Table of Contents
1. The Scam Landscape
The dark web's scam rate is dramatically higher than the clearnet. The reasons are structural: there is no consumer protection, no chargebacks, no reputation system that cannot be faked, no legal recourse, and payments are in cryptocurrency that cannot be reversed. Scammers face almost no consequences and have every incentive to defraud users.
Studies of dark web marketplaces consistently find that a significant proportion of vendors — even on established markets — either deliver nothing, deliver substitutes, or disappear after receiving payment. The term "exit scam" describes the most common pattern: a market or vendor operates legitimately long enough to build trust, then steals all funds and disappears.
Understanding the types of scams and the red flags that identify them is essential before engaging with any dark web resource.
2. Fake Hidden Wiki Mirrors
The Hidden Wiki concept — a link directory for .onion sites — has been copied hundreds of times. Many of these copies exist specifically to scam users in one of two ways:
Replaced Links
A fake Hidden Wiki looks identical to a legitimate directory but replaces real .onion addresses with addresses the scammer controls. A user clicks what appears to be a link to a legitimate service and arrives at a phishing page that steals credentials or requests cryptocurrency "deposits."
Malware Delivery
Some fake Hidden Wiki sites serve drive-by malware to visitors. With JavaScript enabled, a malicious site can attempt browser exploits. This is one reason Tor Browser's "Safest" security setting (which disables JavaScript) is essential.
Never use a Hidden Wiki URL found through a Google search, a forum post from an unknown account, or a social media link. These are extremely common vectors for fake directories.
3. Phishing Sites
Phishing on the dark web works the same way as on the clearnet — a site mimics a legitimate service to steal your login credentials or cryptocurrency. The difference is scale: there are hundreds of phishing sites targeting dark web markets and services.
How Dark Web Phishing Works
A phishing site copies the visual design of a legitimate .onion service exactly — same layout, same logo, same color scheme. The .onion address differs from the real one, often by just one character. A user who doesn't check the full address sees what looks like the legitimate site, logs in, and has their credentials captured.
Cryptocurrency Phishing
Many phishing sites present a "deposit" interface. The address shown for deposits is controlled by the phisher, not the legitimate service. Any cryptocurrency sent to it is gone immediately.
4. Exit Scams
An exit scam is when a market or vendor that has built up trust deliberately disappears with users' funds. It is endemic to dark web markets because the escrow systems they use are controlled by the market operators — who can steal from them at any time.
The pattern is consistent: a market grows, builds a reputation, accumulates large amounts of cryptocurrency in escrow or user wallets, then the operators withdraw everything and shut down without warning. Users find the site offline and their funds gone.
Notable exit scams include Empire Market (~$30M, 2020), Evolution (~$12M, 2015), and Wall Street Market (~$11M, 2019). For a detailed technical analysis, see our post-mortem of 10 marketplace collapses.
5. Law Enforcement Honeypots
Law enforcement agencies operate fake dark web sites to identify and arrest users. These "honeypots" have included marketplaces, forums, and services. When a user interacts with a honeypot — creating an account, making a purchase, communicating with vendors — they provide evidence to investigators.
Confirmed law enforcement honeypot operations include Hansa Market (taken over and run for a month by Dutch police in 2017 while logging all user data), and multiple smaller forums. The FBI, Europol, and other agencies have confirmed this practice in court documents.
There is no reliable way to distinguish a legitimate dark web service from a well-run honeypot. This is a fundamental risk that cannot be eliminated through technical means — only through avoiding illegal activity.
6. Universal Red Flag Checklist
Apply this checklist to any dark web site before engaging with it:
🚨 Immediate Red Flags — Leave Immediately
- The site asks for cryptocurrency upfront before providing any service or showing any product
- The .onion address was found through a Google search or unverified forum post
- The site claims to sell things that are obviously impossible (hacked bank accounts, government databases, assassination services)
- The site has no verifiable history, forum presence, or third-party reviews
- Prices are dramatically lower than any comparable service — "too good to be true" applies here more than anywhere
- The site pressures urgency: "limited time offer," "only 3 spots left," "price increases in 24 hours"
⚠ Warning Signs — Proceed with Extreme Caution
- No PGP-signed messages from vendor or admin — legitimate operations use PGP for verification
- Escrow is not available or "optional" — markets that push direct payment bypass any fraud protection
- Recent account age with high feedback counts — feedback can be purchased or faked
- No verifiable presence on multiple independent forums
- Customer support is unresponsive or gives evasive answers
- The site recently moved to a new address "for security reasons" — this is a common exit scam precursor
7. How to Verify .onion Addresses
Verifying a .onion address is the most important step before visiting any dark web site. Here is the correct process:
- Find the address from multiple independent sources — not just one forum post or one directory. Cross-reference at least two or three sources that are independently operated.
- Check the full 56-character address character by character — do not rely on visual similarity. One changed character creates a completely different site.
- Look for PGP-signed address announcements — legitimate services often publish their .onion addresses signed with their PGP key. Verify the signature.
- Use Ahmia (
ahmia.fi) — a moderated Tor search engine that filters known scam and illegal sites. It is not perfect, but it is better than unmoderated directories. - Check forum reputation threads — established privacy forums often have dedicated threads for verifying current .onion addresses for major services.
8. If You've Been Scammed
If you have been scammed on the dark web, your options are limited — but there are steps worth taking:
- Cryptocurrency transactions cannot be reversed — if you sent crypto to a scammer, it is gone. Do not send more money to "recover" it — this is a secondary scam called "recovery fraud."
- If credentials were stolen — change passwords on any accounts that used the same or similar passwords immediately. Enable 2FA everywhere. See our password security guide.
- If malware may have been installed — do not continue using that system for sensitive activities. If you were using Tails, simply rebooting removes the malware. On a regular OS, assume it is compromised until cleaned.
- Document what happened — if you intend to report the scam to relevant forums or communities to warn others, save screenshots and the .onion address involved.
- Do not report to police unless the scam involved something legal — reporting illegal activity exposes you to scrutiny as well.
Never send cryptocurrency to any dark web site you cannot independently verify through multiple trusted sources. The default assumption for any unverified dark web service asking for payment is: it is a scam.
Related Articles
Dark Web Marketplace Deaths: A Technical Post-Mortem of 10 Collapses
Empire took $30M. Evolution took $12M. How 10 major dark web markets collapsed.
OPSEC for Everyday People: Protect Your Digital Life
Threat modeling, compartmentalization, pseudonyms, metadata scrubbing — for everyday people.
The Complete Beginner's Guide to the Tor Network
How onion routing works, how to use Tor Browser safely, and what Tor can and cannot protect you from.