How to Avoid Phishing Sites and Scams on the Dark Web

:shield: How to Avoid Phishing Sites and Scams on the Dark Web

Phishing is one of the most common dangers on the dark web. A fake site may look nearly identical to the real one while secretly stealing usernames, passwords, cryptocurrency, PGP messages, or other sensitive information.

A polished design, working login page, familiar logo, or professional-looking URL does not prove that a site is legitimate.

Golden rule: Never trust an onion address merely because it appears on a directory, forum, search engine, Reddit post, private message, or familiar-looking website. Verify it independently before using it.


1. Start With Established Sources—but Never Trust One Source Completely

Begin with established community forums and link directories such as Dread or Daunt, when they are available and you have independently confirmed their genuine addresses.

However, even a trusted source can be:

  • Cloned by phishers
  • Temporarily compromised
  • Outdated
  • Impersonated through a similar onion address
  • Reached through a fraudulent mirror
  • Supplied with a malicious user-submitted link

A directory listing should be treated as a starting point, not final proof.

Safer link-checking method

  1. Obtain the address from an established source.
  2. Compare it with at least one independent source.
  3. Look for an official PGP-signed announcement.
  4. Verify the signature using a previously authenticated public key.
  5. Compare the complete onion address—not merely its beginning and ending.
  6. Bookmark the verified address inside Tor Browser or add it to your password manager like Gnome Secrets.
  7. Always look out for private links in markets. As these provide the most direct connection to market. Also they will usually work if main link is getting ddos attacked.

Never search Google, Reddit, Telegram, or an ordinary dark-web search engine for a market or service and automatically trust the first result. Phishing pages are frequently promoted through advertisements, fake directories, impersonation accounts, and manipulated search results.

A directory can verify where a link was published. Only a valid signature from an authenticated key can provide stronger evidence about who published it.


2. Inspect the Complete Onion Address Carefully

Modern version 3 onion addresses contain 56 characters before .onion. Phishers create addresses that resemble legitimate ones and rely on users checking only the first or last few characters.

For example, a phishing address may:

  • Share a recognizable prefix
  • Have a similar ending
  • Differ by characters in the middle
  • Be displayed using a misleading hyperlink
  • Appear beside the legitimate site’s name and logo

Before opening or using a site

  • Compare the entire address character by character.
  • Check what is actually in Tor Browser’s address bar.
  • Do not rely on the visible text of a hyperlink.
  • Be suspicious of shortened, redirected, or unusual gateway links.
  • Do not assume that a familiar prefix proves authenticity.
  • Bookmark the address only after verification.
  • Recheck the bookmark after any announced address change.

Copying and pasting reduces typing mistakes, but it does not protect you if the copied source is fraudulent or your clipboard has been altered by malware.

Bookmark safely

Once you have independently verified an onion address:

  1. Bookmark it directly in Tor Browser.
  2. Give the bookmark a clear name.
  3. Use that bookmark instead of repeatedly searching for the site.
  4. Reverify the address if the site announces a migration or replacement mirror.
  5. Never replace a verified bookmark based solely on a private message or unsigned post.

Bookmarks reduce exposure to phishing, but they cannot protect you if the device, browser profile, or original source was already compromised.


3. Use PGP Signatures to Verify Addresses and Announcements

A legitimate service may publish a PGP-signed message containing its official onion addresses, mirrors, canary, or status announcement.

A valid signature can demonstrate that:

  • The message was signed by the corresponding private key.
  • The signed portion has not been altered since it was signed.
  • The address displayed inside the verified message is exactly what the signer included.
  • Learn PGP from our PGP guide in our wiki section.

However, a valid signature is useful only if you already know that the public key truly belongs to the service.

Verify the public key first

Compare the key’s complete fingerprint with copies obtained through multiple independent and previously trusted sources. A phisher can create a new key, sign a fake address, and falsely label the key as “official.”

A “Good signature” from an unknown or unverified key does not prove that the signer is legitimate.

Basic verification process

  1. Obtain the service’s public key from an established source. Such as a market subdread or from the actual market.
  2. Confirm its complete fingerprint through another independent source.
  3. Import the authenticated public key into GnuPG or Kleopatra.
  4. Copy the entire signed announcement without changing it.
  5. Verify the signature.
  6. Confirm that the signer’s fingerprint matches the authenticated key.
  7. Copy the onion address only from the text that the software confirms was signed.

A successful verification should identify a valid signature from the expected key. Stop if you receive:

  • Bad signature
  • Invalid signature
  • No public key
  • An unexpected fingerprint
  • A signature from an unfamiliar identity
  • A message that has been edited or reformatted
  • An onion address outside the verified portion

Do not rely only on the words “PGP signed” printed above a message. Anyone can paste a signature block beneath fraudulent text. Your PGP software must verify it.

GnuPG also cautions that verification requires knowing exactly what was signed and by whom. Read the verification result and the authenticated fingerprint—not merely a green icon or success-looking message. See the GnuPG documentation.


4. Watch for Common Phishing and Scam Red Flags

Phishing sites often look convincing. Behavior and inconsistencies may reveal the scam.

Website red flags

  • The onion address differs from your verified bookmark.
  • The site unexpectedly claims that every known mirror has changed.
  • A login page requests information the real service does not normally require.
  • Your normal credentials suddenly fail on only one mirror.
  • The site repeatedly logs you out and asks you to sign in again.
  • PGP verification or security features are missing or broken.
  • Deposit addresses change unexpectedly.
  • The site requires a payment merely to unlock an account or withdrawal.
  • Links lead through redirects, gateways, or unfamiliar domains.
  • Text contains strange errors, missing pages, or inconsistent branding.
  • An unsigned announcement demands immediate action.
  • The site pressures you to disable security protections or enable unnecessary scripts.

A broken page alone does not prove phishing; legitimate onion services can experience technical problems or attacks. Treat unexplained changes as a reason to stop and investigate.

Social-engineering red flags

  • Someone claiming to be “support” contacts you first.
  • A user offers a special mirror unavailable to everyone else.
  • Someone asks for your password, private key, seed phrase, PIN, or recovery code.
  • You are pressured to act before verifying the information.
  • A message claims your funds or account will disappear unless you pay immediately.
  • Someone promises guaranteed recovery of stolen cryptocurrency.
  • A supposed administrator asks you to install software or run a terminal command.
  • A stranger offers an unbelievable discount, refund, investment, or private deal.
  • A seller or buyer asks you to move communication or payment outside established safeguards.
  • An account uses the same avatar and nearly the same username as a known staff member.

Legitimate staff should never need your password, wallet seed, private key, or PGP private key.


5. Never Trust Unsolicited “Support” Messages

Scammers frequently impersonate administrators, moderators, vendors, recovery specialists, or directory operators.

If someone contacts you claiming to be support:

  1. Do not click the link they provide.
  2. Do not continue through the private message.
  3. Open the site using your independently verified bookmark.
  4. Check the official support process.
  5. Verify announcements and staff identities through established channels.
  6. Report the impersonation attempt to moderators.

A username, profile image, title, or account age is not proof of identity. Look carefully for substituted letters, added punctuation, and recently created accounts.


6. Protect Your Credentials and Wallets

Even careful link verification cannot compensate for poor account security.

  • Use a unique username and password for every service.
  • Generate strong passwords with a trusted password manager.
  • Never reuse a dark-web password on an email, exchange, social-media, or clearnet account.
  • Enable the service’s legitimate multifactor or PGP authentication when available.
  • Never provide a wallet seed, private key, or recovery phrase to a website.
  • Never paste sensitive information into an unknown “verification” tool.
  • Review every cryptocurrency address before sending.
  • Confirm critical addresses through an authenticated source.
  • Treat an unexpected address change as suspicious.
  • Keep only the minimum necessary amount in any custodial account.

Cryptocurrency transactions generally cannot be reversed. If a phishing site receives the funds, recovery services promising to retrieve them are often a second scam.


7. Do Not Let Urgency Override Verification

Scammers deliberately create panic:

  • “Your account will be deleted.”
  • “This mirror expires today.”
  • “Deposit immediately to unlock withdrawals.”
  • “The main site was seized—use this replacement.”
  • “Only a few spots remain.”
  • “Support must verify your wallet.”
  • “You have five minutes to protect your funds.”

Stop whenever a message creates urgency. Open a separate Tor Browser tab, return through your verified bookmark, consult independent sources, and verify any signed announcement.

A legitimate security process should survive a few minutes of careful checking.


8. What to Do If Something Looks Wrong

If you suspect a phishing site:

  1. Stop interacting with it.
  2. Do not submit additional information.
  3. Do not send cryptocurrency.
  4. Record the onion address carefully.
  5. Compare it with your verified bookmark and signed sources.
  6. Warn moderators without reposting it as a clickable “working link.”
  7. Change any password entered on the site.
  8. Change that password anywhere it was reused.
  9. Review legitimate accounts for unauthorized activity.
  10. Assume any seed phrase or private key entered there is compromised.

If a wallet seed or private key was exposed, changing the wallet password is not enough. Create a new wallet with a new seed on a trusted device and move any remaining funds.

If you downloaded or executed anything from the suspected site, stop using the device for sensitive activity until it has been properly assessed.


Quick Safety Checklist

Before trusting an onion site, ask:

  • Did I obtain the address from an established source?
  • Did I compare it with an independent source?
  • Did I inspect the complete onion address?
  • Did I verify a signed announcement?
  • Did I authenticate the signer’s complete key fingerprint?
  • Does the address match my verified bookmark?
  • Is the site behaving as expected?
  • Is anyone pressuring me to act quickly?
  • Am I being asked for information the legitimate service should never need?
  • Have I stopped to investigate anything unusual?

If any answer concerns you, do not proceed.


Final Rule

Verify the source, verify the complete address, verify the PGP signature, and stop when anything changes unexpectedly.

No forum, directory, moderator, search engine, or security tool is infallible. Using multiple independent checks makes it much harder for a single compromised source or convincing clone to fool you.

When uncertain, walking away is safer than gambling with your identity, credentials, or cryptocurrency.


For lawful privacy education, scam prevention, and defensive security purposes.

Last reviewed: August 2026