OpSec checklist for Tor market buyers
Most people who get caught do not get caught by the shop or by law enforcement breaking Tor. They get caught by mistakes on their end. Ten habits fix nine tenths of it.
1. Use Tor Browser only from a boot to Tor OS
Tails on a USB stick or Whonix inside VirtualBox. Do not use Tor Browser on your normal Windows install. The moment something on your host OS goes sideways, your session is only as private as your host.
2. Never resize the browser window and never install an extension
Both change your fingerprint and make you unique across sites. Tor Browser looks the same as every other Tor Browser only if you leave it alone.
3. Buy Monero not Bitcoin
Bitcoin transactions are public forever. Any address you send from, anyone can look up later. Monero is the default privacy coin. If a shop takes Monero, use Monero. If it only takes Bitcoin, run the Bitcoin through a Lightning swap into Monero first when you can.
4. Use a fresh receive address every time
Your Tor market account has a deposit address. Some shops rotate that automatically, some make you tap for a new one. Never reuse an address across orders. If a shop uses the same address twice, address them about it. If they shrug, that is your answer.
5. Learn to send and verify PGP
Every serious shop has a PGP key. Encrypt your shipping address to the seller's key. Verify the shop's address rotations against the shop's key before you type them into Tor Browser. Both take a minute once you have GPG installed and both save you from the most common attacks.
6. Ship to an address that does not tie back to you
Nothing on this list saves a buyer who has the package sent to their own bedroom under their real name. A drop address is one that receives packages you can pick up without them being under your legal name. Read up on drop addresses somewhere else, this guide is not about that.
7. Do not chat off market
Every serious market has an on-platform message system that is PGP encrypted. Use it. Do not move the conversation to Telegram, WhatsApp, Signal or a regular email. Every off market chat is a new attack surface with weaker guarantees.
8. Do not brag
Do not tell your friend. Do not post the product on a forum where you have your normal handle. Do not connect any account you use on the dark web to any account you use anywhere else. The same username on Dread and Reddit is a doxx waiting to happen.
9. Coin hygiene after buying
If you had to buy Bitcoin from a KYC exchange, do not send it straight to a market address. Move it through a wallet or a swap first. Better yet, buy Monero on Cake Wallet, deposit Monero. The path from your name to the order should be as long and blurry as you can make it.
10. Delete conversations after the order is done
Once the package is in your hands and you have marked the order complete, wipe the message thread on the market side. Delete the seller from your saved contacts if the shop keeps such a list. There is no reason for either side to keep the record around after the deal is done.
Bonus. Assume the shop will be seized
Every big shop gets seized eventually. When it happens, the seizure team gets whatever the shop knew about you. So the shop should know as little as possible. No real name, no repeated address, no ship-to city that could tie back, no chat that goes off the encryption model. Plan every account and every order as if the shop database will be published on the internet next Tuesday. Because someday one of them will be.