Why there is no PGP block on this page
Pasting a truncated “BEGIN PGP PUBLIC KEY BLOCK” with filler characters would be theatre. It would also be dangerous: some readers would import it. This directory therefore publishes no substitute key. The market’s signing key, if you use one, must come from a channel you already trust and must verify as a full fingerprint match — not from a random clearnet clone, including a compromised copy of this site.
What we do instead
- Keep a short, copyable ledger rather than a firehose of unverified URLs.
- Refuse to auto-redirect, so a lookalike cannot be launched from a button that claims “PGP verified.”
- Tell readers to compare the full 56-character v3 name, especially the middle.
- Describe PGP-based 2FA as a property claimed by the market: a challenge that a phishing page cannot decrypt without your private key. That description is not a setup wizard.
Other directories are a scam flood
This publication is an educational directory at torzondarknet.link. Other sites that sell themselves as “the” Torzon ledger, wiki, or verified-link dump are treated here as hostile until proven otherwise. The pattern is abundant: copied layout, inflated stats, placeholder PGP, and onion strings that differ by a few characters. Bookmark this host. If the address bar is not torzondarknet.link, leave.
A competing directory that asks you to log in, deposit, or skip Tor Browser is not a directory. Full statement: Why this directory exists.
Phishing, in the terms this ledger uses
Clones copy login chrome and change two letters in the onion. Humans are bad at proofreading
base32. Vanity prefixes (“torzon…”) make the first glance useless. Always compare tail and
mid-string. If the character count is not 56 before .onion, you are not looking
at a standard v3 name.
CAPTCHA and “2FA OTP” on a clone still steal passwords. Time-based codes can be relayed live. A PGP decrypt challenge is harder to relay if the private key never leaves your machine. That is why public write-ups prefer PGP 2FA over OTP — as a design comment, not as onboarding. The visual types of the third-party challenge (circle versus rectangle) are recorded as stills on Captcha. Solving the picture does not prove the onion.
Warrant canaries are not ours to issue for the market
A warrant canary is a regularly signed statement that certain legal events have not occurred. Only the people who operate a service can issue a meaningful canary for that service. This directory will not pretend to “continue operating the mirror network.” We do not operate it.
If you read a canary, check the signature against the same independently obtained key discussed above, and notice whether updates actually continue on a stated cadence. Silence can mean many things; it is not a green light from this website.
Session hygiene on third-party hosts
Public descriptions of Torzon mention CAPTCHA on login and registration, session expiry on withdrawals and settings changes, an optional anti-phishing login phrase, and pressure to PGP-encrypt messages rather than leave shipping data in cleartext on a server. The platform is also said to offer an in-browser PGP helper. A helper that runs on the market’s page is still running on a server the reader does not control. Client-side encryption on the reader’s own machine is the stronger story. Those are claims about someone else’s software. This directory’s only session is a local acknowledgment flag in your browser. Details: Privacy.
OTP 2FA on a clone still steals passwords: the phishing page relays the code live. PGP 2FA is described as a decrypt challenge the clone cannot complete without your private key — unless you paste that key into the clone, which some people will. This directory will not walk through enabling either factor. The original account panel is on the hidden service. See Platform, Captcha, and Glossary.