Market addresses · 3 total

pure .onion, open in Tor Browser
Verifiedv3 .onion
nexusb2l7njnf2i5dm3ushgrwayuicpofzcs4bkknpzfdwwbwbgqwtyd.onion
Verifiedv3 .onion
nexusma2iyspdg2vv5zjk5wgrs4pkmxn3bvuokjtt3wcfudzqfhb3wyd.onion
Verifiedv3 .onion
nexusabcdokpdgsnsxmyfebtdz2p3clqp663qwg4frvkdnmj5plg75id.onion
one character is all it takes

The clone problem

A clone does not have to be perfect. It has to load before you check the address. The whole economics of phishing in this niche run on a single typo, and the person who built the clone is counting on you being one character away from the real thing.

How a clone works

A registrant takes an onion address that is close to a live one. The first half is the same. The second half is not. They copy the login screen. Then they wait. An old post in a blog. A typo in a forwarded message. A bookmark that was cached from a month ago. Every character that gets retyped wrong hands the password to the clone. The clone does not have to look perfect. It has to load first.

Five tells

  1. The address barCheck the first six and the last six characters against the links page. A letter in the middle of an onion address does not forgive typos. The ends are where a transcribed address drifts, and where a clone is least likely to bother matching.
  2. The domainA .com, a .net, a .io login is phishing by definition. The market lives on .onion only. Anything else is a page that wants your PIN and has no route to the market to send it to.
  3. The seed requestThe market never asks for the seed phrase. Not in login, not in support, not in a popup. "Wallet migration" and "security update" are the attacker doing a pump. The moment a page wants the seed, the page is not the market.
  4. The PGP blockThe real market has a key and a signed list, on the verification page. A clone has no key, or a key that is "new" with no history of signatures behind it. A key with no past is a key nobody has used.
  5. The order of the screensThe real market always shows "Checking your browser" and the DDoS page before the login. A clone often hands you the login instantly, because the login is the only screen it built.

The clone that looks right

The hard case. Pixel for pixel the same. An onion address that looks valid. The browser check is there. The DDoS page is there. The sequence is right. This is the one that gets people, because every easy check passes.

The defense is the last six characters against a source you already trust, and the PGP fingerprint of the block on the page, and the Dread thread when the market is quiet longer than usual. When in doubt, the rule is not to check more carefully. The rule is to leave.

Real

  • The .onion in the address bar, first six and last six matching the links page.
  • The browser check screen, then the DDoS page, then the login. The full sequence.
  • A PGP key on the page that matches the fingerprint on the verification page.
  • A signed mirror list behind the address.
  • A login that asks for a PIN and a recovery phrase, and nothing else.

Clone

  • A .com, .net, or .io, or a gateway wrapping the onion.
  • A login that appears the instant the page loads, with no check before it.
  • A popup asking for the seed before anything else.
  • No PGP key, or a key with no signature history.
  • A shorter sequence than the real one. The real one is not short.

After a slip

If you entered your details on a page that felt wrong: change the PIN from an address you have already checked. Look at the balance. Do not make a panicked withdrawal at the first "suspicious login" email, because that email is the second wave of the phishing, not the first. If you did not type the seed, the coins are still yours. The PIN, though, is now someone else's PIN, and the fix is the one that takes a minute, not the one that takes a withdrawal.

The links page has the full addresses and the end character table. The verification page has the key and the signed list. The troubleshooting page covers the case where nothing opens at all, which is a different problem from the one where the wrong thing opens too easily.