2026-06-18

Real Nexus Market vs Scam Clones — How to Verify in 30 Seconds

BY MARCUS VALE // Anti Phishing
Real Nexus Market vs Scam Clones — How to Verify in 30 Seconds

A buyer I know typed “nexus market” into a search engine, clicked the third result, and lost $450 in Monero to a clone that mirrored the real login page pixel-for-pixel. The URL had a single extra character – an “i” where an “l” should have been – and the captcha looked identical. Within 30 seconds of opening the page, his wallet was already drained through a forced address-replacement attack. This kind of mistake happens more often than people think, and the difference between a clean transaction and a total loss usually comes down to a few seconds of verification.

Why Clones Are Getting Harder to Spot

Scam operators no longer rely on obvious typos or broken layouts. Modern phishing kits copy the full HTML, CSS, and JavaScript of the real Nexus Market, including the rotating captcha, the PGP-signed welcome message, and even the vendor list. The only differences are usually in the onion URL itself, the deposit address shown at checkout, and sometimes a subtle change in the site’s PGP key fingerprint. Because Tor Browser hides the address bar by default on mobile and some desktop configs, users often don’t notice they’re on the wrong domain until money has already moved.

The real Nexus Market has a strict policy: it never asks you to log in from a link sent via Telegram, Jabber, or email. It never offers a “mirror” outside of its verified .onion address list. If you arrived through any other path – a search engine result, a forum post, a Discord invite – assume the page is hostile until proven otherwise.

Prerequisites Before You Open Any Market

You need Tor Browser 13.5 or newer, downloaded directly from torproject.org and verified against the signature on the download page. Anything older than 13.0 lacks the current v3 onion address handling and may silently downgrade your security. You also need a clean Monero wallet – Feather Wallet 2.6.0 or the official Monero GUI 0.18.4.0 – with a fresh subaddress generated for each market session. Never reuse a wallet address across markets or sessions; address correlation is one of the fastest ways to lose anonymity.

Disable JavaScript globally in Tor Browser before opening any market link. Go to about:config, set javascript.enabled to false, and restart. Most modern markets still function with JS off, and this single setting blocks the majority of clipboard-hijacking and address-swapping attacks that clones use. If a market absolutely requires JS, enable it only for that specific site using the NoScript panel, and never while a wallet address is visible on screen.

The 30-Second Verification Process

Step one: confirm the onion address. The real Nexus Market uses a v3 .onion address that is 56 characters long and ends in .onion. Compare every character against the official list maintained on Dread, the Nexus subdread, and the Tor List directory. A single mismatch – a swapped “0” for “o,” a “rn” that should be “m” – means you are on a clone. Bookmark the verified address and never type it manually again.

Step two: check the PGP-signed login page. The real Nexus Market publishes a PGP key with fingerprint that you can verify independently. Open Kleopatra or GPG4USB, import the key, and confirm the signature on the “About” or “Rules” page. Clones either omit the signature entirely or use a key with a different fingerprint. If the fingerprint doesn’t match what you’ve verified through three independent sources, close the tab immediately.

Step three: inspect the deposit address at checkout. Before sending any XMR, generate a fresh subaddress in your wallet, copy it, and paste it into the market’s deposit field. If the market shows a different address after you paste – or if the clipboard contents change without you doing anything – you are on a phishing site with active clipboard malware. This is the exact attack that drained my friend’s $450.

Scam Comparison

Scam Type How It Works Red Flags How to Avoid
Address Replacement JavaScript on the page silently swaps your copied wallet address with the attacker’s Pasted address differs from what you copied; clipboard contents change Disable JS; manually verify the first and last 4 characters of every address
Fake Login Mirror Phishing site copies the real market’s login page and harvests credentials URL is off by one character; no PGP signature; no v3 .onion Bookmark verified .onion; never click links from forums or search engines
Escrow Bypass Vendor or “support agent” convinces you to finalize early or pay outside escrow Pressure to release funds before delivery; offers to “save fees” Never finalize early; only use the market’s built-in escrow system
Fake Support Impersonator contacts you claiming to be market staff after a small purchase Asks for your order ID and password; offers to “refund” you Real support never asks for passwords; only contact staff via the official ticket system

If You’ve Already Sent Funds

Stop all activity on the site immediately. Do not log in again, do not attempt a “recovery,” and do not respond to anyone claiming they can get your money back – that’s the second wave of the same scam. Save the onion URL, the deposit address you sent to, and any transaction IDs. If you used a custodial exchange to buy the XMR, that exchange’s records now link your identity to the transaction, so your next priority is operational separation: stop using that exchange, rotate any identifiers tied to the purchase, and assume the funds are gone.

Report the clone to the real Nexus Market through their official subdread and to Tor List so the directory can flag it. Most importantly, document exactly which step you missed in the verification process so you don’t repeat it. The 30-second check exists because even experienced users get tired, distracted, or rushed – and the clones are designed to exploit exactly those moments.

Additional Security Recommendations

Run all market sessions from Tails 6.2 or Whonix 17 on a dedicated device that never touches your real-world identity. Never access a market from your regular operating system, even over Tor. Enable Tor Browser’s “Safest” security level, which disables JavaScript on every site by default and blocks fonts that can leak your system fingerprint. Generate a unique username and password for every market – KeePassXC 2.7.10 with a 6-word diceware passphrase handles this without exposing anything to your clipboard.

Finally, treat every link, every address, and every signature as untrusted until you’ve verified it against three independent sources. The 30 seconds it takes is the difference between a normal transaction and an expensive lesson.

Submit Response

REQUIRED FIELDS ARE MARKED *

Tor List – Darknet Markets

LAST REVIEWED: 2026-10-10
Research Disclaimer

This directory is provided strictly for informational and research purposes. DarkScope does not host, operate, or maintain any marketplace. No links on this site lead to illegal content. All .onion addresses are presented as redacted reference data for academic and journalistic research into darknet infrastructure patterns.

Notice

This archive provides no direct links to illegal services, does not facilitate any transactions of any kind, and does not enable access to listed platforms. Address tokens are placeholders for verification reference only. Users are solely responsible for their own actions and jurisdictional compliance.

TOR LIST - DARKNET MARKETS // VERIFICATION ARCHIVE // 2026