A phishing clone of a darknet market is a copy of the market's interface, hosted at an address that differs from the real one by one or two characters. It looks right at a glance, it takes your password, and it is gone. This is the most common way funds are lost on the dark web, and it is the one that is almost entirely preventable.

How the clones are made

The operator takes the market's front end, hosts it on their own server, and registers an onion address that is close to the real one. The closeness is the trick. A v3 address is 56 characters, and a clone that changes one character near the end looks identical when you scan it, but resolves to a completely different site. The clone does not need to be perfect. It needs to be right enough that you stop checking.

How they reach you

Three channels, in order of frequency. A message in a chat or a forum, from an account that claims to be the market or a staff member, announcing a "new mirror" or a "temporary address". A search result, when the real market is down and you go looking, where the clone is waiting with a title that promises the working link. And a bookmark that has gone stale, pointing at an address that was real last month and is now owned by someone else.

The first two are the active attacks. The third is the passive one, and it is the one that catches people who thought they were careful, because the address was correct once, and it looked correct again.

The check that stops them

Copy the address from a list you trust, never type it. After the page loads, read the address in the bar from the end backwards, and compare it with the one you copied. The backwards read is the habit, because the eye skips differences at the start of a string that it expects to be the same, and it catches them at the end. Five seconds, every login, no exceptions.

The mirror list is the source of truth for the current addresses, and the verification guide covers the deeper check, including the signed announcement.