Language
N NEXUSINFO

NEXUS MARKET // QUESTIONS

Nexus Market URL and mirrors: questions and answers

Fifteen questions that arrive again and again, answered in the narrowest way the evidence allows and with the limits of each answer written into the answer itself.

//ADDRESS RECORDS

Read the answers against these records. Several of the questions below are only really answerable with a string in front of you.

  • nexusma2iegzo7atzwbrwxhcdopyri3vare2twibldnlc3txqjdeb5yd.onion
  • nexusabcdpvtnivv6owtqjkvd22k5x3hlpofkgjqjmgzltlde6mwe2qd.onion
  • nexusncagw2vnag3ycv62occuouhfgkp6htx7alhnzl5xwgtzi2mfbid.onion

Open in the Tor Browser. Copy the whole string, including the .onion suffix.

I//ADDRESSES AND MIRRORS

Why is there more than one Nexus Market url?

A hidden service can publish several descriptors and answer on several addresses. Operators do this so that one address becoming unreachable, whether through pressure, load or an ordinary configuration mistake, does not remove every route at once.

From the reader side the practical effect is simple: if one string does not resolve, the next one is worth trying before you conclude that anything is wrong.

Are these nexus market mirrors different sites?

They are separate addresses. What sits behind them is not something this page can inspect, and any claim that they are identical, or that they are not, would be a claim beyond what an address string can support.

Which of the three should I use first?

Any of them. The list is unranked on purpose, because ranking would require measuring how each one behaves and no measurement is taken here.

How do I know a nexus market address is not a lookalike?

Compare the whole string, and pay particular attention to the last eight characters. Forgeries are generated to match a memorable opening because that is the part people check, and they cannot match the whole label without possessing the corresponding key.

Comparing by eye across a tab boundary is unreliable. Copy the record, paste it next to what your browser shows, and let the two strings sit on the same line.

II//WHAT THIS SITE KNOWS

Is the market online right now?

This site cannot say. It opens no connection to any onion service, keeps no history of checks and publishes no status light, so any answer it gave would be decoration rather than information.

The only way to find out is to try a record yourself in the Tor Browser.

Why are there no vendor, user or order counts?

Because those are measurements of a marketplace, and this site measures nothing about a marketplace. What it can state plainly, it states in ordinary sentences: it publishes three addresses, each a fifty six character v3 label followed by the .onion suffix, in six languages. A figure beyond that would be one somebody invented, and an invented figure next to a real address makes the real address look invented too.

What does verified mean in the page title?

It refers to transcription. The strings were checked character by character against the record supplied, and every page serves the same characters from the same file. It is never a claim that a service answered.

How current is this page?

The modification stamp in the structured data comes from the newest source file behind the page, not from the clock at the moment you loaded it. That is why no visible date is printed anywhere in the text: a date generated on request would tell you when you visited and nothing about when the content changed.

III//PRACTICAL MATTERS

Can I open a nexus market onion address in a normal browser?

Not without a Tor client, and not through a public gateway host. Gateways work by fetching the onion page on your behalf, which means the whole session passes through equipment run by a stranger who can read it. That is why no gateway is listed here.

Should I bookmark an address?

A bookmark saves you from retyping, which is worth something, but it also lets an old string quietly become your default long after it stopped being useful. Keep the bookmark and keep a written copy of the record too, then compare them when something behaves oddly.

What about a nexus market login page that appears on a different domain?

Treat any sign in form reached from an ordinary web domain as hostile. A hidden service is addressed by its onion string; a clearnet page asking for the same credentials has no legitimate reason to exist and every reason to be collecting them.

A string here does not match one I saw elsewhere. Which is right?

This page cannot arbitrate that, and a site that claimed it could would be overstating what it knows. What you can do is treat the disagreement as the signal: stop, do not enter anything anywhere, and compare both strings against a third source you already trusted before today.

IV//SIGNED BLOCKS

What is the inspector on the front page actually for?

It takes an ASCII armoured block apart so that you can see what you are holding. It separates the armour headers from the payload, decodes the payload out of base64, recomputes the CRC24 checksum that the armour carries at the end and then walks the resulting bytes looking at packet headers, reporting the tag number and declared length of each one it can read.

That is genuinely useful for spotting a mangled paste, a block that lost its last line in a chat client, or a file that is not a PGP block at all despite having the right first line. It is not useful for deciding whether to trust anybody.

Does a block that decodes cleanly prove the address list inside it is real?

No, and the distinction matters more than almost anything else on this page. Decoding proves the file is well formed. Checking a signature proves that a particular key was used, which is a different question, and it requires the corresponding public key plus a cryptographic library that this site deliberately does not load.

Anyone can produce a well formed signed message. The tool will happily take one apart and print its structure, and none of that output says a word about who made it or whether the contents are true.

Where should a signed list of addresses come from, then?

From a key you already held before you needed it, verified in a client that does real signature checking. A key fetched today, from the same page as the message it is supposed to authenticate, verifies nothing at all: whoever wrote the message could equally well have written the key.

//SITE INDEX

Six pages, published in six languages.