A brokerage logo, an investment tier selector, a W-8BEN-style form and a cryptocurrency deposit address, all on a domain with no relationship to the broker being named. No single element is proof; that combination on that domain is what earns a danger verdict, including on a page registered this morning that no feed has seen yet.

The honest limit: SafeBrowz warns you when the allocation page opens in your browser. It cannot recover cryptocurrency you have already sent, and it does not sit in your email, so the lure still reaches you. What it buys is a hard stop at the exact screen where the money leaves, which is the last moment the decision is still yours.

Detection signatures are derived from threat-intelligence research and our internal brand database, not from user browsing data. SafeBrowz does not store per-user browsing history.

🛡 LIVE CHECK

Check that investment link before you fill in anything

Sent a share offer, an allocation portal or a tax form link? Paste the address here. Our 3-layer engine (Local + APIs + AI) returns a verdict in about 3 seconds. Free, no signup. You can also click any red domain above to run it through the scanner.

Full scan with deep AI analysis → · No URL is logged to your identity.

Frequently asked questions

Can I still buy pre-IPO SpaceX shares?

No. There is no pre-IPO window left to buy into. SpaceX completed its initial public offering and its stock has traded on Nasdaq under the ticker SPCX since June 12, 2026, priced at $135 a share. From that day forward, buying SpaceX means buying SPCX at the market price through an ordinary brokerage account, exactly like any other listed stock. Nobody needs a special allocation portal, an invitation email, a tax form sent to their inbox, or a cryptocurrency deposit. Any site still selling a pre-IPO SpaceX allocation is selling something that does not exist.

Is fidelityspacex[.]site a real Fidelity website?

No. Fidelity's website is fidelity.com, and Robinhood's is robinhood.com. Netcraft published fidelityspacex[.]site, fidelityspacexipo[.]site, robinhoodspacex[.]com, adanispacex[.]com, spacexshares[.]xyz, muskspacexipo[.]vip and muskspacexipo[.]com as indicators from a single fraud campaign on July 15, 2026. A large regulated brokerage does not spin up a separate campaign domain that welds its brand to a company name on a cheap top-level domain. When a page carries a broker's logo, always look at the address bar rather than the artwork, and reach the broker by typing its own domain yourself.

Why would an investment site ask me to fill in a W-8BEN form?

A W-8BEN is a genuine United States tax form that non-US persons use to certify their foreign tax status for certain US-source income, so real brokers do collect it. That is precisely why scammers copy it. The difference is where it appears. A real broker collects the form inside your logged-in account or through its own document workflow, as part of an application you started yourself. A fraudulent site emails you a W-8BEN-style form out of the blue as a gate that supposedly unlocks a share allocation, then follows it with funding instructions. Paperwork that arrives before you ever approached the firm, and that ends at a wallet address, is the scam.

I sent Bitcoin to a SpaceX share allocation page. Can I get it back?

Be prepared for the honest answer: cryptocurrency sent to a wallet controlled by a stranger is normally gone, because those transfers are irreversible and there is no chargeback. Stop sending money immediately and ignore any message demanding a release fee, a tax payment or a verification deposit to free your balance, because that is the second wave of the same fraud. Save the URL, the emails, the wallet addresses and the transaction hashes. Report it to the SEC at sec.gov/tcr, to the FTC at reportfraud.ftc.gov, and to the FBI at ic3.gov, and tell the exchange you sent the funds from.

How can I check whether an investment offer is legitimate?

Start from the assumption that an unsolicited offer is not, then verify from your side rather than theirs. Never use a phone number, link or document that came with the offer. Type the broker's own domain into the address bar and sign in normally to see whether the offer exists in your account. Look up the person and firm in the SEC and FINRA public databases rather than trusting a screenshot of a licence. The SEC's investor alert on pre-IPO scams at investor.gov warns that an unregistered offering with no investment limits and no income or net worth requirements is itself a red flag.

Last updated 2026-07-24

Related SafeBrowz coverage