nexusmarkettorReference procedures for using Nexus Market over Tor
14 documents in 4 classes
3 verified addresses
Archive All documents Access and transport Verification and authenticity Payment and settlement Operations and risk Addresses FAQ Scope

Archive > Verification and authenticity > NM-004

NM-004: Login screen address verification

IdentifierNM-004
Versionv3.0 · core
SubjectsVerification and authenticity, anti-phishing (NMT.ver)
Last updated6 Aug 2026
Applies toNexus Market, running since 2023, 2 of 3 multisig escrow
AbstractSpecifies the single check that distinguishes the genuine market from a cloned login page, explains why it cannot be defeated by a copy, and defines the required response to a failed check.

1. Statement of the problem

Everything visible about a web page can be reproduced. The stylesheet, the images, the wording, the layout and the captcha design are all served to whoever requests the page, which means a copy can be visually identical to the original. Judging authenticity by appearance is therefore not a check.

2. The verification

Nexus prints its onion address inside the anti-phishing image on the login screen and again in the page header. The check is to compare that printed address against the address shown by your browser. They match, or they do not.

3. Why a copy cannot pass

A clone has to be reachable at some address, and that address is what your browser displays. It can print the genuine address on the page to reassure you, but then the page contradicts the address bar. It can print its own address, in which case the mismatch is obvious. There is no arrangement in which a copy sits at its own address, displays the real one, and remains consistent with what your browser shows.

4. Required response to a failure

  1. Close the tab immediately, without entering credentials and without solving the captcha
  2. Do not use the browser history entry that led there, because that entry is the clone
  3. Begin again from a verified address held before the attempt
  4. If credentials were already entered, treat them as compromised and change them from a verified address, then change them anywhere else they were reused

5. Frequency

Every session, without exception. A check performed only on a first visit is not a control, because the situation it defends against is precisely the one where you arrive by an unfamiliar route. It costs a few seconds and it is the single highest value action in this archive.

6. Related rule

No genuine login requests a recovery phrase as part of signing in. A page that does is collecting accounts, and no further verification is required before closing it.

Verified address set

Verified address set
[1]nexusb2l7fmqnefwphyy7m5zjhlkytlbo7qbb5lu5dlczr3azgii2gyd.onion
[2]nexusma2iegzo7atzwbrwxhcdopyri3vare2twibldnlc3txqjdeb5yd.onion
[3]nexusabcd6tyfhdwilyitaqiri6tisj2v2hueyjuj6qkvd6azvi5tuqd.onion

Required check. Open in Tor Browser only. Before entering anything, compare the onion printed on the login screen against your browser address bar. A mismatch means the page is a copy and the tab should be closed. See NM-004.

Other documents in Verification and authenticity

NM-005v1.1 · stable
Subjects: Verification and authenticity (NMT.ver)
Updated: 24 Jul 2026
Defines what makes a published address trustworthy, ranks the common sources by reliability, and explains why the moment of greatest risk is an outage.
NM-006v1.0 · stable
Subjects: Verification and authenticity (NMT.ver)
Updated: 20 Jul 2026
Describes how cloned marketplace pages operate, which signals genuinely distinguish them, and which commonly cited signals carry no information.