Phishing is the real threat
More accounts and coins are lost to phishing than to any flaw in a market. A phishing site is a perfect copy of the storefront that changes only two things: the onion address, and the deposit addresses it shows you. Everything else looks right, which is exactly why it works.
How the attack runs
- An attacker stands up a clone at a look-alike onion and pushes it through search ads, forum posts and fake "official link" pages.
- You log in. The clone captures your username and password and forwards them to the real market so your session appears to work.
- You make a deposit. The address shown is the attacker's. The coins are gone and the market never saw them.
The defence, in three seconds
- Source. Copy addresses only from a source you trust: this site over its onion, or the PGP-signed list. Never a search ad.
- Compare. Match the address the login page prints against your browser bar, every session.
- Refuse. No genuine login asks for your recovery mnemonic. A page that does is a clone; close it.
Typing a fifty-six character onion from memory is how you land on a clone with one wrong character. Copy, never type.
Last reviewed 2026-07-13.