2026-07-05

5 Signs a Darknet Market Is a Scam — Legit DNM Checklist

BY GH0STWIRE // Anti Phishing
5 Signs a Darknet Market Is a Scam — Legit DNM Checklist

A buyer I know lost $800 because he trusted a phishing link that looked identical to Nexus Market‘s login page. The URL had one extra character, the captcha loaded from a third-party CDN, and the deposit address was a single-use XMR subaddress that auto-forwarded to an exchange. By the time he noticed the wallet balance hadn’t moved after six hours, the vendor profile had been deleted and the market’s support channel had gone silent.

Why the Scam Checklist Matters

Darknet markets disappear constantly — some get exit-scammed, some get seized, and some never existed in the first place. The difference between losing $50 and losing $800 usually comes down to five verifiable signals. Before depositing funds into any market, run the URL, the escrow model, the vendor verification system, the PGP infrastructure, and the community footprint through the checklist below. If two or more fail, walk away.

This guide assumes you’re already running Tor Browser 13.5+ with the security slider set to “Safest,” have a Tails OS live session or a hardened Whonix workstation, and have generated a Monero wallet using the official CLI or GUI client. If any of that isn’t set up yet, stop here and fix the foundation first — no amount of scam-spotting will save you if your browser leaks your real IP.Sign 1: The URL Doesn’t Match the Canonical Onion Address

Every legitimate market publishes its canonical .onion address through multiple independent channels — their PGP-signed key on a public keyserver, Dread or Torzon-style forum posts from verified staff accounts, and the market’s own clearnet mirror (if one exists). If the URL you’re looking at isn’t listed in at least two of those sources, it’s a phishing mirror. Real markets like Nexus, DarkMatter, and Torzon never rotate their primary onion without a signed announcement posted 48 hours in advance.

Common phishing tricks include adding extra characters (“nexusmarket” vs “nexussmarket”), swapping letters (“torz0n” with a zero), or using a v3 onion that resolves but isn’t signed by the market’s master key. Always verify the address by importing the market’s PGP public key from a keyserver like keys.openpgp.org and checking the signed message yourself in Kleopatra or gpg4win.Sign 2: No Multisig Escrow or Trusted Third-Party Resolution

Legitimate markets offer 2-of-3 multisignature escrow where the buyer, vendor, and market each hold one key. If a dispute arises, two of the three signatures can move the funds — the market can’t steal them unilaterally. Scam markets either skip escrow entirely (“FE only” or Finalize-Early), use a centralized wallet they fully control, or claim to offer multisig but actually route everything through a single hot wallet.

Test the escrow before depositing. Place a small order with a vendor who has 500+ positive feedbacks and confirm the transaction ID appears on the blockchain explorer the market provides. If the market refuses small test orders or pushes hard for FE on every vendor, the escrow system is theater.Sign 3: Vendor Verification Is Cosmetic

Real markets like Nexus and DrugHub require vendors to post a PGP-signed verification message from a staff account before they can list. The signature must verify against the staff key imported from the keyserver, not just a username match. Scam markets show “Verified Vendor” badges that are either self-issued or based on a deposit fee.

Check the vendor’s profile for a PGP field. Click it, copy the key fingerprint, and verify it matches the fingerprint posted on Dread or the market’s official forum thread. If the fingerprint is missing, doesn’t verify, or was registered less than 30 days ago, treat the vendor as unverified regardless of their feedback count.Sign 4: The Market Has No Independent Community Footprint

Search Dread, the Hub, or other independent forums for the market’s name. Legitimate markets have active subforums with thousands of posts, staff participation, and public dispute resolution threads. Scam markets either have no forum presence, a forum that was created last week, or a forum where every post is from the same handful of accounts.

Look for posts older than six months. Real markets accumulate years of community history. If the oldest thread you can find is from last month, the market is either brand new (high risk) or a fresh phishing clone of a seized market.

Sign 5: Support Channels Are Silent or Auto-Reply Only

Open a ticket before depositing. Ask a technical question about the multisig implementation or the PGP verification process. Legitimate markets have staff who respond within 24 hours with specific, technically accurate answers. Scam markets either never respond, send generic copy-paste replies, or close the ticket without addressing the question.

Real markets also publish their support PGP key separately from their main market key. Verify the support key the same way you verified the market URL — through multiple independent sources, not just the market’s own About page.

Scam Comparison

Scam Type How It Works Red Flags How to Avoid
Phishing Mirror Fake .onion URL copies the real market’s login page and steals credentials on submit URL not in PGP-signed announcement; missing or wrong captcha domain; no HTTPS-equivalent certificate Always verify the onion address through the market’s signed PGP key on a public keyserver
Exit Scam Market collects deposits, then disappears overnight with the escrow wallet Sudden promotion of FE-only vendors; withdrawal delays; staff going silent on forums Never leave large balances in market wallets; withdraw to your own XMR wallet after each order
Fake Vendor Profile Scammer creates a vendor account with stolen feedback or bought reviews Feedback all from the same week; no PGP key or unverifiable fingerprint; prices 40%+ below market average Cross-check vendor feedback on independent forums; require PGP-signed order confirmations
Centralized Escrip Theft Market claims multisig but routes funds through a single hot wallet they control No transaction IDs on blockchain explorer; “internal ledger” instead of on-chain escrow Verify each escrow transaction on a Monero block explorer before funding
Malware-laden Mirror Phishing site serves a malicious Tor Browser bundle or exploits a browser vulnerability Site prompts you to download a “required update” or “new Tor version” Never download Tor from a market link; only use torproject.org and verify the signature

If You’ve Already Deposited

Move fast. If you funded the wallet within the last hour, check the deposit address against the market’s signed address list — if it doesn’t match, the funds went to a scammer and are unrecoverable. If the address matched but the market is now unresponsive, document everything (screenshots, transaction IDs, support tickets) and post it publicly on Dread with the market’s signed PGP key attached. Public exposure is the only leverage that sometimes forces a seized market’s admins to release funds.

For the future, set a hard rule: never keep more than one order’s worth of funds in any market wallet. Treat every market balance as already lost. Use multisig whenever available, require PGP-signed communication from every vendor, and verify every URL through at least two independent channels before logging in.

Submit Response

REQUIRED FIELDS ARE MARKED *

Tor List – Darknet Markets

LAST REVIEWED: 2026-09-17
Research Disclaimer

This directory is provided strictly for informational and research purposes. DarkScope does not host, operate, or maintain any marketplace. No links on this site lead to illegal content. All .onion addresses are presented as redacted reference data for academic and journalistic research into darknet infrastructure patterns.

Notice

This archive provides no direct links to illegal services, does not facilitate any transactions of any kind, and does not enable access to listed platforms. Address tokens are placeholders for verification reference only. Users are solely responsible for their own actions and jurisdictional compliance.

TOR LIST - DARKNET MARKETS // VERIFICATION ARCHIVE // 2026