🎣 Anti-Phishing Protection

⚠️ Common Attacks

The most damaging phishing attacks are pixel-perfect clones of the real TorZon login page, hosted on a vanity onion address ground out to start with the same characters as the real one. Generating a vanity .onion prefix takes real compute time but nothing exotic — it's a known, automatable attack, which is exactly why "the address starts right" is worth nothing on its own. Enter credentials there and the attacker has your username and password in real time; if 2FA is also captured, they can relay it to the real site before your code expires, turning a captured page into a live account takeover rather than just a stolen password. Beyond fake login pages, the same playbook shows up as fabricated mirror lists posted in forums and paste sites, and as direct messages from "support" or a "trusted vendor" pushing a link — compromised accounts hand out clone links for a living, so a familiar username sending you a link is not a reason to trust it.

💡 Tip: A vanity onion address that starts with "torzon" proves nothing — generating one is a known, automated technique, not a sign of legitimacy.

🔍 URL Verification

A Tor v3 onion address is 56 characters plus .onion, generated from the market's public key, and every one of those characters is load-bearing — there's no "close enough." Match the full string against our verified mirrors page, not just the first six or eight characters, since that's precisely the part a vanity clone gets right on purpose. Visual substitutions matter here too: a zero swapped for a capital O, a lowercase L for the digit 1, or one transposed pair of characters deep in the string are all easy to miss at a glance and are the entire reason clones bother with near-identical addresses instead of obviously different ones. Bookmark the address inside Tor Browser itself once verified, and treat any other way of arriving at the market — a search result, a forum post, a private message — as untrusted by default. Run anything you're unsure about through the link checker before you type a single credential.

💡 Tip: Check the full 56-character address, not the first few letters — that's the part every convincing clone gets right.

🛡️ Protection Methods

No single habit closes off phishing entirely, so the working defense is several weak layers stacked together. Bookmark the address in Tor Browser rather than re-searching or re-typing it each visit, since that removes the one moment where a search result or muscle-memory typo could substitute a clone. Keep 2FA active so a captured password alone isn't enough for a full takeover. Check the market's PGP-signed canary or announcement channel before trusting any claimed address change — an operator change is exactly the moment clone operators try to slip in a fake "new official link." And treat any login page that looks or behaves even slightly differently from your last visit — a shifted layout, a missing element, an extra field — as a reason to stop and re-verify rather than a cosmetic update you can ignore.

💡 Tip: An operator's address-change announcement is the exact moment clone operators try to slip in a fake replacement — verify the PGP signature, don't just trust the timing.

⚠️ Important Warnings

  • 🔍 Match the full 56-character address — a matching prefix means nothing, vanity addresses are trivial to generate
  • 💬 A link from a "trusted" contact or vendor is not automatically safe — compromised accounts hand out clone links routinely
  • 🔖 Bookmark the verified address in Tor Browser instead of re-searching for it each time
  • 🧪 Run any address you're unsure about through the link checker before entering credentials