Nexus Market — questions & answers

Everything we have on Nexus Market — onion addresses, accepted currencies, phishing protections. Answers compiled from operator-published primary sources.

Nexus Market onion endpoints — verified set

Current v3 onion endpoints for Nexus Market. Verify the full 56-character fingerprint against the operator’s PGP-signed announcement on Dread before logging in. Click any address to open in Tor.

Nexus has been around since 2023. That doesn't sound long until you remember most Tor markets don't last a year. The interface is English-only. Layout's nothing fancy: categories on the side, search up top, vendor pages, account balance in the header. If you've used any other Tor market in the past few years, you already know where everything is.

Sign-up is the usual deal. Pick a username, paste your PGP key, solve a captcha, set a withdrawal PIN. From there it's a normal dashboard. You fund the account by sending crypto to a fresh deposit address that's never reused. BTC credits after a couple confirmations, LTC a bit faster, XMR takes around ten blocks but that's twenty minutes give or take.

Nexus is one of only three markets here that takes Litecoin. That matters more than it sounds. BTC fees can eat a small deposit alive, and LTC sidesteps that without making you figure out Monero. About XMR though — that's what to pick if privacy is the reason you're on Tor at all. The Bitcoin ledger is public and people get traced from it routinely. Monero hides everything at the protocol level.

About phishing. Nexus does the thing where the captcha shows the real onion address baked into the image. A fake site can't easily clone that without holding the key. There's also a banner with the same address on every page. And the operator signs mirror announcements with PGP on Dread. Three layers, takes about a minute to check, and it's the single best use of that minute on this market or any other.

What is the current Nexus Market onion address?

Nexus Market currently publishes three v3 hidden-service endpoints. All three resolve to the same back-end and any of them is the right one to use — the operator keeps several running concurrently so that pressure on a single onion does not take the site off the network.

Each of those is a 56-character v3 fingerprint. Before submitting credentials, verify the full string against the operator’s PGP-signed announcement pinned in their Dread account. The first eight characters are an operator-chosen vanity prefix; phishers can and do generate strings that match the prefix and randomise the rest, so a partial-prefix match is not a verification.

Why three onions?

A single hidden service is cheap to denial-of-service against. Publishing several lets traffic move between them without any client-side reconfiguration; if one address starts misbehaving, paste another from the list above into Tor Browser and continue.

See also

Which cryptocurrencies does Nexus Market accept?

Nexus Market settles in Bitcoin, Litecoin and Monero.

BTC LTC XMR

Notes per currency

Monero (XMR). The default privacy option. Amounts, sender and receiver are hidden at the protocol layer. If you do not have an opinion on which coin to use, Nexus expects this one.

Bitcoin (BTC). Universally accepted and easy to source. Privacy is the trade-off: BTC transactions are public, and forensic services routinely correlate exchange withdrawals with on-chain darknet activity.

Litecoin (LTC). Faster confirmations and lower fees than BTC. Useful for small deposits where BTC network fees would eat the order, but on-chain privacy properties are similar to BTC.

Deposit flow

Deposit addresses are generated freshly per request rather than reused. After the configured number of on-chain confirmations the funds credit the account balance. Withdrawals follow the same per-request fresh-address pattern.

See also

How does Nexus Market protect against phishing?

Three layers, in order of how much they help: the login captcha, the page banner, and the operator’s signed announcements on Dread.

Fingerprint-embedded captcha

The login captcha image carries the canonical v3 onion fingerprint rendered into the image itself, in a font that survives moderate compression and is legible to a human. A phishing front-end that proxies the operator’s captcha will show the operator’s fingerprint, which will mismatch the cloned address bar; a phishing front-end that generates its own captcha image will not be able to embed a matching fingerprint without holding the corresponding private key.

Page banner

The canonical onion is reprinted in the page header on every render. Compare it letter-for-letter against the address bar before logging in. The full string is 56 characters; do not stop at the first eight.

Signed mirror announcements

When the endpoint rotation changes, the operator posts a detached-PGP-signed announcement on their Dread account. Imports the operator’s public key once, verifies signatures forever after. See how to verify a Tor market onion address for the verification workflow.

See also

Background reading