🎣 Anti-Phishing Protection
Learn to identify and avoid phishing attacks targeting TorZon Market users.
Common Attacks
The most damaging phishing attacks are pixel-perfect clones of the real
TorZon login page, hosted on a vanity onion address ground out to start with the same
characters as the real one. Generating a vanity .onion prefix takes real
compute time but nothing exotic — it's a known, automatable attack, which is exactly why
"the address starts right" is worth nothing on its own. Enter credentials there and the
attacker has your username and password in real time; if 2FA is also captured, they can
relay it to the real site before your code expires, turning a captured page into a live
account takeover rather than just a stolen password. Beyond fake login pages, the same
playbook shows up as fabricated mirror lists posted in forums and paste sites, and as direct
messages from "support" or a "trusted vendor" pushing a link — compromised accounts hand out
clone links for a living, so a familiar username sending you a link is not a reason to trust
it.
URL Verification
A Tor v3 onion address is 56 characters plus .onion, generated from the
market's public key, and every one of those characters is load-bearing — there's no
"close enough." Match the full string against our verified mirrors
page, not just the first six or eight characters, since that's precisely the part a
vanity clone gets right on purpose. Visual substitutions matter here too: a zero swapped for
a capital O, a lowercase L for the digit 1, or one transposed pair of characters deep in the
string are all easy to miss at a glance and are the entire reason clones bother with
near-identical addresses instead of obviously different ones. Bookmark the address inside
Tor Browser itself once verified, and treat any other way of arriving at the market — a
search result, a forum post, a private message — as untrusted by default. Run anything
you're unsure about through the link checker before you type a
single credential.
Protection Methods
No single habit closes off phishing entirely, so the working defense is several weak layers stacked together. Bookmark the address in Tor Browser rather than re-searching or re-typing it each visit, since that removes the one moment where a search result or muscle-memory typo could substitute a clone. Keep 2FA active so a captured password alone isn't enough for a full takeover. Check the market's PGP-signed canary or announcement channel before trusting any claimed address change — an operator change is exactly the moment clone operators try to slip in a fake "new official link." And treat any login page that looks or behaves even slightly differently from your last visit — a shifted layout, a missing element, an extra field — as a reason to stop and re-verify rather than a cosmetic update you can ignore.
⚠️ Important Warnings
- 🔍 Match the full 56-character address — a matching prefix means nothing, vanity addresses are trivial to generate
- 💬 A link from a "trusted" contact or vendor is not automatically safe — compromised accounts hand out clone links routinely
- 🔖 Bookmark the verified address in Tor Browser instead of re-searching for it each time
- 🧪 Run any address you're unsure about through the link checker before entering credentials