Topic: Security & Verification

How do I avoid Tor market phishing sites?

Last reviewed: June 2026

The largest share of money users lose on Tor markets is lost to phishing clones, not to exit scams or law-enforcement seizures. The good news: phishing is the failure mode that is easiest to defend against, because all the checks are mechanical.

Never reach a market through search

A clearnet "first result" for a market name is almost always a clone. Type the onion by hand from a verified source; do not click through search results.

Use a verified source

PGP-signed announcement on the operator’s Dread account. Not Telegram. Not Reddit. Not email. Not chat groups. See how to verify an onion address.

Verify the full 56 characters

A vanity-prefix match (the first 8–12 characters identical) is not a verification. Phishers run vanity generation to match the prefix and randomise the rest, hoping you do not check the full string. Always read all 56 characters.

If you think you got phished

Change passwords on the real marketplace immediately and move any balance off the compromised account. If the phisher captured a PGP-encrypted shipping address from a message you sent through the cloned site, treat that address as burned and use a different drop next time.

See also

The shapes it comes in

A copied login page at a near miss address. A helpful message carrying a working replacement address during an outage. A search result that appears at exactly the moment you go looking. A request for a recovery phrase or a private key, framed as support. They are variations on one idea, which is getting you to act quickly outside your normal habits.

Why vigilance is the wrong defence

Nobody stays alert indefinitely, and the attacks are timed for the moment you are least likely to be. What works instead is a small number of standing rules that do not require a decision. Addresses come from a saved list. Compare the login screen against the address bar every time. Never type a recovery phrase anywhere. Never take an address from something that arrived unprompted.

If you already typed a password into one

Assume it is gone and change it anywhere else you reused it, which is where the real damage usually is. Do not send anything to any address that page gave you. Come back through an address you already had and check the account from there.

The one thing that is never legitimate

A request for a mnemonic, a wallet seed or a private key. There is no service, no support process and no circumstance where a genuine one needs any of them. The request existing is the entire signal and there is nothing further to weigh.