How to spot a fake Tor market mirror
A fake mirror will look identical to the real one down to the pixel. It has to, or nobody would type their password. The tells are almost never visual.
The old advice that still works
Compare the onion address against a signed source. If the market has a PGP key, and it does if it is worth using, the current address will be sitting inside a signed announcement somewhere. Verify the signature (there is a whole guide on this on the site) and then eyeball the address against the one you are about to open. Every letter matters. Fake addresses match the real one for the first 8 to 12 letters and then diverge, because generating a matching prefix takes hours or days of GPU work but generating the whole 56 character match is centuries.
The captcha trick
Most real markets carry their real onion address inside the login captcha image. Anubis, TorZon, Osiris and a few others all do this. You solve the captcha, type the letters, and while you are looking at the picture you compare the small print at the bottom against the address bar. If they do not match, that page is fake. It is that simple.
Some phishing setups have caught on and started painting the fake address into their own captcha to make the check pass. The fix is that the captcha address should match the address that was in the last signed announcement, not just the address you happen to be on. Both should be the same.
Missing anti-DDoS queue
The big markets in 2026 all run a wait page in front of the login. It says something like "you are number 314 in the queue" and holds you for anywhere from ten seconds to a couple of minutes. This is not just for show. It is what stops attackers piling requests on the login form.
Phishing sites almost never bother to build the queue system because it is expensive and complicated. If a mirror sends you straight to the login without a wait, or the queue clears instantly on the first try every single time, be suspicious. If the queue does show and behaves right (holds you, decrements, shows a real countdown) the mirror is more likely to be legit.
Read the URL bar every single time
The reason so many buyers get phished is that they bookmarked a mirror in July, the mirror got hijacked in September, and by December they are still clicking their old bookmark. Every session, glance at the address bar and compare against the current signed address. Takes two seconds. Would save an ocean of stolen deposits if everyone did it.
Site behavior tells
Real markets rotate their captcha image on every load. Fake ones sometimes serve the same image ten times in a row because they baked one image and never touched it again.
Real markets show a slightly different balance after every deposit refresh, real prices, real order counts. Fake ones show static numbers because they are only meant to catch your password, they never expected you to actually make it past the login and click around.
If you log in and something looks off (balance from three weeks ago, orders in a language the market never used, weird typo in a system message) log out and go verify the address again against the signed source. Do not enter your PGP passphrase to check.
Search engine listings are dangerous
Somebody types "Anubis mirror" into DuckDuckGo, clicks the top result, that page is not a market. It is either a directory listing (some legit, most not) or a phishing landing page dressed up as one. In 2025 and 2026 there has been a wave of freshly indexed sites with domain names that look sort of like directory names, sitting on the first page of results for exactly these queries.
The reliable directories are the ones that have been around for years, list the same primary onion the market itself publishes, and don't hide the fact that they are a directory behind a bunch of banners. Small brand new listing sites are almost always trying to route your click into their affiliate onion, which usually turns out to be a phishing page.
What to do when you are unsure
Close the tab. Open a fresh Tor Browser window (New Identity from the menu). Go to the market's PGP key location that you already trust. Read the current signed announcement. Copy the address from the announcement, paste it into the URL bar. If the site looks like the one you closed a moment ago, you were fine. If it looks a little different, congrats, you just dodged a phishing page.
Nobody has ever regretted checking one extra time. Plenty of people have regretted not doing it once.