Clone teardown // tells // 2026

Anatomy of a Fake Mirror

A convincing fake does not look wrong. It looks exactly right, because it copied a page like this one character for character and changed the single thing you cannot eyeball: the onion. This teardown shows how a clone is put together, and the tells that surface before you ever type a password. The one string a clone cannot hold is the signed one on the card.

Canon pointerEvery tell below points back to one defence. The signed string a clone cannot reproduce sits on the card:torzonguqmlfy2kfi5tjbnt4bp3idtkjzi4qtupmhpdihjftomjtdzqd.onionOpen the card
How the trick worksthree moves

How a clone earns a login it should never get

A phishing mirror is not clever, it is patient. It leans on the fact that people trust what a page looks like. Three moves take it from a copy to a stolen account, and none of them touch the part that actually matters.

Anatomy of a fake mirrorCopythe layoutSwapthe onionHarvestyour login
1 // CopyThe clone lifts the layout wholesale. Fonts, colours, wording, even a warning box like the one further down.
2 // SwapThe single change is the onion string, repointed at a server the attacker runs. The look stays untouched.
3 // HarvestYou sign in on the fake and your credentials go straight to them. That is the entire business model.
The tellsbefore you type

Five tells that give a clone away

  1. The string is off. One or two characters differ from the signed onion. This is the only tell that always holds, and the only one worth trusting.
  2. No real signature. A key block that will not verify, a fingerprint with nothing behind it, or a page that skips PGP and tells you to just trust the link.
  3. Everything is green. Fake sites love a wall of Online badges. An honest board shows Checking far more than it shows a live node.
  4. Urgency at the door. Countdowns, a login that demands money before you are in, or a missing captcha where the real gate should be.
  5. Pay off-market. Any push to send coin outside the market escrow, to a wallet pasted in chat or on the page, is the clone showing its hand.

Only the first tell is decisive. The rest raise suspicion, but a careful clone can dodge them. The string, checked against the signed set, cannot be faked.

Side by sidecard vs clone

The real card next to a clone

Lined up, the difference is not in the pixels. It is in what each one can prove and what it asks of you.

The signed card

  • Shows the full 56-character onion that matches the signed record.
  • Leaves statuses on Checking until a probe actually answers.
  • Points every payment through the market escrow in Monero.
  • Never handles your funds or asks for a keystroke it cannot justify.

A phishing clone

  • Carries a near-identical string with a few characters swapped.
  • Paints everything Online to look busy and trustworthy.
  • Rushes you with a countdown or an upfront payment demand.
  • Steers coin to a wallet it controls, outside any escrow.
Questionsshort answers

Clone questions people ask

It looked identical, so how was it fake?

Identical is the point. A clone copies the markup, so the look tells you nothing. What it cannot copy is a valid signature over the real onion, which is why the check happens on the string, never on the page.

Can a clone fake the PGP signature?

No. It can paste a key block and a fingerprint that look the part, but it cannot produce a signature that verifies against the real signing key. That is the whole reason the key outranks the domain.

There is a padlock and https, doesn't that prove it?

No. A certificate only says the connection is encrypted, not that the site is Torzon. Onion services do not use it the way clearnet does. A padlock has never verified an onion address.

Next

Prove a string in one command

Now that the trick is clear, put the defence to work. The bench turns "looks right" into a hard pass or fail.

Run the signature bench