Clone teardown // tells // 2026

Anatomy of a Fake Torzon Mirror: Phishing Tells to Know (2026)

A convincing fake does not look wrong. It looks exactly right, because it copied a page like this one character for character and changed the single thing you cannot eyeball: the onion. This teardown shows how a clone is put together, and the tells that surface before you ever type a password. The one string a clone cannot hold is the signed one on the card.

logged by Alex Ferran // checked 2026-08-25

Canon pointerEvery tell below points back to one defence. The signed string a clone cannot reproduce sits on the card:torzonguqmlfy2kfi5tjbnt4bp3idtkjzi4qtupmhpdihjftomjtdzqd.onionOpen the card
How the trick worksthree moves

How a Torzon clone earns a login it should never get

A phishing mirror is not clever, it is patient. It leans on the fact that people trust what a page looks like. Three moves take it from a copy to a stolen account, and none of them touch the part that actually matters.

Anatomy of a fake mirrorCopythe layoutSwapthe onionHarvestyour login
1 // CopyThe clone lifts the layout wholesale. Fonts, colours, wording, even a warning box like the one further down.
2 // SwapThe single change is the onion string, repointed at a server the attacker runs. The look stays untouched.
3 // HarvestYou sign in on the fake and your credentials go straight to them. That is the entire business model.
The tellsbefore you type

Five tells that give a Torzon clone away

  1. The string is off. One or two characters differ from the signed onion. This is the only tell that always holds, and the only one worth trusting.
  2. No real signature. A key block that will not verify, a fingerprint with nothing behind it, or a page that skips PGP and tells you to just trust the link.
  3. Everything is green. Fake sites love a wall of Online badges. An honest board shows Checking far more than it shows a live node.
  4. Urgency at the door. Countdowns, a login that demands money before you are in, or a missing captcha where the real gate should be.
  5. Pay off-market. Any push to send coin outside the market escrow, to a wallet pasted in chat or on the page, is the clone showing its hand.

Only the first tell is decisive. The rest raise suspicion, but a careful clone can dodge them. The string, checked against the signed set, cannot be faked.

Side by sidecard vs clone

The real Torzon card next to a clone

Lined up, the difference is not in the pixels. It is in what each one can prove and what it asks of you.

The signed card

  • Shows the full 56-character onion that matches the signed record.
  • Leaves statuses on Checking until a probe actually answers.
  • Points every payment through the market escrow in Monero.
  • Never handles your funds or asks for a keystroke it cannot justify.

A phishing clone

  • Carries a near-identical string with a few characters swapped.
  • Paints everything Online to look busy and trustworthy.
  • Rushes you with a countdown or an upfront payment demand.
  • Steers coin to a wallet it controls, outside any escrow.

Every item on the clone side of this comparison is a behavior, not a visual defect — nothing here is something a screenshot comparison would catch, because a well-built clone's screenshot is designed to look identical to the real Torzon card. The distinguishing signal is always what happens when you check the string against the signed record, never how convincing the surrounding page looks.

Distributionwhere clones spread

Where fake Torzon links actually spread

Search engine results

Search results for a market name routinely surface phishing clones alongside or above genuine reference sites, because clearnet search has no reliable way to verify an onion address before indexing a page that links to one. A high ranking is not a trust signal for a darknet market link under any circumstances.

Forum posts and paste sites

A comment thread or paste site is trivial to post to and carries an appearance of community vetting that is usually not real — upvotes and reply counts can be manufactured, and a genuinely helpful poster can unknowingly repost a link that was already swapped upstream. Treat every link from these sources as unverified until checked against the signed record, regardless of how many people appear to vouch for it.

Directory and "best markets" sites

Third-party directory sites that rank or list multiple markets have an obvious incentive problem: some accept payment for placement, and none of them are positioned to verify a signature the way the market's own signed source can. A directory listing is a lead, never a verification.

Ads and sponsored placements

A paid ad slot has even less relationship to legitimacy than an organic search result — an ad network approving a placement checks payment and basic policy compliance, not whether the destination is a genuine Torzon address or a clone built to harvest credentials. Treat a Torzon-branded ad exactly like an unverified forum link: a lead to check, never a source to trust on its own.

CASE PATTERNhow a fake Torzon page is actually built

How a fake Torzon mirror is actually built, step by step

Understanding the mechanics behind a fake Torzon page makes the warning signs easier to remember, because they stop being an arbitrary checklist and start being the visible seams of a specific process.

Step one: clone the front end

Cloning a market's visible front end is mechanical and fast — save the HTML, CSS and images from a real Torzon session, or from a previous clone, and the result looks identical to the genuine page because it is, pixel for pixel, the same interface. This is exactly why visual similarity carries zero weight as a trust signal on a darknet market page: a perfect clone and the genuine article render identically.

Step two: register a look-alike onion or domain

A cloned front end needs somewhere to live. Operators generate onion addresses until one shares a visually similar prefix with a real Torzon address (v3 onions are long enough that brute-forcing a plausible-looking prefix is feasible), or register a clearnet look-alike domain with a swapped character. Neither approach can reproduce the exact signed address — that is the one property that resists copying no matter how much effort goes into everything else.

Step three: swap the payout destination

The final and most consequential step is swapping wallet addresses shown at checkout, or capturing login credentials submitted to a fake authentication form, and forwarding the real session onward so the victim does not immediately notice anything wrong. This is why escrow and independent address verification both matter: even a visually flawless clone cannot survive a fingerprint check against the record signed by Tor's own hidden-service address format rules, because the signed record simply will not contain the clone's address.

What changedclone tracking

What changed recently in Torzon clone tracking

The five tells above are structural and do not shift with any single clone campaign; a fake Torzon page can only ever fail the signature check, not pass it, no matter how the surface details are tuned. What does shift, campaign to campaign, is which distribution channel a Torzon clone is currently favoring, noted below.

Recent Torzon clone distribution patterns

Clone links impersonating Torzon continue to surface most often through paid search placements and typo-adjacent domains rather than through Tor-native channels, because clearnet ad platforms are where a phishing operator can buy visibility a genuine Torzon onion address cannot compete for. A sponsored result claiming to be Torzon's "official mirror" is a stronger red flag than an organic one, precisely because legitimate Torzon addresses are not something anyone can pay a search engine to promote.

Why a Torzon clone's PGP block is always the tell, never the fix

Some more recent Torzon clones have started pasting a plausible-looking, but non-matching, PGP key block onto their login page — a response to more visitors asking for one. This does not close the gap the signature bench exists to catch; a key block copied onto a page proves nothing about that page's own trustworthiness. Only running the verification yourself against a key fetched independently of the page you are checking closes that gap, which is exactly why this card keeps repeating the same instruction across every page in the Torzon reference.

Reporting a Torzon clone you find

If you find a Torzon clone in active use, the most useful step is not reporting it to this card, which has no takedown authority over a clearnet domain or a search engine's ad inventory, but sharing the exact URL in a community space where other prospective Torzon visitors are likely to search before clicking, alongside the specific signature-mismatch evidence rather than a vague warning.

Questionsshort answers

Clone questions people ask

It looked identical, so how was it fake?

Identical is the point. A Torzon clone copies the markup, so the look tells you nothing. What it cannot copy is a valid signature over the real Torzon onion, which is why the check happens on the string, never on the page.

Can a clone fake the PGP signature?

No. A Torzon clone can paste a key block and a fingerprint that look the part, but it cannot produce a signature that verifies against Torzon's real signing key. That is the whole reason the key outranks the domain.

There is a padlock and https, doesn't that prove it?

No. A certificate only says the connection is encrypted, not that the site is Torzon. Onion services do not use it the way clearnet does. A padlock has never verified an onion address.

Why do fake links rank well in search engines?

Search engines have no mechanism to verify an onion address before indexing a page linking to one, so a well-optimized phishing page can rank as highly as a genuine reference site. Ranking position carries zero trust signal for a darknet market link.

Someone I trust shared a link that turned out fake. Now what?

It happens even to careful people, because a clone can spread through a chain of good-faith reposts. Warn them so they can correct it, and treat this as confirmation that the fingerprint check matters more than trusting the source of a link, however credible.

Should I report a fake mirror I find?

Reporting to the real market through its own verified channel is useful; reporting to a third-party directory site does little since that site cannot independently verify your claim either. Your own fingerprint check remains the defense that matters regardless of what gets reported.

Can a Torzon clone show a valid-looking mirror status page too?

Yes. A clone can build its own fake status page showing whatever labels it wants, since nothing stops a malicious site from displaying "Online" next to every address it lists. Status words on a page carry no authenticity signal on their own; only the signature check on the underlying address does.

Do fake Torzon pages usually ask for money before login, or after?

Both patterns exist, but a request for a deposit, a wallet address, or payment before you have even reached a real login form is the more obvious tell — the genuine market gate never asks for money at that stage. A more sophisticated clone may wait until after a fake login to make its move, which is why the signature check matters even when nothing about the page itself looks wrong yet.

Is a clone that has been up for months more trustworthy than a new one?

No. Uptime says nothing about authenticity; a phishing clone can run indefinitely if it is not reported or taken down, and its longevity is not evidence it is the real Torzon. The fingerprint check gives the same answer on day one as it does a year later, which is the entire point of relying on it over any signal that accumulates with time.

Next

Prove a string in one command

Now that the trick is clear, put the defence to work. The bench turns "looks right" into a hard pass or fail.

Run the signature bench