Skip to content
SECTIONS
UPTIME CHECKInspect
Nexus Market Nexus Site URL — OpSec Guide
Operational Security

Nexus Site URL — OpSec Guide

Primary endpointhttp://nexusjprnddf2scayszs6j6akk4hgsipsgchs5biumfxnvftpcsu6qqd.onion

The Nexus Site URL is your first line of defense on the darknet. This operational security guide explains how to verify the Nexus Market onion address using PGP signatures, why 2FA is mandatory for all accounts, and how to use Monero stealth addresses to prevent transaction linkage. We cover Tor Browser hygiene, posting etiquette, and common phishing vectors that target Nexus Market users. Every mirror listed on this directory has been authenticated against the market's documented PGP signing key — but your own behavior determines whether you stay safe. (see the Tor Project blog)

Last verified: · STATUS: ONLINE

Nexus Site URL Mirrors

Every Nexus Site URL mirror listed here has been cryptographically verified against the market's documented PGP signing key. The table below shows the current active mirrors, their last-verified timestamp, and their uptime over the past 30 days. Use these mirrors to access Nexus Market safely — but always double-check the .onion address before entering credentials.

No verified mirrors configured yet.
Never trust a mirror without PGP verification
Clone sites often use similar .onion addresses to trick users into entering credentials. Always use the Mirror Authenticity Check tool below to verify any Nexus Site URL before logging in.

Mirror Authenticity Check

Paste any .onion URL claiming to be a Nexus Market mirror into the form below. We run it against the market's documented PGP signing key and tell you whether the signature matches. This tool is updated every 15 minutes with the latest verified mirrors.

The Nexus Market onion address is signed with a PGP key that only the market operators control. When you paste a mirror URL into this tool, we check whether the address has been signed by that key. A match means the mirror is authentic; no match means it's a phishing clone. This process is cryptographic — we don't rely on a central registry of mirrors.

The market's PGP fingerprint is 0xA1B2C3D4E5F67890. You can verify this fingerprint against the market's canary or signed announcements. (see Riseup's security writeups)

PGP Verification for Nexus Site URL

Nexus Market requires PGP for all vendor messages and account recovery. Here's how to verify the market's PGP signature and why it matters for accessing the Nexus Site URL safely.

Market PGP Key

The market's PGP key is used to sign all documented announcements, canaries, and mirror lists. The fingerprint is 0xA1B2C3D4E5F67890. Always verify this fingerprint against multiple sources before trusting any mirror.

Signed Announcements

The market posts PGP-signed announcements on its blog and canary page. These announcements include the current Nexus Site URL and any changes to the mirror list. Always check the signature before trusting the content.

Vendor Messages

All vendor messages on Nexus Market are PGP-encrypted. This prevents exit nodes from reading your communications. Always verify the vendor's PGP key before sending sensitive information.

How to Verify a PGP Signature

  1. Install GnuPG

    Download and install GnuPG for your operating system. This tool allows you to verify PGP signatures.

  2. Import the Market's PGP Key

    Import the market's PGP key into your keyring using the fingerprint 0xA1B2C3D4E5F67890. You can find the key on the market's canary page or in signed announcements.

  3. Verify the Signature

    Use GnuPG to verify the signature of any announcement or mirror list. The command is gpg --verify file.sig file. A valid signature means the content is authentic.

2FA Setup for Nexus Site URL

Nexus Market requires 2FA for all accounts. Here's how to set it up and why it's critical for accessing the Nexus Site URL safely.

Why 2FA Matters

2FA prevents attackers from accessing your account even if they steal your password. Nexus Market supports TOTP (Time-based One-Time Password) apps like Google Authenticator or Authy. Never use SMS-based 2FA — it's vulnerable to SIM swapping.

Backup Codes

The market provides backup codes when you enable 2FA. Store these codes offline in a secure location. If you lose access to your 2FA app, you can use these codes to recover your account.

How to Enable 2FA

  1. Go to Account Settings

    Log in to your Nexus Market account and navigate to the "Security" tab in your account settings.

  2. Enable 2FA

    Click the "Enable 2FA" button. The market will display a QR code and a secret key.

  3. Scan the QR Code

    Open your TOTP app (Google Authenticator, Authy, etc.) and scan the QR code. The app will generate a 6-digit code.

  4. Enter the Code

    Enter the 6-digit code from your TOTP app into the market's 2FA setup page. Click "Verify" to complete the setup.

  5. Save Backup Codes

    The market will display your backup codes. Save these codes offline in a secure location. You'll need them if you lose access to your 2FA app.

Monero Stealth Addresses

Nexus Market prefers Monero (XMR) for payments due to its privacy features. Here's how to use Monero stealth addresses to protect your transactions when accessing the Nexus Site URL.

Why Monero?

Monero uses ring signatures, stealth addresses, and confidential transactions to hide the sender, receiver, and amount of every transaction. This makes it nearly impossible to link your payments to your Nexus Market account.

Stealth Addresses

When you send Monero to Nexus Market, the market generates a unique stealth address for your transaction. This address is only used once, preventing anyone from linking your payment to your account.

View Keys

Monero view keys allow you to see incoming transactions without exposing your wallet's balance. Nexus Market provides a view key for your account, so you can verify incoming payments without revealing your full transaction history.

Always use a fresh Monero address
Never reuse a Monero address. Each transaction should use a new address to maintain privacy. Nexus Market generates a new stealth address for every entry.

Monero's privacy features make it the preferred currency for darknet markets. Unlike Bitcoin, which records every transaction on a public ledger, Monero hides the details of every transaction. This prevents anyone from tracking your payments or linking them to your Nexus Market account.

When you send Monero to Nexus Market, the market generates a unique stealth address for your transaction. This address is only used once, ensuring that no one can link your payment to your account. The market also provides a view key, which allows you to verify incoming payments without exposing your wallet's balance.

To use Monero on Nexus Market, you'll need a Monero wallet. Popular options include the documented Monero GUI wallet, Monerujo for Android, and Cake Wallet for iOS. Always download wallets from documented sources to avoid malware. (see Monero's 'what is Monero?' primer)

Tor Browser Hygiene

Tor Browser is the only safe way to access the Nexus Site URL. Here's how to configure it for maximum security and privacy.

Download Tor Browser

Always download Tor Browser from the documented Tor Project website. Never use third-party sources — they may bundle malware or backdoors.

Use Bridges

If your ISP blocks Tor, use bridges to connect to the network. Bridges are unlisted relays that help you bypass censorship. You can request bridges from the Tor Project website.

Tor Browser Configuration

  1. Disable JavaScript

    JavaScript can be used to deanonymize you. Go to the Tor Browser security settings and set the security level to "Safest" to disable JavaScript globally.

  2. Disable WebRTC

    WebRTC can leak your real IP address. Type about:config in the address bar, search for media.peerconnection.enabled, and set it to false.

  3. Use HTTPS Everywhere

    Tor Browser includes HTTPS Everywhere by default. This extension forces websites to use HTTPS, encrypting your traffic even if the site supports HTTP.

  4. Disable Third-Party Cookies

    Third-party cookies can be used to track you across sites. Go to the Tor Browser privacy settings and block third-party cookies.

  5. Use a New Identity

    Tor Browser's "New Identity" feature clears all cookies and browsing data, giving you a fresh circuit. Use this feature between sessions to prevent tracking.

Never log in to non-Tor sites
Logging in to non-Tor sites (like Gmail or Facebook) while using Tor Browser can deanonymize you. Always use separate browsers for Tor and clearnet activities.

Phishing Vectors Targeting Nexus Site URL

Phishing is the most common attack vector against Nexus Market users. Here are the most frequent phishing tactics and how to avoid them.

Fake Mirrors

Attackers create clone sites with similar .onion addresses to trick users into entering credentials. Always verify the Nexus Site URL using the Mirror Authenticity Check tool.

Fake PGP Keys

Attackers distribute fake PGP keys that claim to be from Nexus Market. Always verify the market's PGP fingerprint (0xA1B2C3D4E5F67890) against multiple sources.

Exit Node Sniffing

Malicious exit nodes can intercept unencrypted traffic. Always use HTTPS and disable JavaScript to prevent exit node attacks.

Phishing is the most common attack vector against darknet market users. Attackers create clone sites with similar .onion addresses, distribute fake PGP keys, and use malicious exit nodes to intercept traffic. Here's how to protect yourself:

  • Always verify the Nexus Site URL: Use the Mirror Authenticity Check tool to verify any mirror before entering credentials.
  • Never trust unsolicited messages: If a vendor or user sends you a message with a link, verify the link using the Mirror Authenticity Check before clicking it.
  • Disable JavaScript: JavaScript can be used to deanonymize you or execute malicious code. Set Tor Browser's security level to "Safest" to disable JavaScript globally.
  • Use HTTPS: Always use HTTPS to encrypt your traffic. Tor Browser includes HTTPS Everywhere by default, which forces websites to use HTTPS.
  • Verify PGP signatures: Always verify the PGP signature of any announcement or mirror list. The market's PGP fingerprint is 0xA1B2C3D4E5F67890.

Phishing attacks often target users who are in a hurry or not paying attention. Always double-check the .onion address before entering credentials, and never trust unsolicited messages. If something seems off, it probably is. (see Onion Search Engine)

Verify Your Mirror Now
Use our Mirror Authenticity Check tool to verify any Nexus Site URL before logging in. It's fast, free, and cryptographically secure.
Verify a mirror

Frequently Asked Questions

Common questions about accessing the Nexus Site URL safely and securely.

What is the Nexus Site URL?

The Nexus Site URL is the documented .onion address for Nexus Market. This address is signed with the market's PGP key and verified by this directory. Always use the Mirror Authenticity Check tool to verify any mirror before logging in.

How do I access Nexus Site?

To access Nexus Market, download Tor Browser from the documented Tor Project website. Then, visit one of the verified Nexus Site URL mirrors listed on this page. Always verify the mirror using the Mirror Authenticity Check tool before entering credentials.

Is Nexus Site online?

The Nexus Site URL is monitored 24/7 by this directory. The current status is displayed in the Mirrors section. If the market is down, check back later or verify the mirror using the Mirror Authenticity Check tool.

Is Nexus Site down?

If the Nexus Site URL is not loading, it could be due to a temporary outage, a Tor network issue, or a phishing attack. Always verify the mirror using the Mirror Authenticity Check tool before assuming the market is down.

How can I verify a Nexus Site mirror?

Use the Mirror Authenticity Check tool on this page. Paste any .onion URL claiming to be a Nexus Market mirror, and we'll verify it against the market's documented PGP signing key. A match means the mirror is authentic; no match means it's a phishing clone.

Why is Nexus Site not loading?

If the Nexus Site URL is not loading, it could be due to a Tor network issue, a temporary outage, or a phishing attack. Try using a bridge to connect to the Tor network, or verify the mirror using the Mirror Authenticity Check tool.

03

PGP Keys and Message Security

Nexus Market requires PGP encryption for all vendor–user communication. The market provides an documented PGP key in its footer, signed with the same certificate used to sign its onion address. Users should cross-reference this key against the Mirror Authenticity Check tool to ensure they're interacting with the genuine market.

The market's PGP key is published in two places: the footer of every page and the /pgp.txt endpoint on the onion site. Both locations should yield an identical ASCII-armored block. The key's fingerprint is 3A7C 4F2D 8E1B 9A0F 7C3E 5B6D 2D4A 1E9F 0B8C 6D3A. Users should verify this fingerprint against the one displayed in the Mirror Authenticity Check tool before trusting any key material.

When messaging vendors, Nexus Market enforces PGP encryption by default. The platform provides an in-browser PGP tool that generates a keypair for new users. While convenient, this tool stores private keys in the browser's localStorage, which is vulnerable to XSS attacks. Security-conscious users should generate their keypair offline using GnuPG and import the public key into their Nexus Market profile. (see Riseup's security writeups)

Key Generation Steps
  1. Download GnuPG

    Obtain the latest version from gnupg.org. Verify the download's integrity using the provided SHA256 checksums.

  2. Generate Keypair

    Run gpg --full-generate-key and select RSA (4096-bit) for both the public and private key. Set an expiration date 12–24 months in the future.

  3. Export Public Key

    Use gpg --armor --export [email protected] to create an ASCII-armored block. Copy this block into your Nexus Market profile under "PGP Public Key".

Encryption Workflow
  1. Retrieve Vendor Key

    Navigate to the vendor's profile page and copy their PGP public key. Import it into your keyring with gpg --import.

  2. Compose Message

    Write your message in plaintext. Avoid including sensitive information like fulfilment channel addresses until after encryption.

  3. Encrypt Message

    Use gpg --encrypt --armor -r [email protected] to create an encrypted block. Paste this block into the Nexus Market message interface.

Key Management Warning

Private keys stored on the same device used to access Nexus Market are vulnerable to compromise. Consider using an air-gapped machine for key generation and storage. If you must store keys on your primary device, use a hardware token like a YubiKey or Nitrokey for additional protection.

Ready to Access Nexus Market?
Verify a mirror using the tool above, then proceed to the market.
View verified mirrors