Primary Endpoint
Blog

How to Spot Phishing Mirrors

Published 2026-08-30

addyrus operates strictly within the US-to-US domestic pipeline, but our digital storefront is visible globally. That visibility makes us a target for clone engines, credential harvesters, and malicious redirects. When you are looking for clean pressed generics or high-purity champagne MDMA, landing on a fake interface means lost coins and compromised fulfilment channel data.

Community reports on Dread and Recon show a spike in sophisticated phishing mirrors targeting the addyrus brand. These clones copy our signature blue #1864af and red #ea1651 layout perfectly. They look identical, but their backend is designed to intercept your PGP keys and drain your Monero. Protecting your setup requires active verification.


The Mechanics of a Darknet Phishing Attack

Phishing in the onion space does not rely on complex exploits. It relies on human error and search engine manipulation. Attackers register similar-looking onion URLs, scrape our live site front-end, and proxy your requests to the real server while swapping out collateral note addresses.

How Proxy Phishing Works

  1. The Bait: You search a public directory or a clearnet forum for addyrus links.
  2. The Interception: You click a link that looks correct but has two characters swapped in the onion address.
  3. The Proxy: The fake site fetches our real inventory in real-time. You log in, but the phisher captures your credentials.
  4. The Swap: When you generate a collateral note address for your entry, the phisher replaces our wallet with their own.

Your transaction goes through on the blockchain, but your addyrus account balance remains zero. The entry is never placed, and your fulfilment channel details are now stored on an attacker's database.


Verifying the Signature: The PGP Proof

Never trust a visual layout. The only absolute proof of identity on the darknet is cryptographic verification. If a mirror cannot prove it controls the master addyrus PGP key, it is a hostile node.

"If you do not verify the PGP signature of your mirror, you are donating your Monero to a scammer. There is no middle ground." — Dread Security Admin

Before entering your credentials or funding your wallet, perform these steps:

  1. Fetch our documented canary or signed mirror list.
  2. Import the trusted addyrus public key into your local GnuPG environment.
  3. Save the signed message containing the current onion address list.
  4. Run the verification command: gpg --verify mirrors.txt.asc
  5. Verify the output displays a "Good signature" from our verified key fingerprint.

If your terminal output shows a bad signature or a key mismatch, close your Tor Browser immediately. Purge your identity and restart your circuit.


Common Red Flags of Fake Mirrors

While cryptographic proof is your primary shield, several operational anomalies can tip you off to a compromised connection.

  • No PGP Signed Message: The mirror does not offer a verification file, or the verification link leads to a 404 error.
  • Static Captchas: Real addyrus infrastructure uses dynamic, rotating security checks to block automated scrapers. Fake mirrors often use static images that accept any input.
  • Pre-filled Monero Addresses: If a collateral note address is displayed immediately without you initiating an entry, the page is a hardcoded fake.
  • Broken PGP 2FA: If you have PGP two-factor authentication enabled (which you should) and the site lets you log in with just a password, you are on a phisher's harvesting page.

Community-Sourced Verification Habits

The darknet community relies on collective defense. Veteran users do not bookmark clearnet link hubs or rely on Google search results to find our shop.

  • Use Trusted Directories Only: Utilize verified aggregators like Daunt, Tor.taxi, or Dread. Cross-reference listings across multiple independent platforms.
  • Keep Private Bookmarks: Once you verify a genuine addyrus onion address via PGP, bookmark it locally in your Tor Browser. Never click links from Reddit, Telegram, or Discord.
  • Check the Onion Header: Train your eyes to read the first 16 characters of our v3 onion address. While brute-forced vanity addresses can mimic the start of our URL, they cannot replicate the entire 56-character string.
  • Isolate Your Sessions: Keep your market browsing separate from your general web surfing. Use a fresh Tor identity for every transaction.

Securing Your Account on the Real Shop

If you have successfully verified the mirror and logged into the genuine addyrus platform, your security protocol does not stop there. You must configure your account to resist future phishing attempts.

Enable PGP 2FA

Navigate to your account settings and input your public PGP key. Enable Two-Factor Authentication. Once active, every login attempt will require you to decrypt a message using your local private key. Because phishing mirrors cannot decrypt this message on the fly without your private key, they cannot complete the login process, rendering captured passwords useless.

Monitor Your entry History

Always verify your active entries. If you funded an address and the entry does not appear in your history within 20 minutes (allowing for block confirmation times), you likely deposited to a hijacked address on a cloned site. Report the incident to our documented support team immediately with the txid and the exact onion link you used.


Operational Security Checklist

Keep this checklist handy every time you prepare to restock your inventory.

  1. Tor Browser Security Level: Set to "Safer" or "Safest" to disable unnecessary Javascript that could leak your IP.
  2. Clean Circuit: Click the padlock icon in your URL bar and select "New Tor Circuit for this Site" to clear any compromised nodes.
  3. Verify Mirror: Run gpg --verify on the mirror list before logging in.
  4. Check Wallet Address: Double-check that your Monero destination address matches the output format of our genuine platform.
  5. Encrypt fulfilment channel Info: Always encrypt your fulfilment address locally using our PGP key before pasting it into the session field. Never rely on any site's "auto-encrypt" feature.

The Bottom Line

Phishing mirrors are a persistent threat, but they are entirely preventable. By taking sixty seconds to verify our PGP signature before you enter your credentials, you completely neutralize the attacker's toolkit. Keep your bookmarks private, enforce PGP 2FA on your addyrus account, and never trust a link from an unverified source. Your security is your responsibility; run the signatures and stay safe.

Comments

No comments yet — be the first.

Leave a comment

Comments are moderated. PGP-encrypted feedback is preferred via /contact/.