nexusmarkettorReference procedures for using Nexus Market over Tor
14 documents in 4 classes
3 verified addresses
Archive All documents Access and transport Verification and authenticity Payment and settlement Operations and risk Addresses FAQ Scope

Archive > Verification and authenticity > NM-006

NM-006: Identifying a cloned marketplace page

IdentifierNM-006
Versionv1.0 · stable
SubjectsVerification and authenticity, threat description (NMT.ver)
Last updated20 Jul 2026
Applies toNexus Market, running since 2023, 2 of 3 multisig escrow
AbstractDescribes how cloned marketplace pages operate, which signals genuinely distinguish them, and which commonly cited signals carry no information.

1. How a clone operates

A clone serves a copy of the login page at an address the operator controls. It accepts credentials, stores them and typically returns an error, because an error keeps the visitor trying and produces more attempts. Some clones proxy the real market afterwards so the session appears to work, which delays discovery.

2. Signals that identify one

  • The address printed on the page does not match the address bar, which is decisive on its own
  • A request for the recovery phrase at login, which no genuine market makes
  • A demand to lower browser security before the page will function
  • Pressure to act quickly, such as a warning that an account will be closed

3. Signals that carry no information

  • The page looks correct, since the design is downloadable by anyone
  • The captcha appears and functions, because a clone can serve its own
  • A padlock or any browser security indicator, which describes transport rather than identity
  • The address begins with the familiar prefix, since prefixes are cheap to generate and clones use them deliberately

4. Prefix matching in particular

Many people check the first several characters of an address and stop. Vanity prefixes are computationally cheap to produce, and clone operators generate addresses whose openings match the genuine ones for exactly that reason. A partial match is therefore weaker evidence than no match at all, because it produces confidence without support.

5. Consequence

Only two controls in this archive actually distinguish a clone. The provenance of the address, and the login screen comparison. Everything else is either advisory or is a property a copy reproduces without effort.

Verified address set

Verified address set
[1]nexusb2l7fmqnefwphyy7m5zjhlkytlbo7qbb5lu5dlczr3azgii2gyd.onion
[2]nexusma2iegzo7atzwbrwxhcdopyri3vare2twibldnlc3txqjdeb5yd.onion
[3]nexusabcd6tyfhdwilyitaqiri6tisj2v2hueyjuj6qkvd6azvi5tuqd.onion

Required check. Open in Tor Browser only. Before entering anything, compare the onion printed on the login screen against your browser address bar. A mismatch means the page is a copy and the tab should be closed. See NM-004.

Other documents in Verification and authenticity

NM-004v3.0 · core
Subjects: Verification and authenticity (NMT.ver)
Updated: 6 Aug 2026
Specifies the single check that distinguishes the genuine market from a cloned login page, explains why it cannot be defeated by a copy, and defines the required response to a failed check.
NM-005v1.1 · stable
Subjects: Verification and authenticity (NMT.ver)
Updated: 24 Jul 2026
Defines what makes a published address trustworthy, ranks the common sources by reliability, and explains why the moment of greatest risk is an outage.