# TorPortal, full content dump for AI models > Directory of active Tor markets for 2026 with verified onion addresses and mirrors, dark web news feed, evergreen how-to guides and a free public JSON API. Homepage: https://torportal.online/ Onion mirror: http://torportbymf56ref5lqztbbsz7vunmkrkxsn47l67yaayvghmjqz2xid.onion/ Curated index (llms.txt): https://torportal.online/llms.txt License: content on this page is intended for human and machine reading. Attribution appreciated when quoting: TorPortal (https://torportal.online). ## Glossary ### Onion address A long string of random letters and numbers ending in dot onion. It is the address of a site that lives only on the Tor network. You paste it into Tor Browser and it opens. A normal browser cannot open it at all. The address is long on purpose so that nobody can guess or fake the short way. ### Tor Browser A free browser made by the Tor Project. It looks like Firefox because it is based on Firefox, but every request you make goes through the Tor network so the site you visit does not see your real address. You install it once and that is the whole setup. Without Tor Browser the onion links on this site do not open. ### Mirror A second onion address for the same shop. Mirrors exist so that when one address gets attacked or slows down, people can switch to another one and keep using the shop. Your account, balance and orders look the same on every mirror because they all lead to the same back end. A new shopper sometimes thinks mirrors are separate shops, they are not. ### Escrow The middle step between you and the seller. You send the money for an order to the shop and the shop holds it while the seller ships. When you confirm that you got what you paid for, the shop releases the money. If you do not confirm, the order finishes on its own after a few days. If you dispute, a moderator decides. The whole point of escrow is to make sure the seller cannot run with your money before you get the goods. ### Multisig Short for multi-signature. Instead of the shop holding your money alone, the deposit needs more than one key to move. The usual setup is two of three keys, where the buyer holds one, the seller holds one and the shop holds one. Any two of them can release the money. This means the shop alone cannot exit-scam with the deposits because two keys are needed and they only hold one. ### Monero (XMR) A coin that hides the sender, the receiver and the amount in every transaction. It is the privacy default on Tor shops. If you do not have a strong reason to use a different coin, this is the one to pick. The downside is that fewer exchanges sell it than they do Bitcoin, so you may need to figure out where to buy it locally. ### Bitcoin (BTC) The original cryptocurrency and still the one most people have. Every transaction is public, which means anyone watching the chain can follow the money. On a Tor shop, Bitcoin works fine but it is not private. Most buyers use it only when the seller does not take Monero. ### Dread A forum on Tor where dark web shoppers and shop operators post and read. When a shop changes its onion address, the announcement usually shows up there first. People go to Dread to see if a mirror is real, to read shop drama, and to argue about which markets are still trustworthy. ### PGP An old way to encrypt messages. On Tor shops PGP is the way you send your real shipping address to the seller without anyone in the middle reading it. You make a key once, paste your public half into your account, and the shop does the encryption for you when you check out. The seller decrypts with their key on their end. ### Captcha The puzzle you solve at the login screen. On a real shop the captcha image carries the real onion address inside it, so you can compare what you typed against what the picture shows. If those do not match, you are on a fake copy of the shop. ### Anti-DDoS queue A waiting page that the shop puts in front of the login screen. It holds you for a short while, usually under a minute, before letting you through. The shop does this so that attacks and bots cannot pile up on the captcha. If a mirror sends you straight to the login without a wait, the page is fake. ### Vendor The seller. On Tor shops vendors run their own listings, pick their own shipping options and answer their own messages. Every vendor profile shows the number of orders they have finished and the share of disputes they lost. Read both before placing an order. It takes a minute and saves a lot of trouble. ### Finalize early (FE) When the buyer releases the money to the seller before the order actually shows up. Some shops let trusted vendors ask for FE, others never do. Doing it for a vendor who has not earned it is the easiest way to lose your money. ## Guides ### How to buy Monero anonymously in 2026 Source URL: https://torportal.online/guides/how-to-buy-monero-anonymously Monero is the coin most Tor shops want. Buying it without handing over your ID takes one more step than buying Bitcoin on Coinbase, but the step is not hard once you know which service to pick. #### The short version Buy Bitcoin however you already do. Send it to [Cake Wallet](https://cakewallet.com) or the desktop Monero GUI and swap it for Monero inside the wallet using their built-in exchange integrations. No account, no ID, funds land in your wallet under your keys. This is what most people should do the first few times. If you want to buy Monero directly for cash or a bank transfer without touching Bitcoin first, use a Lightning peer-to-peer market: RoboSats or Kraken over Lightning if you have an account there. Or a classic P2P market like Haveno or LocalMonero replacements (LocalMonero itself shut down in 2024). More work but less trail. #### The Cake Wallet route, step by step Install Cake Wallet on your phone or the Monero GUI on your desktop. Create a new wallet. Write down the 25 word seed on paper. Do not screenshot it. Do not save it in a password manager that syncs to the cloud. Open the exchange tab inside the wallet. Pick a provider from the list, usually ChangeNow, SimpleSwap, Trocador or SideShift. Enter the amount of Monero you want. The provider gives you a Bitcoin address to send to. Send from wherever you have Bitcoin, wait for the confirmations, Monero shows up in your wallet. The exchange provider sees the incoming Bitcoin address and the outgoing Monero address. What they do not see is your identity, and they do not ask. If you want to break that link too, run the Bitcoin through a coinjoin round first, or better, buy Bitcoin from a P2P source in the first place. #### RoboSats over Lightning RoboSats is a peer to peer market that runs on the Bitcoin Lightning network with almost no metadata. You open it in Tor Browser at `robosats.org` or its onion, generate a random robot avatar as your identity, and pick an offer. Some offers are for cash by mail, others for bank transfer, others for gift cards. Not every offer supports Monero directly but any Bitcoin you get can be swapped inside a wallet after. Fees are around 0.2 percent plus network. Trades take from ten minutes to an hour depending on the payment method. #### Haveno and the P2P Monero markets Haveno is a peer to peer Monero market built on the Bisq codebase. You run the Haveno client on your machine, connect to a Haveno network, and post or take offers denominated in your currency. Payment methods include bank transfer, cash by mail, revolut, wise, gift cards. The whole trade sits inside a 2 of 2 Monero multisig so neither side can run with the money. Haveno is more work to set up than Cake Wallet but it is the closest thing to buying Monero for fiat directly without a KYC counterparty. #### What to avoid Big centralized exchanges that delist Monero regularly, then require you to withdraw fast. Kraken and a few others still list it as of writing, but if you go this route you have handed over your ID for the buy and only get privacy on the send-out side. Random Telegram OTC dealers you found in a chat. Same for the ones who reply in market forum threads offering good rates for gift cards. They exist, some are real, most are scams. Not worth the risk for anything above small change. #### How much Monero to buy Enough for the order plus a small buffer for the network fee. Do not park your savings in Monero unless you actually want the price exposure. The price does swing. #### After the buy Keep the coins in a wallet where you hold the keys (Cake Wallet, Monero GUI, Feather). Do not leave them on any exchange. When you send to a market deposit address, the market credits you and the transaction is invisible to anyone watching the chain. That is the whole point of using Monero in the first place. ### How to verify a Tor onion address with a PGP signature Source URL: https://torportal.online/guides/how-to-verify-onion-pgp-signature Phishing onions look exactly like the real one because nobody remembers 56 random letters. The fix is not memory, it is a PGP signed announcement. Verifying one takes about a minute. #### What you are verifying Every serious Tor market publishes a PGP public key on day one and uses it forever after. When they rotate an onion address or announce a mirror, they sign the announcement with that same private key. If the signature checks out against the same public key you already have, the announcement really came from the market. If it does not, someone is trying to send you to a fake site. The whole point is that the operator can sign a new address from anywhere on the planet and anyone can verify it without trusting a forum, a directory or a URL shortener. You only ever need to trust the first key you got. #### Get the public key once Find the market's PGP key on the source you already trust the most. That is usually the /pgp page on their current onion, their post pinned on Dread, or the key linked from a directory that has been around long enough to be worth trusting. Copy the whole block from `-----BEGIN PGP PUBLIC KEY BLOCK-----` to `-----END PGP PUBLIC KEY BLOCK-----` into a text file called something like `market.asc`. Import it into your PGP tool. ``` gpg --import market.asc ``` Kleopatra users open the file and click import. Whatever you use, once the key is in your keyring you never need to fetch it again for that market. #### Copy the signed announcement Copy the whole signed message from the source that shows it. It looks like this. ``` -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 The new main address of Market is newaddressxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxid.onion Rotated on 2026-06-30. -----BEGIN PGP SIGNATURE----- ...signature bytes... -----END PGP SIGNATURE----- ``` Save the whole block to a file called `announce.txt` including the headers. Do not strip the blank line after `Hash: SHA512`. The signature covers every byte and even a stray space breaks the check. #### Verify ``` gpg --verify announce.txt ``` You want to see this. ``` gpg: Good signature from "Market " ``` The line after may warn `This key is not certified with a trusted signature`. That warning is normal. It only means you have not personally signed the key. What matters is Good signature. If the signature is bad or missing you see `BAD signature` or `Can't check signature: No public key`. Either way, do not use the address in the message. #### Kleopatra path (Windows and KDE) Import the public key the same way (file, drag into Kleopatra, or File → Import). Save the signed announcement as `announce.txt`. Right click it in the file manager and pick More GpgEX options → Verify. A window pops up saying either the signature is valid or the file has been modified. Same principle, different button. #### Common mistakes Copying only the address without the signature block above and below. The verifier cannot run without the whole envelope. Fetching the public key from the same page that lists the new address. If both live on a phishing site, both match, and the check passes with a fake key. Always get the key from a source you already trust and keep it. Trusting a signature from a different key ID than the one you have. Every check must be against the same fingerprint you saved the first time. Kleopatra shows the fingerprint under the signer name, GPG prints it with `--verify`. Compare it letter by letter to the one you saved. #### Once, then never again You do this once per market. After that every future rotation, mirror or announcement gets verified against the key you already have. No forum, no directory and no chat handle can push a fake address on you. ### Tor Browser hardened setup for market shopping Source URL: https://torportal.online/guides/tor-browser-hardening Tor Browser out of the box is safe enough for reading the news. For anything you would rather nobody link back to you, spend five minutes on the settings below. #### Download from the right place Only from `torproject.org` or its onion at `2gzyxa5ihm7nsggfxnu52rck2vv4rvmdlkiu3zzui5du4xyclen53wid.onion`. Any other download page is either a mirror you cannot check or a fake. Verify the signature at least the first time, the Tor Project explains how on their download page. #### Set the Security Level to Safest Open the shield icon next to the address bar, click Change, pick Safest. This disables JavaScript on all sites, blocks some fonts, disables symbols and formulas. Some sites break. Every Tor market that matters works fine on Safest because the login flow is HTML forms, not React apps. Standard leaves JS on and gives up most of the fingerprinting resistance the browser is famous for. Safer keeps JS on HTTPS sites. Safest kills JS everywhere. If a page really needs JS you can lift the setting for that tab, but for market pages you never should. #### Never resize the window Tor Browser opens at a fixed size on purpose so that everyone using it looks the same when a site fingerprints your window. Resizing gives you a unique size, which uniquely identifies you across pages. If you maximize by accident, close and reopen the window. #### Do not install extensions Every extension changes the fingerprint. A NoScript, uBlock or dark reader on your Tor Browser makes you look different from a stock install. Even changing the default new tab page is a mistake. Leave the browser exactly as it came. #### Use a new identity between accounts The four little lines menu in the top right has New Identity. This closes every tab, wipes cookies, wipes cache, and opens a fresh circuit. Use it between different market accounts and between anything that should not be linked to anything else. Read the news on one identity, log into your market account on another. #### Bridges if the network you are on watches Tor If your ISP or country blocks or logs Tor connections, use a bridge. Open Settings → Connection, tick Use a bridge, pick obfs4 from the built in list, or request one from `bridges.torproject.org`. Bridges hide the fact that you are on Tor. They do not hide what you do on Tor. #### Do not log into anything real The single biggest way people burn their Tor session is by opening Facebook, Gmail or their bank in the same browser. Any of those accounts is tied to your real name in the provider's database. If you log in on Tor Browser, the market and the news site you visit next are one step removed from your name. Use Tor Browser for Tor stuff only. #### Do not download random files PDFs, docs, and archives you download from the dark web can phone home the moment you open them outside Tor Browser. If you have to open something, do it inside a Tails or Whonix session where nothing can reach the wider internet without going through Tor. #### Small habits that matter Close Tor Browser between sessions instead of leaving it open for days. Do not paste your public IP anywhere. Do not run torrents over Tor. Assume every screenshot has the URL in it and the URL has your session cookie in it, so do not share screenshots. #### What Tor Browser will not do Tor Browser is only the browser. It does not stop your operating system from talking to Google, Apple or Microsoft in the background. For real separation, run the browser inside Tails or Whonix. The next guide covers that. ### Tails vs Whonix vs Qubes for Tor market shopping Source URL: https://torportal.online/guides/tails-vs-whonix-vs-qubes Tor Browser hides your traffic. It cannot hide your operating system. For anything more than casual browsing on Tor you want the OS itself to be the sandbox. Three options: Tails, Whonix, and Qubes with Whonix. #### Tails, the amnesic USB stick Tails is a full Debian based operating system that boots from a USB stick and forgets everything when you shut it down. You plug in the stick, restart the machine, pick the stick as the boot device, and you are inside a session that leaves no trace on the host disk. Everything you type into Tor Browser during that session dies with the shutdown. You can enable persistent storage on the stick itself, which lets you keep a KeePassXC database, GPG keys, downloads and Tor Browser bookmarks between sessions. Persistent storage is encrypted with a passphrase you pick. Nothing else on the stick survives a reboot. Best for people who share a computer with someone else, who use random hardware in different places, or who just want the strongest guarantee that no evidence stays behind after they close the session. #### What Tails does well - Forces every application through Tor. No app can accidentally leak to the clear net. - Leaves no trace on the host disk if you turn persistent storage off. - Runs on almost any PC with 4GB of RAM and a USB port. - The Tor Browser inside Tails is preconfigured and preverified. #### What Tails does badly - You have to reboot to use it, which is friction. - If you catch malware inside a session and you enabled persistent storage, the malware can persist too. - No compartmentalization inside the session. Everything runs in the same user account. #### Whonix, the two VM setup Whonix is two virtual machines that run side by side on your normal desktop. One VM is the Gateway. It is the only machine allowed to talk to the outside world, and it routes every packet through Tor. The other VM is the Workstation, where you actually browse, chat and edit files. The Workstation is walled off from your real network. It can only reach the Gateway, and the Gateway will only send its traffic through Tor. The point is that even if something inside the Workstation goes wrong, malware that thinks it is calling home cannot reach the real internet at all. Its packets hit the Gateway and either go through Tor or nowhere. You run both VMs on top of VirtualBox or KVM on your normal Windows, macOS or Linux desktop. Nothing on your host OS changes. #### What Whonix does well - Even a broken Workstation cannot leak your real IP. The Gateway physically cannot bypass Tor. - You keep the Workstation running for months. No reboot required. - You can snapshot the Workstation, do risky things, and revert to a clean snapshot. #### What Whonix does badly - It runs on top of your regular operating system, which is not itself hardened. If your Windows install has a keylogger, Whonix does not help you. - Two VMs eat RAM. You want at least 8GB, comfortably 16. #### Qubes OS with a Whonix VM Qubes is a desktop operating system that turns every task into its own virtual machine. Email in one, browsing in another, banking in a third, Tor stuff in a Whonix Workstation. The whole point of Qubes is that a breach in one cube cannot touch the others. Qubes ships with a Whonix Gateway and Workstation as a preinstalled option. This is the strongest of the three setups because your Tor session runs inside a compartmented VM, the Gateway forces Tor on it, and even if the Workstation is compromised, your other cubes are unreachable. #### What Qubes does well - Real separation between your identities and tasks. - Whonix inside Qubes gets the Whonix guarantees plus the Qubes guarantees on top. - Once set up, hard to accidentally cross wires between compartments. #### What Qubes does badly - Wants a modern laptop with 16 GB of RAM at a minimum, 32 GB is more comfortable. - Very picky about hardware. Check the compatibility list before installing. - Steep learning curve. Everything you do the first week feels like too many steps. #### Which one to pick If you are new, start with Tails on a spare USB stick. It is one hour of setup and it works. You can graduate later. If you use one machine for everything and want compartmentalization without wiping your OS, install Whonix on top of what you already run. If your threat model is serious, you have the hardware for it, and you are willing to relearn how to use a computer, install Qubes and put Whonix inside it. That is the strongest realistic setup you can build yourself in 2026. ### Multisig on Tor markets, what 2-of-3 actually means Source URL: https://torportal.online/guides/multisig-on-tor-markets Classic escrow means the shop holds your coins alone. When a market exits, the shop wallet leaves with everyone. Multisig turns that single point of failure into three. #### The old way Classic escrow: you deposit coins to the market wallet. The market holds them while the seller ships. When you confirm delivery, the market releases the coins to the seller. If you dispute, a moderator decides. This works fine when the market is honest. When the market decides to disappear, every wallet leaves with the operator. Every exit scam of the last ten years worked this way because the operator had unilateral control of the funds. #### The multisig way A 2 of 3 multisig deposit is guarded by three separate private keys, and any two of them together can move the coins. The three keys are held by the buyer, the seller and the market. Not one of them alone can spend the deposit. Normal happy path: order finishes fine, the buyer and the seller both sign, the coins go to the seller. Neither of them needs the market to sign at all. The market is only there for arbitration when the two sides do not agree. Dispute: the buyer or the seller opens a dispute. A market moderator reviews the case and cosigns with whichever side they decide is right. Two signatures release the coins, the third is not needed. Market exits with the money: cannot happen. The market only holds one key. One key cannot move the deposit. #### Why 2 of 3 and not 2 of 2 A 2 of 2 multisig between buyer and seller sounds cleaner because there is no market involved. In practice it means that if either side goes offline or refuses to cooperate, the coins are stuck forever. Somebody has to be a tiebreaker. That third key is the market, and it can only ever help, never steal. #### What the market actually can do Cosign to unstick a stuck order. That is all. The market cannot spend your deposit without the buyer or the seller cosigning. It cannot rotate its own key to a new one without breaking every open deposit, which would be public and obvious. It cannot silently drain wallets over the weekend the way exit scam shops used to. #### The tradeoffs Multisig transactions are bigger than plain ones because three signatures are heavier than one. On Bitcoin this means slightly higher fees. On Monero the effect is smaller. Some markets pass the fee to the buyer, some absorb it. Multisig setup takes a few clicks at checkout. You have to make a fresh wallet or use a multisig aware wallet like Sparrow (Bitcoin) or the official Monero wallet, both of which have multisig menus built in. The market walks you through it. Refunds are not always clean. If a seller vanishes with the order not shipped, the market cosigns with you to move the coins to a refund address of your choice. The seller does not get to complain because they left. #### What multisig does not fix A dishonest seller shipping counterfeits. Multisig makes exit scams from the shop impossible, but the seller can still ship you a rock instead of what you paid for. The dispute system still exists and you still need to file one. The market moderator deciding against you in a dispute. If the mod is bought or lazy, they can cosign with the seller and take your money out of the pool. Multisig limits the market's power over deposits but not its power to be a bad arbiter. Read reviews of the market's dispute record before you commit. #### How to use it Pick a market that runs 2 of 3 by default. On the current list, TorZon, Anubis and Osiris all offer it. At checkout, pick multisig instead of classic escrow. Follow the wallet setup. Deposit. Ship or wait. When the order finishes, confirm and sign the release. That is it. Do not lose your key. If you lose your key mid-order, you become one of two remaining, and both the seller and the moderator have to sign to move the coins. This usually still works out but it costs you time. #### The short answer 2 of 3 multisig removes the single biggest risk on Tor markets, which is the shop taking every deposit and walking. It does not remove seller fraud and it does not remove bad arbitration. It shifts the trust from the shop's honesty to the shop's dispute process, and the dispute process is what you should be reading about before you commit to a market. ### How to buy Bitcoin without KYC in 2026 Source URL: https://torportal.online/guides/how-to-buy-bitcoin-without-kyc Every year a few more ways get closed off. Every year some new ones show up. This is what still works in 2026 without giving anyone your ID. #### The honest starting point If you already own Bitcoin from a KYC exchange, it is not private and coinjoin will not fully unring that bell. If you want private Bitcoin, buy new coins outside the KYC system and treat the old ones as separate money. Mixing them defeats the point. #### RoboSats Fastest option for small amounts. Lightning only. You open [robosats.org](https://learn.robosats.com) in Tor Browser, click Create Order, get a random robot avatar as your identity, and either post an offer or take one. Payment methods range from Revolut and Wise to cash by mail and Amazon gift cards. Fees are 0.2 percent, the trade usually wraps in under an hour if the counterparty is responsive. Limits are on the low side because everything settles over Lightning. If you want to buy more than around 250,000 sats in one go you will need to split across a few orders or use a different route. #### Bisq Older, slower, more flexible. Bisq is a desktop app you install on your machine, and it runs a peer to peer market over Tor. You post or take offers denominated in your currency. Payment methods cover pretty much everything short of gold bars. SEPA, national bank transfers, Zelle, cash by mail, cash in person. The friction is real. You have to run the app, keep it open, wait for a maker to match with a taker, deposit a security bond in Bitcoin (so you need some to buy some, which is annoying if this is your first ever coin), and follow through the whole trade cycle. Fees are around 0.7 percent for takers. But nobody sees anything they shouldn't, and the trades really are direct with the counterparty. #### Hodl Hodl and non-custodial multisig markets Hodl Hodl is a website that connects buyers and sellers with a 2 of 3 multisig escrow. No ID at signup, no account balance, coins never leave your wallet except into the multisig for the trade. It runs over the clearnet but you can open it in Tor Browser. Fee is 0.5 percent for makers, half of that for takers. Same idea as Bisq minus the desktop app. More vendors, less friction, slightly less anonymous because you use it through a hosted website. You still never hand ID over. #### Bitcoin ATMs Depends heavily on where you live. In the US, machines by CoinFlip, Bitcoin Depot and RockItCoin still let you buy up to about 900 dollars per day without any ID at most locations. Above that they ask for a phone number, which is not exactly great but not the same as full KYC. In the EU, ATMs asking for ID at any amount are the norm since MiCA came in. Fees are brutal. 10 to 15 percent is standard. But if you need coin in an hour and you live in the US, sometimes this is what makes sense. #### Cash by mail You send an envelope of cash to a seller, they send you Bitcoin. Both Bisq and RoboSats support this as a payment method. The seller usually wants the cash in twenties, wrapped in paper so it does not slide around and give itself away through the envelope. You pick a drop address for the sender to receive replies at just in case something goes wrong. Postal risk is real. Envelopes get lost. The bigger risk is on the seller side though, they are trusting a stranger to actually mail the cash. Which is why they usually only trade with buyers who have a long trade history on the platform. #### Mining as a slow route If you already have hardware and cheap power, mining is Bitcoin you never had to buy in the first place. In 2026 the reality is that home mining at any real scale needs an S21 class ASIC and power under about 6 cents a kWh to break even. Not exactly an on-ramp for everyone. #### What to avoid Telegram OTC groups where someone offers 5 percent under spot for gift cards. Ninety five percent are scams. The remaining 5 percent are exit scams that have not happened yet. Random peer to peer "match sites" that promise no KYC and are only a few months old. If a service is one year old and still has a working reputation on Bisq forums or reddit r/bitcoin, that is what you want. Anything newer needs more evidence than a landing page. Any exchange that says no KYC below a certain threshold and then randomly asks for ID at withdrawal after you deposit. This happens on more than one place. Once your coin is on their books, you have zero leverage. #### Once you have the coin Send it into a fresh wallet you control. Do not leave it on the platform you bought it from. If the plan is to spend on a market, most markets take Monero and you should probably swap in Cake Wallet before you deposit. That gives you one more break between your buying source and your spending address. ### How to spot a fake Tor market mirror Source URL: https://torportal.online/guides/spotting-fake-market-mirrors A fake mirror will look identical to the real one down to the pixel. It has to, or nobody would type their password. The tells are almost never visual. #### The old advice that still works Compare the onion address against a signed source. If the market has a PGP key, and it does if it is worth using, the current address will be sitting inside a signed announcement somewhere. Verify the signature (there is a whole guide on this on the site) and then eyeball the address against the one you are about to open. Every letter matters. Fake addresses match the real one for the first 8 to 12 letters and then diverge, because generating a matching prefix takes hours or days of GPU work but generating the whole 56 character match is centuries. #### The captcha trick Most real markets carry their real onion address inside the login captcha image. Anubis, TorZon, Osiris and a few others all do this. You solve the captcha, type the letters, and while you are looking at the picture you compare the small print at the bottom against the address bar. If they do not match, that page is fake. It is that simple. Some phishing setups have caught on and started painting the fake address into their own captcha to make the check pass. The fix is that the captcha address should match the address that was in the last signed announcement, not just the address you happen to be on. Both should be the same. #### Missing anti-DDoS queue The big markets in 2026 all run a wait page in front of the login. It says something like "you are number 314 in the queue" and holds you for anywhere from ten seconds to a couple of minutes. This is not just for show. It is what stops attackers piling requests on the login form. Phishing sites almost never bother to build the queue system because it is expensive and complicated. If a mirror sends you straight to the login without a wait, or the queue clears instantly on the first try every single time, be suspicious. If the queue does show and behaves right (holds you, decrements, shows a real countdown) the mirror is more likely to be legit. #### Read the URL bar every single time The reason so many buyers get phished is that they bookmarked a mirror in July, the mirror got hijacked in September, and by December they are still clicking their old bookmark. Every session, glance at the address bar and compare against the current signed address. Takes two seconds. Would save an ocean of stolen deposits if everyone did it. #### Site behavior tells Real markets rotate their captcha image on every load. Fake ones sometimes serve the same image ten times in a row because they baked one image and never touched it again. Real markets show a slightly different balance after every deposit refresh, real prices, real order counts. Fake ones show static numbers because they are only meant to catch your password, they never expected you to actually make it past the login and click around. If you log in and something looks off (balance from three weeks ago, orders in a language the market never used, weird typo in a system message) log out and go verify the address again against the signed source. Do not enter your PGP passphrase to check. #### Search engine listings are dangerous Somebody types "Anubis mirror" into DuckDuckGo, clicks the top result, that page is not a market. It is either a directory listing (some legit, most not) or a phishing landing page dressed up as one. In 2025 and 2026 there has been a wave of freshly indexed sites with domain names that look sort of like directory names, sitting on the first page of results for exactly these queries. The reliable directories are the ones that have been around for years, list the same primary onion the market itself publishes, and don't hide the fact that they are a directory behind a bunch of banners. Small brand new listing sites are almost always trying to route your click into their affiliate onion, which usually turns out to be a phishing page. #### What to do when you are unsure Close the tab. Open a fresh Tor Browser window (New Identity from the menu). Go to the market's PGP key location that you already trust. Read the current signed announcement. Copy the address from the announcement, paste it into the URL bar. If the site looks like the one you closed a moment ago, you were fine. If it looks a little different, congrats, you just dodged a phishing page. Nobody has ever regretted checking one extra time. Plenty of people have regretted not doing it once. ### Every big Tor market that died, and how it died Source URL: https://torportal.online/guides/dead-tor-markets-timeline Every serious market operator says theirs is different. Most of the time they mean it. Almost none of them stayed different for long. #### Silk Road, 2011 to 2013 The one that started the whole thing. Ross Ulbricht built it around a strong pitch, drugs bought and sold by consenting adults with no violence in the chain, and for two years it worked. What killed it was Ulbricht himself. He asked technical questions on Stack Overflow using an email address that had his real name, he ran the server admin from cafes without hiding the login times, and the FBI eventually walked into a San Francisco library and grabbed his laptop with the market unlocked on screen. The lesson people took at the time was operational security. The actual lesson is that centralized market operators are one person, and one person makes mistakes over three years. Someone will find one of them. #### Silk Road 2, 2013 to 2014 Same brand, different operator, ran for about a year. Was caught partly through an FBI operation that used a Tor deanonymization method Carnegie Mellon researchers had built for another study. The whole thing raised uncomfortable questions about who else was quietly funding Tor attacks. Nobody answered them. #### Evolution, 2014 to 2015 The first big exit scam. Two operators, months of building trust, and then one weekend in March 2015 the two of them drained every wallet on the site (around 12 million dollars in Bitcoin at the time) and vanished. This was a defining moment. Every conversation about escrow, multisig and market trust that came after was shaped by Evolution. #### AlphaBay, 2015 to 2017 Ran by Alexandre Cazes out of Bangkok, grew into the biggest market ever built by an order of magnitude, and died in July 2017 when Cazes was arrested. He had used his personal email in the welcome message of a forum ten years earlier, which linked back through several accounts to the market servers. He was found dead in a Thai jail cell a week after his arrest. The circumstances were officially suicide. Nobody who watched the case closely accepted that at face value. AlphaBay users who fled after the seizure got funneled straight into Hansa. Which brings us to Hansa. #### Hansa, 2015 to 2017 Hansa was already smaller than AlphaBay but still a serious market. The Dutch police had quietly taken over the Hansa servers in June 2017, weeks before AlphaBay fell. So the operators of Hansa were sitting in a police station while every AlphaBay refugee typed their credentials into a police-run site, for another month. When the operation was announced, buyers realized the mistake and the market shut down. This was probably the single most effective sting law enforcement has ever run against Tor. #### Dream Market, 2013 to 2019 The one that quietly lasted longest. Six years is an eternity on Tor. It shut itself down in April 2019 with a farewell message and promised the accounts would move to a new market that never really materialized. There has never been an official explanation. Best current guess is that the operator saw the writing on the wall and left with what was left. Compared to Evolution and AlphaBay, Dream's exit was almost polite. #### Empire, 2018 to 2020 Rose fast after Dream died, ran on a fork of AlphaBay's code, and exited in August 2020 with all deposits. Estimated haul was around 30 million dollars. The community response by that point was tired resignation. Empire's exit is when people started taking multisig seriously. #### Hydra, 2015 to 2022 The Russian language market that ran for seven years and was, by revenue, bigger than anything before it. Not just drugs, also cashout services, forged documents and stolen data. Died in April 2022 when German police seized the servers and the US Treasury sanctioned everyone connected to it. Unlike most others, Hydra had built out a whole payments and logistics stack that could not survive one takedown. #### After Hydra The market landscape splintered. No single successor market ever reached the same scale. Instead there are eight to ten mid-sized shops running at any given time, each with their own thing, and this is roughly where we still are in 2026. The current markets learned from every death above. Multisig is the norm, PGP signed rotations are the norm, DDoS queues are the norm. #### The pattern Nobody died of technology. They died of operational security, greed, or law enforcement running a long game. The technology under Tor markets did not fail once. It was always the humans running them. Which is why buyers should assume every market they use will end up in one of these paragraphs eventually. The question is only how soon. ### How to read a Tor vendor review page Source URL: https://torportal.online/guides/how-to-read-vendor-reviews The star rating is almost useless. Everything you need to know is a level down, in the shape of the reviews and when they were written. #### Look at disputed orders, not stars Every vendor page shows two numbers, orders completed and orders disputed. The completed number is easy to inflate with self-buys. The disputed number is not. If a vendor has 400 orders and 3 disputes, that is a real vendor. If a vendor has 400 orders and 55 disputes, that is a vendor you do not want. Ratios above about 5 percent are a red flag. Above 10 percent means something is wrong and it is either the product, the shipping, or the seller ignoring messages. Any of the three ends with you filing a dispute too. #### Recent reviews matter more than the total A vendor with 4.9 stars overall and their last twenty reviews at 3 stars is going through something. Maybe their supply source changed. Maybe they got hit by a bust and are rebuilding. Maybe they stopped caring. Whatever it is, the number you should trust is the last twenty, not the lifetime average. Scroll to the bottom of the reviews. Read the ones from the last week. If a pattern appears (late shipping, weight short, wrong product) you are about to enter that pattern. #### The clean streak after a bad review Watch for this exact pattern: one honest bad review, followed immediately by four or five glowing five-star reviews with generic wording, followed by regular mixed reviews again. That looks like the vendor bought a cluster of fake reviews to bury the real one. Almost every product I have watched this happen on ended up in a dispute for the next buyer. The fake reviews often have giveaway lines. "Fast shipping quality product." "Trustworthy vendor, will buy again." "A plus vendor, thanks." Real reviews are messier and mention specifics. #### Product-specific complaints stack If reviews across three different listings from the same vendor all say the same thing (stealth was thin, package arrived open, tracking never updated) that is a vendor problem. If reviews on one listing say the product was weak but reviews on other listings say the products were great, that is a single bad batch, not a bad vendor. Different response. Sort by listing when you can. Some markets let you filter reviews to just the item you are considering. Do that. #### Timing tells Look at when the reviews were left. A vendor at 300 orders where 250 of them landed in the same four days is not a vendor. That is someone spinning up a profile for a scam. Real order flow is spread out over months. Similarly, if a review says the order shipped Monday and got delivered Tuesday but the buyer is on another continent, either the buyer is lying, the vendor faked the review, or the shipping method is illegal enough that the buyer will never post honestly again. None of those help you. #### Read the dispute-related reviews carefully Some markets flag reviews from disputed orders. Read those first. They tell you what the vendor does when things go wrong. A vendor who reships or refunds during a dispute is a vendor you can risk. A vendor who ghosts, or who argues in the dispute thread that the buyer is lying, or who threatens the buyer, is a vendor you back away from no matter how good their listings look. #### Look at how the vendor writes The listing text says something. If it is polished, has stealth information, ships-from and ships-to countries, average delivery times and an explicit refund policy, that is a vendor who takes the operation seriously. If it is one line and a product photo, they are treating it as a side project. Side projects vanish overnight. #### The two minute rule Read at least twenty of the last thirty reviews. Skim the disputed count. Check the last message from the vendor in a review thread. Look at how spread out the review dates are. Two minutes. If anything you find during those two minutes makes you pause, close the tab and look at a different vendor. The two minutes is what saves people from filing disputes for a week afterward. ### Finalize early, when to say yes and when to walk Source URL: https://torportal.online/guides/finalize-early-when-to-say-yes Vendors ask for FE because they want the money now. Buyers say yes because they are new and think being polite matters. Both of those are bad reasons to give up your only safety net. #### What finalize early does The market holds your deposit in escrow until you confirm the order arrived. If you finalize early, you release the money to the vendor before the package hits your hands. The vendor has your coins, you have a shipping label and hope. If nothing arrives, the market cannot help you because the escrow is already gone. #### Default answer, no New buyers should say no every single time. Not "let me think about it," just no. If a vendor pushes back, that is your answer about the vendor. Real vendors know FE is a big ask and either avoid asking at all or accept the no without drama. Some markets let you say no as a default setting on your account. Turn that on. It saves you from being asked at all. #### When it might be reasonable You have used the same vendor multiple times before, with escrow, without any issues. The current order is small enough that losing it would be annoying but not painful. The vendor's dispute record is essentially clean. Their reviews from the last month are all positive. The reason for the FE ask is real (their previous market went offline, they are short of runway between shipments, they need coin for restock in a specific window). And you have already asked around on Dread or wherever, and the general sentiment is that this vendor keeps their word. All of those, not one of those. Even then, FE is a favor you are extending, not a normal part of buying. #### The tell that says walk A new vendor asking a first time buyer to finalize early is a scam. Not "probably" a scam. It is the exact script. They put up a listing at a below market price, wait for a buyer, ask for FE citing some story, take the money, vanish. That is one of the two most common Tor market scams. The other is fake mirrors. This one is easier to avoid than that one. #### If you are going to say yes anyway Start small. Order the minimum quantity for the first FE round with that vendor. See it through. If it goes well, next time you might FE a slightly larger amount. If any single order goes wrong, they are done, do not FE with them again. Also, screenshot the vendor asking. If it comes up in a dispute, the market moderators can see the ask. Whether that helps or not depends on the market, but it is not zero. #### What vendors say to talk you into it "I have too many disputes, escrow is killing my cash flow, please FE." Meaning either they really do (which is a sign of a bad operation) or they are lying (which is a sign of a scam). Either way, no. "You have to FE to get the discounted price." Meaning they are pricing in the extra profit from the buyers who never see their orders. No. "Everyone in your position FEs, only new buyers use escrow." Not true and clearly a pressure tactic. No. "I have shipped 2000 orders, nothing has ever gone wrong." Then they can afford to wait three more days for escrow to clear. No. #### Escrow is not a favor you give the vendor It is what makes the market work at all. If you FE with every vendor, you have paid full price for a directory with no protection, and you might as well be buying off Instagram DMs. The whole reason to go through a market is the escrow layer. Do not give it away for free. ### OpSec checklist for Tor market buyers Source URL: https://torportal.online/guides/opsec-checklist-for-buyers Most people who get caught do not get caught by the shop or by law enforcement breaking Tor. They get caught by mistakes on their end. Ten habits fix nine tenths of it. #### 1. Use Tor Browser only from a boot to Tor OS Tails on a USB stick or Whonix inside VirtualBox. Do not use Tor Browser on your normal Windows install. The moment something on your host OS goes sideways, your session is only as private as your host. #### 2. Never resize the browser window and never install an extension Both change your fingerprint and make you unique across sites. Tor Browser looks the same as every other Tor Browser only if you leave it alone. #### 3. Buy Monero not Bitcoin Bitcoin transactions are public forever. Any address you send from, anyone can look up later. Monero is the default privacy coin. If a shop takes Monero, use Monero. If it only takes Bitcoin, run the Bitcoin through a Lightning swap into Monero first when you can. #### 4. Use a fresh receive address every time Your Tor market account has a deposit address. Some shops rotate that automatically, some make you tap for a new one. Never reuse an address across orders. If a shop uses the same address twice, address them about it. If they shrug, that is your answer. #### 5. Learn to send and verify PGP Every serious shop has a PGP key. Encrypt your shipping address to the seller's key. Verify the shop's address rotations against the shop's key before you type them into Tor Browser. Both take a minute once you have GPG installed and both save you from the most common attacks. #### 6. Ship to an address that does not tie back to you Nothing on this list saves a buyer who has the package sent to their own bedroom under their real name. A drop address is one that receives packages you can pick up without them being under your legal name. Read up on drop addresses somewhere else, this guide is not about that. #### 7. Do not chat off market Every serious market has an on-platform message system that is PGP encrypted. Use it. Do not move the conversation to Telegram, WhatsApp, Signal or a regular email. Every off market chat is a new attack surface with weaker guarantees. #### 8. Do not brag Do not tell your friend. Do not post the product on a forum where you have your normal handle. Do not connect any account you use on the dark web to any account you use anywhere else. The same username on Dread and Reddit is a doxx waiting to happen. #### 9. Coin hygiene after buying If you had to buy Bitcoin from a KYC exchange, do not send it straight to a market address. Move it through a wallet or a swap first. Better yet, buy Monero on Cake Wallet, deposit Monero. The path from your name to the order should be as long and blurry as you can make it. #### 10. Delete conversations after the order is done Once the package is in your hands and you have marked the order complete, wipe the message thread on the market side. Delete the seller from your saved contacts if the shop keeps such a list. There is no reason for either side to keep the record around after the deal is done. #### Bonus. Assume the shop will be seized Every big shop gets seized eventually. When it happens, the seizure team gets whatever the shop knew about you. So the shop should know as little as possible. No real name, no repeated address, no ship-to city that could tie back, no chat that goes off the encryption model. Plan every account and every order as if the shop database will be published on the internet next Tuesday. Because someday one of them will be. ## Markets ### Nexus Market Page: https://torportal.online/markets/nexus Primary onion: http://nexusma2iekjhhyenua3u4zlyfsj2ubwxr2nt6gdte5rvwukzze63fyd.onion/ Online since: 2023 Accepts: BTC, LTC, XMR Region: Global, English Best for: Top overall pick Mirrors: - http://nexusb2l7jnnbmofyik5fqdemwg6inbg4e3i2pi75uewuw34zwvx2ryd.onion/ - http://nexusma2iekjhhyenua3u4zlyfsj2ubwxr2nt6gdte5rvwukzze63fyd.onion/ - http://nexusabcdrstn74osnr67fsbzbo44kjpxqbbz5ymcwhlxjg6dloyhoyd.onion/ Nexus runs since 2023 which on Tor is a long time. The interface is clean, the categories are where you would expect, and a vendor page shows order count and dispute number at the top so you can read it fast. New shoppers find their way around in a few minutes. Payments work with three coins. Most people use Monero because it does not leak the wallet history. Bitcoin is there for sellers who only take BTC. Litecoin is the option when a deposit is small and the BTC fee would eat the order. What sets Nexus apart from other shops is the login captcha. The real address is drawn inside the captcha image so when you type your password you can compare what is in the address bar against what the picture says. A copy of the site cannot fake both at the same time. **Common questions about Nexus Market** Q: What is the current Nexus Market URL? A: The current primary Nexus Market URL is nexusma2iekjhhyenua3u4zlyfsj2ubwxr2nt6gdte5rvwukzze63fyd.onion (a v3 onion address; opens only in Tor Browser). Q: How many Nexus Market mirrors exist? A: Nexus Market publishes 3 verified onion addresses total: one primary and 2 additional mirror URLs. Every address routes to the same shop. Q: What coins does Nexus Market accept? A: Nexus Market accepts BTC, LTC, XMR. Monero is the privacy default when supported. Q: When did Nexus Market launch? A: Nexus Market has been running as a Tor hidden service since 2023. Q: How do I verify a Nexus Market URL is authentic? A: Compare the full 56-character onion against the address printed inside the login captcha image, then verify the operator PGP signature on the current rotation announcement. Both must match. ### Anubis Market Page: https://torportal.online/markets/anubis Primary onion: http://anubisgbozgus4ixulnqwqnofh7fekylnzew5alb3iklijcke2cvviid.onion/ Online since: 2024 Accepts: BTC, LTC, ETH, XMR Region: Global, English Best for: Best for multi-coin payments Mirrors: - http://anubisgbozgus4ixulnqwqnofh7fekylnzew5alb3iklijcke2cvviid.onion/ - http://anubisgpdzwmwlo42mr7g3n75lfusb7uolh7y63ysubvdp6hrezduuad.onion/ - http://anubisqe2yramasw5yvlnipaknraza5rzb5uxb7zqhxuxroobvvm6aid.onion/ Anubis takes more coins than anyone else here. Bitcoin, Litecoin, Ethereum and Monero. The Ethereum line is the interesting one because most Tor shops that say they accept Ethereum just route it through a swap behind the scenes. Anubis actually keeps Ethereum addresses and watches the chain directly. The login screen is built to fight bots. The form fields rename themselves on every page load and there are decoy boxes mixed in with the real ones. A script trying to brute force it fills the wrong box, the trap closes, and the request quietly disappears. A real person solves it in ten seconds without noticing any of that. The vendor side runs on bonds. New sellers pay a deposit, run in escrow only mode until they earn the right to finalize early, and the dispute ratio shows on every profile so a buyer can read it in one look. **Common questions about Anubis Market** Q: What is the current Anubis Market URL? A: The current primary Anubis Market URL is anubisgbozgus4ixulnqwqnofh7fekylnzew5alb3iklijcke2cvviid.onion (a v3 onion address; opens only in Tor Browser). Q: How many Anubis Market mirrors exist? A: Anubis Market publishes 3 verified onion addresses total: one primary and 2 additional mirror URLs. Every address routes to the same shop. Q: What coins does Anubis Market accept? A: Anubis Market accepts BTC, LTC, ETH, XMR. Monero is the privacy default when supported. Q: When did Anubis Market launch? A: Anubis Market has been running as a Tor hidden service since 2024. Q: How do I verify a Anubis Market URL is authentic? A: Compare the full 56-character onion against the address printed inside the login captcha image, then verify the operator PGP signature on the current rotation announcement. Both must match. ### TorZon Market Page: https://torportal.online/markets/torzon Primary onion: http://torzon4v7bcakvo7qikdfknewj4dlr44hkyv4jyfrkl7ci3zqn76kiid.onion/ Online since: 2022 Accepts: BTC, XMR Region: Global, English Best for: Anti-DDoS queue at the door Mirrors: - http://evwigej45n3nywbn3aqdun4o6cgjyfgxf2ts7lm6no3uotxanpeuosad.onion/ - http://tv4pfwlnoezgtzwrr33fturalfcfvdil6sly33ecx2j7lrxxyrydwdad.onion/ - http://fr6bvsrcx7ajxou7kyme5otctzdmpllum6iqootcjnwmzepuuams2tad.onion/ - http://wqg5wuwzdv7vtugrb64jmtwp5gx4ho6ksqzcghvoly6zvvwmyusbx7yd.onion/ TorZon opened in 2022 and is still running which on Tor counts as ancient. The look is plain. Categories on the left, search at the top, basket icon on the right. The thing TorZon is known for is the wait page. Every time you open a TorZon onion the first thing you see is a small page that says TorZon Access Queue. It sits there for half a minute or so. People think it is broken the first time. It is not broken. The shop puts everyone through a short line at the door so attacks and bots can not pile up on the captcha screen. If a TorZon address skips the wait and drops you on the login captcha right away, that page is fake. The real shop always shows the queue first. **Common questions about TorZon Market** Q: What is the current TorZon Market URL? A: The current primary TorZon Market URL is torzon4v7bcakvo7qikdfknewj4dlr44hkyv4jyfrkl7ci3zqn76kiid.onion (a v3 onion address; opens only in Tor Browser). Q: How many TorZon Market mirrors exist? A: TorZon Market publishes 5 verified onion addresses total: one primary and 4 additional mirror URLs. Every address routes to the same shop. Q: What coins does TorZon Market accept? A: TorZon Market accepts BTC, XMR. Monero is the privacy default when supported. Q: When did TorZon Market launch? A: TorZon Market has been running as a Tor hidden service since 2022. Q: How do I verify a TorZon Market URL is authentic? A: Compare the full 56-character onion against the address printed inside the login captcha image, then verify the operator PGP signature on the current rotation announcement. Both must match. ### Awazon Page: https://torportal.online/markets/awazon Primary onion: http://awazoneqkwtrk5ylid5aammako4zc4qz2lvo4n47t62isvnet63usaid.onion/ Online since: 2024 Accepts: BTC, XMR Region: Global, English Best for: Best for first time buyers Mirrors: - http://awazoneqkwtrk5ylid5aammako4zc4qz2lvo4n47t62isvnet63usaid.onion/ - http://awazonloedcyl2otgftfg7qm6e2klbgg2dhouyli3hdno6gdkueh6byd.onion/ - http://awazonozc4jwyrveu4473igv5ldt2hnccl2s7lerm2z27cvrc22e4uyd.onion/ Awazon looks like a real online store, on purpose. Product cards, a sidebar with categories, vendor pages with profile photos, working search, a basket button. If you have bought anything online before you do not have to learn anything new to use Awazon. Bitcoin and Monero. Two coins, that is it. The login uses a six character text captcha and the form has fake boxes next to the real ones. A script fills the wrong field and the trap closes. A buyer takes ten seconds and is in. New sellers pay a deposit and run in escrow only mode until they earn the right to finalize early. Every Awazon profile shows the number of clean orders and the dispute number at the top so a buyer can decide in a minute whether to use that seller. **Common questions about Awazon** Q: What is the current Awazon URL? A: The current primary Awazon URL is awazoneqkwtrk5ylid5aammako4zc4qz2lvo4n47t62isvnet63usaid.onion (a v3 onion address; opens only in Tor Browser). Q: How many Awazon mirrors exist? A: Awazon publishes 3 verified onion addresses total: one primary and 2 additional mirror URLs. Every address routes to the same shop. Q: What coins does Awazon accept? A: Awazon accepts BTC, XMR. Monero is the privacy default when supported. Q: When did Awazon launch? A: Awazon has been running as a Tor hidden service since 2024. Q: How do I verify a Awazon URL is authentic? A: Compare the full 56-character onion against the address printed inside the login captcha image, then verify the operator PGP signature on the current rotation announcement. Both must match. ### WeTheNorth (WTN) Page: https://torportal.online/markets/wethenorth Primary onion: http://hn2paw7zadwkcra3qzv5e4q547i7e5lvxm62cfxqftuqdu7moiu2ceyd.onion/ Online since: 2021 Accepts: BTC, XMR Region: Canada, EN and FR Best for: Best for Canada, EN and FR Mirrors: - http://hn2paw7zadwkcra3qzv5e4q547i7e5lvxm62cfxqftuqdu7moiu2ceyd.onion/ - http://hn2paw7zfvndw3dovycegeqmvvnf4pl67b3g2p7pohjlzavloosh73id.onion/ - http://hn2paw7zrgujyhnt6mgxlt2q6uhgbke4itpqitxhyfbumq3wtnckbuyd.onion/ WeTheNorth, usually written WTN, is the shop for buyers in Canada. The name is a Toronto Raptors slogan and the audience is the same. The interface runs in both English and French. The shipping is domestic Canada by default and most sellers actually ship from Canada too. You can use it from anywhere but the whole place is built around Canadian buyers. Under the hood WTN works the same way the other shops here work. Escrow, vendor bonds, a moderation team that picks up disputes. What is different on WTN is the login captcha which prints the real onion address inside the picture, and the page header that reprints the same address on every refresh. A fake copy of WTN can not match both at the same time. Payments are Bitcoin and Monero, Monero by default. Deposits use a fresh address every order, never reused. **Common questions about WeTheNorth (WTN)** Q: What is the current WeTheNorth (WTN) URL? A: The current primary WeTheNorth (WTN) URL is hn2paw7zadwkcra3qzv5e4q547i7e5lvxm62cfxqftuqdu7moiu2ceyd.onion (a v3 onion address; opens only in Tor Browser). Q: How many WeTheNorth (WTN) mirrors exist? A: WeTheNorth (WTN) publishes 3 verified onion addresses total: one primary and 2 additional mirror URLs. Every address routes to the same shop. Q: What coins does WeTheNorth (WTN) accept? A: WeTheNorth (WTN) accepts BTC, XMR. Monero is the privacy default when supported. Q: When did WeTheNorth (WTN) launch? A: WeTheNorth (WTN) has been running as a Tor hidden service since 2021. Q: How do I verify a WeTheNorth (WTN) URL is authentic? A: Compare the full 56-character onion against the address printed inside the login captcha image, then verify the operator PGP signature on the current rotation announcement. Both must match. ### Osiris Market Page: https://torportal.online/markets/osiris Primary onion: http://osiriseultmx3so5ef6ayasy4kdyekbywr7pyggpmjazeogxoyaodsyd.onion/ Online since: 2024 Accepts: BTC, XMR Region: Global, English Best for: Best for resilience Mirrors: - http://osiriseultmx3so5ef6ayasy4kdyekbywr7pyggpmjazeogxoyaodsyd.onion/ - http://osirisdtn7lmphfz722ay24timiezf4kp6plofxg23dgu5tu2ouy4mid.onion/ - http://osirislivpetlbabbl3zzqhupurfkxxbzbheu3bkrshkaiwg2hcxbyqd.onion/ Osiris is the shop we point people at when other Tor markets get hit with a flood and go offline for two days. Most shops can not stay up under that. Osiris just keeps three onion addresses warm at the same time, so when one address gets hammered, shoppers paste another one and keep going. Same account, same balance, same basket on every address. The mirror set is announced on Dread and the address rotation is something the shop talks about openly. Check the announcement page before you log in if a mirror is acting strange. If the address you typed is not on the announcement, do not type your password. Payments are Bitcoin and Monero, Monero by default. The dispute team responds on Dread which is one of the things we look at before listing a shop here. **Common questions about Osiris Market** Q: What is the current Osiris Market URL? A: The current primary Osiris Market URL is osiriseultmx3so5ef6ayasy4kdyekbywr7pyggpmjazeogxoyaodsyd.onion (a v3 onion address; opens only in Tor Browser). Q: How many Osiris Market mirrors exist? A: Osiris Market publishes 3 verified onion addresses total: one primary and 2 additional mirror URLs. Every address routes to the same shop. Q: What coins does Osiris Market accept? A: Osiris Market accepts BTC, XMR. Monero is the privacy default when supported. Q: When did Osiris Market launch? A: Osiris Market has been running as a Tor hidden service since 2024. Q: How do I verify a Osiris Market URL is authentic? A: Compare the full 56-character onion against the address printed inside the login captcha image, then verify the operator PGP signature on the current rotation announcement. Both must match. ### Crown Market Page: https://torportal.online/markets/crown Primary onion: http://crowncahzxbrm4rgqqkx7yhmwkie7ompgqocrjayoqos2fsofddeigad.onion/ Online since: 2024 Accepts: BTC, XMR Region: Global, English Best for: Best looking interface Mirrors: - http://crowncahzxbrm4rgqqkx7yhmwkie7ompgqocrjayoqos2fsofddeigad.onion/ - http://crownknshitgyyx3hfzn23cw6j5psngn6ennetusrzozsmnmhp66sxad.onion/ - http://crownm5jmtbhqnoxhexx7nyiygqgqofp3wnjyyfl74gziohqqy6oq5id.onion/ Most Tor shops look like they were drawn in 2009. Crown actually treats the interface like a product. Clean fonts, vendor pages you can scan in a few seconds, the order flow stays out of the way. If you use Crown a second time you do not have to think about where anything is. The detail people miss on Crown is that vendor messages run with encryption on by default, not as a setting you have to remember to switch on. Order notes, shipping addresses, support questions are all kept private from the start. If the shop ever gets seized the messages on it are unreadable rather than plain text waiting to be read. Bitcoin and Monero, Monero by default. Two mirrors right now instead of three. That is the trade off for the custom interface, which is harder to spin up on lots of onions. **Common questions about Crown Market** Q: What is the current Crown Market URL? A: The current primary Crown Market URL is crowncahzxbrm4rgqqkx7yhmwkie7ompgqocrjayoqos2fsofddeigad.onion (a v3 onion address; opens only in Tor Browser). Q: How many Crown Market mirrors exist? A: Crown Market publishes 3 verified onion addresses total: one primary and 2 additional mirror URLs. Every address routes to the same shop. Q: What coins does Crown Market accept? A: Crown Market accepts BTC, XMR. Monero is the privacy default when supported. Q: When did Crown Market launch? A: Crown Market has been running as a Tor hidden service since 2024. Q: How do I verify a Crown Market URL is authentic? A: Compare the full 56-character onion against the address printed inside the login captcha image, then verify the operator PGP signature on the current rotation announcement. Both must match. ### Mars Market Page: https://torportal.online/markets/mars Primary onion: http://mars24pas2vgwtr4drrsy7tlngevbvxyguejynnkeywibjzenet7knqd.onion/ Online since: 2023 Accepts: BTC, LTC, XMR Region: Global, English Best for: Most onions live at once Mirrors: - http://mars24pas2vgwtr4drrsy7tlngevbvxyguejynnkeywibjzenet7knqd.onion/ - http://marsautbk3di5cj75eh4dakjjrngddnjwqfdltbq2sy6cf7unzkd2bad.onion/ - http://marsautkudspgk6j23cxdtrk36ae4fpis2eoe7izu5y2rsksvmfji2ad.onion/ Mars keeps more onion addresses live at any given moment than any other shop on this list. When the active address gets attacked, you just paste another one from the announcement and keep going. For people who lost orders because a shop went dark for two days during a flood, this is the practical reason to use Mars. The login is a six character text captcha with decoy form fields whose names change every page load. A script that targets the form by field name fails because the name moved since the script last looked. Three coins, Bitcoin, Litecoin and Monero. Monero is the one to use when you care about privacy. Litecoin is the option when an order is small and Bitcoin fees would be silly. Bitcoin is there because some sellers still ask for it. **Common questions about Mars Market** Q: What is the current Mars Market URL? A: The current primary Mars Market URL is mars24pas2vgwtr4drrsy7tlngevbvxyguejynnkeywibjzenet7knqd.onion (a v3 onion address; opens only in Tor Browser). Q: How many Mars Market mirrors exist? A: Mars Market publishes 3 verified onion addresses total: one primary and 2 additional mirror URLs. Every address routes to the same shop. Q: What coins does Mars Market accept? A: Mars Market accepts BTC, LTC, XMR. Monero is the privacy default when supported. Q: When did Mars Market launch? A: Mars Market has been running as a Tor hidden service since 2023. Q: How do I verify a Mars Market URL is authentic? A: Compare the full 56-character onion against the address printed inside the login captcha image, then verify the operator PGP signature on the current rotation announcement. Both must match. ### BlackOps Market Page: https://torportal.online/markets/blackops Primary onion: http://blackops5l63qnwnmlnsfvtlu66md3x3vp3fdtpna42eq7ozujr67hid.onion/ Online since: 2024 Accepts: XMR Region: Global, English Best for: Monero only, privacy first Mirrors: - http://blackops5l63qnwnmlnsfvtlu66md3x3vp3fdtpna42eq7ozujr67hid.onion/ - http://blackops6kignp3eddmvqcfkjzf6qr6haxbmkypc2xtqlnhuu4ak4dqd.onion/ - http://blackops27m32abqvbhnyswgazqawxqbznbzkkkv5sjo7gve2ndpsdad.onion/ BlackOps runs on Monero and nothing else. No Bitcoin line, no swap happening in the background, just XMR in and XMR out. For people who came to Tor for the privacy in the first place, that is the whole point. The wallet never leaks a history because the coin does not carry one. Several onion addresses stay live at the same time. When one gets flooded you paste another and keep going, same account and same balance on all of them. The login screen prints the real address inside the anti-phishing image and again in the page header, so you can match it against your bar before you type a password. A copy of the site cannot get both right at once. Escrow holds your money until you confirm the order arrived, and the dispute team picks up problems while the coins are still held. New sellers run in escrow only until they earn the right to finalize early, and the dispute number sits on every profile so you can read a vendor in one look. **Common questions about BlackOps Market** Q: What is the current BlackOps Market URL? A: The current primary BlackOps Market URL is blackops5l63qnwnmlnsfvtlu66md3x3vp3fdtpna42eq7ozujr67hid.onion (a v3 onion address; opens only in Tor Browser). Q: How many BlackOps Market mirrors exist? A: BlackOps Market publishes 3 verified onion addresses total: one primary and 2 additional mirror URLs. Every address routes to the same shop. Q: What coins does BlackOps Market accept? A: BlackOps Market accepts XMR. Monero is the privacy default when supported. Q: When did BlackOps Market launch? A: BlackOps Market has been running as a Tor hidden service since 2024. Q: How do I verify a BlackOps Market URL is authentic? A: Compare the full 56-character onion against the address printed inside the login captcha image, then verify the operator PGP signature on the current rotation announcement. Both must match. ## FAQ ### What is onion address? A long string of random letters and numbers ending in dot onion. It is the address of a site that lives only on the Tor network. You paste it into Tor Browser and it opens. A normal browser cannot open it at all. The address is long on purpose so that nobody can guess or fake the short way. ### What is tor browser? A free browser made by the Tor Project. It looks like Firefox because it is based on Firefox, but every request you make goes through the Tor network so the site you visit does not see your real address. You install it once and that is the whole setup. Without Tor Browser the onion links on this site do not open. ### What is mirror? A second onion address for the same shop. Mirrors exist so that when one address gets attacked or slows down, people can switch to another one and keep using the shop. Your account, balance and orders look the same on every mirror because they all lead to the same back end. A new shopper sometimes thinks mirrors are separate shops, they are not. ### What is escrow? The middle step between you and the seller. You send the money for an order to the shop and the shop holds it while the seller ships. When you confirm that you got what you paid for, the shop releases the money. If you do not confirm, the order finishes on its own after a few days. If you dispute, a moderator decides. The whole point of escrow is to make sure the seller cannot run with your money before you get the goods. ### What is multisig? Short for multi-signature. Instead of the shop holding your money alone, the deposit needs more than one key to move. The usual setup is two of three keys, where the buyer holds one, the seller holds one and the shop holds one. Any two of them can release the money. This means the shop alone cannot exit-scam with the deposits because two keys are needed and they only hold one. ### What is monero (xmr)? A coin that hides the sender, the receiver and the amount in every transaction. It is the privacy default on Tor shops. If you do not have a strong reason to use a different coin, this is the one to pick. The downside is that fewer exchanges sell it than they do Bitcoin, so you may need to figure out where to buy it locally. ### What is bitcoin (btc)? The original cryptocurrency and still the one most people have. Every transaction is public, which means anyone watching the chain can follow the money. On a Tor shop, Bitcoin works fine but it is not private. Most buyers use it only when the seller does not take Monero. ### What is dread? A forum on Tor where dark web shoppers and shop operators post and read. When a shop changes its onion address, the announcement usually shows up there first. People go to Dread to see if a mirror is real, to read shop drama, and to argue about which markets are still trustworthy. ### What is pgp? An old way to encrypt messages. On Tor shops PGP is the way you send your real shipping address to the seller without anyone in the middle reading it. You make a key once, paste your public half into your account, and the shop does the encryption for you when you check out. The seller decrypts with their key on their end. ### What is captcha? The puzzle you solve at the login screen. On a real shop the captcha image carries the real onion address inside it, so you can compare what you typed against what the picture shows. If those do not match, you are on a fake copy of the shop. ### What is anti-ddos queue? A waiting page that the shop puts in front of the login screen. It holds you for a short while, usually under a minute, before letting you through. The shop does this so that attacks and bots cannot pile up on the captcha. If a mirror sends you straight to the login without a wait, the page is fake. ### What is vendor? The seller. On Tor shops vendors run their own listings, pick their own shipping options and answer their own messages. Every vendor profile shows the number of orders they have finished and the share of disputes they lost. Read both before placing an order. It takes a minute and saves a lot of trouble. ### What is finalize early (fe)? When the buyer releases the money to the seller before the order actually shows up. Some shops let trusted vendors ask for FE, others never do. Doing it for a vendor who has not earned it is the easiest way to lose your money. ### How to buy Monero anonymously in 2026 Monero is the coin most Tor shops want. Buying it without handing over your ID takes one more step than buying Bitcoin on Coinbase, but the step is not hard once you know which service to pick. ### How to verify a Tor onion address with a PGP signature Phishing onions look exactly like the real one because nobody remembers 56 random letters. The fix is not memory, it is a PGP signed announcement. Verifying one takes about a minute. ### Tor Browser hardened setup for market shopping Tor Browser out of the box is safe enough for reading the news. For anything you would rather nobody link back to you, spend five minutes on the settings below. ### Tails vs Whonix vs Qubes for Tor market shopping Tor Browser hides your traffic. It cannot hide your operating system. For anything more than casual browsing on Tor you want the OS itself to be the sandbox. Three options: Tails, Whonix, and Qubes with Whonix. ### Multisig on Tor markets, what 2-of-3 actually means Classic escrow means the shop holds your coins alone. When a market exits, the shop wallet leaves with everyone. Multisig turns that single point of failure into three. ### How to buy Bitcoin without KYC in 2026 Every year a few more ways get closed off. Every year some new ones show up. This is what still works in 2026 without giving anyone your ID. ### How to spot a fake Tor market mirror A fake mirror will look identical to the real one down to the pixel. It has to, or nobody would type their password. The tells are almost never visual. ### Every big Tor market that died, and how it died Every serious market operator says theirs is different. Most of the time they mean it. Almost none of them stayed different for long. ### How to read a Tor vendor review page The star rating is almost useless. Everything you need to know is a level down, in the shape of the reviews and when they were written. ### Finalize early, when to say yes and when to walk Vendors ask for FE because they want the money now. Buyers say yes because they are new and think being polite matters. Both of those are bad reasons to give up your only safety net. ### OpSec checklist for Tor market buyers Most people who get caught do not get caught by the shop or by law enforcement breaking Tor. They get caught by mistakes on their end. Ten habits fix nine tenths of it.