VERIFICATION // ARCHIVE // FORENSICS
WeTheNorth Onion Verification Archive 2026: Address History & PGP Methodology
This is the technical layer of the WeTheNorth reference cluster: how v3 onion cryptography actually works, the PGP methodology behind a signed address, the character-level fingerprints a phishing clone leaves behind, and a dated log of every confirmed WeTheNorth address rotation. WeTheNorth, written we the north and shortened to wtn, is a Canadian darknet marketplace — not the basketball chant. For the step-by-step walkthrough of reaching the market itself, see the access guide on wethenorth-official.com.
http://hn2paw7hljeihrk7qm2toniay5bb4cfz46cav5iywnsv64klm45mypqd.onionOne confirmed reference address. The pill is a probe reading, never a guarantee. Copy it, compare all 56 characters, verify the key, then open it only in Tor Browser.
pending (Phase 0)A domain proves nothing; the key does. Anyone can rent a tidy hostname and reproduce every pixel, but nobody outside the operators can sign with their key. That key arrives in Phase 0.What WeTheNorth is, and what it is not
WeTheNorth is a Canadian darknet marketplace that runs as a Tor hidden service. There is no clearnet storefront and no phone app. The name happens to echo a Toronto basketball slogan, yet the two share nothing beyond the words. On this board, we the north, wtn, and wethenorth all point at a single onion market.
Honest limit: we publish the reference and the checks. We do not run the market, we cannot see your account, and we never guarantee that a mirror is answering at the exact moment this board loads in front of you.
Read it like a diff
A clone rarely looks wrong. It usually differs by one character buried in the middle of the string, or by the absence of a signature you never thought to check. Lay the real address next to the one you were sent and the gap shows up fast.
Same-looking, one character apart. The genuine string on top, a clone on the bottom:
Genuine WeTheNorth
The full 56-character v3 onion, letter for letter. A signature that matches the published fingerprint. A row on the signed list. All three, or you stop.
Swapped character
One letter changed where the eye skips, often past the tenth character. The page still loads and still looks right, which is exactly the trap.
Unsigned paste
An address lifted from a forum reply or a search result, with no signature standing behind it. Popular is not the same as verified.
Login-first clone
A page that wants your wtn login before you ever reach the onion. The real login only exists inside the market, on Tor.
How a link gets checked before you trust it
Every candidate address takes the same short path. It is not enough that a mirror answers; it has to survive a character compare and a signature check. Here is where each test happens.
Three signals, and no shortcuts
- R1chars 56/56pass
Full address
All 56 characters match, not just the first handful. Clones bank on you checking the start and stopping.
- R2pgp keypending
Matching signature
The PGP fingerprint lines up with the published one. A copied look cannot forge a signature.
- R3canon listpass
On the signed list
The address sits in the signed directory, not in a forum reply or a paste someone swears by.
- R4live probeprobe
Honest status
Status holds at Checking for as long as a probe has not answered. A green light is never assumed on our behalf.
The one verified WeTheNorth mirror
| Role | Onion URL | Status | Action |
|---|---|---|---|
| Primary | http://hn2paw7hljeihrk7qm2toniay5bb4cfz46cav5iywnsv64klm45mypqd.onion | Checking | |
| Failover | additional signed mirrors are being provisioned | Pending | n/a |
Last checked . When a second mirror is signed, it appears here and nowhere else.
The rotation archive
A v3 onion address is a cryptographic key, not a rented domain, so WeTheNorth can rotate to a fresh one without asking a registrar. This is the layer that answers the question a mirror list cannot: when a WeTheNorth address changed, what triggered it, and how the change was confirmed against the signed record — not just what the current address is. One entry exists in the log today; the format is built to grow with every future rotation.
Open the rotation archive →Verify the address before you connect
pending (Phase 0)Honest limit: the signing key is not published yet. Until it lands in Phase 0, this page cannot prove the address by signature, so compare all 56 characters by eye and cross-check the canon first.
Open the operator key and the verification steps
-----BEGIN PGP PUBLIC KEY BLOCK-----
(withheld for now; the key stays offline through Phase 0)
-----END PGP PUBLIC KEY BLOCK-----gpg --import canon-pub.asc
gpg --verify mirrors.json.sig mirrors.jsonReaching the market itself
This archive verifies the address; it is not the install-and-login walkthrough. Hardening the browser, importing the key, opening the onion, clearing the captcha, and signing in are covered step by step on the cluster's dedicated access guide.
WeTheNorth onion vs clearnet mirror: full comparison
This WTN darknet reference exists on a clearnet domain specifically to hand you off to the genuine WeTheNorth onion. Understanding why those two things are not interchangeable is worth a full section, not just a footnote.
What a clearnet WTN reference can and cannot do
A clearnet page like this one is indexed by ordinary search engines, easy to remember, and reachable without Tor at all — which is exactly why it is also the easier target for a phishing clone to imitate. What it cannot do is serve the actual WeTheNorth market: no login, no listings, no orders happen here. Its entire job is verification and handoff to the real onion.
What the WeTheNorth onion itself provides
The onion address is where WeTheNorth the darknet market actually lives. It cannot be DNS-hijacked or seized the way a clearnet domain can, and it cannot be typo-squatted with a "close enough" address, because a changed character in an onion v3 string produces a completely different cryptographic key, not a similar-looking near miss. The trade is reach: only Tor Browser can open it, and it carries none of the memorability of a clearnet name.
Why a phishing clone targets the clearnet side first
Building a convincing clearnet WeTheNorth lookalike is cheap: register a similar domain, copy the layout, and rank it in search next to legitimate WTN darknet references like this one. That is precisely why this page treats every WTN mirror and every onion address the same way — verified against a signed record, never trusted because a page merely looks right.
Switching between the two safely, in the right order
The safe sequence only runs one direction: start on a clearnet WTN reference like this one, confirm the address against the signed record shown below, then move to Tor Browser and open the WeTheNorth onion directly. Never reverse that order by pasting a WTN address you found somewhere else back into a search engine to "double-check" it — that habit is exactly what a well-ranked phishing clone is built to catch, since the clone's whole strategy is to sit next to legitimate WeTheNorth results and hope you click without re-verifying. Once you have opened the onion and it matches what this page shows, there is no need to bounce back to the clearnet side mid-session; treat the WeTheNorth onion tab as the trusted destination for the rest of that visit, not a link to keep re-confirming.
What changes when WeTheNorth rotates its onion address
An onion address is a cryptographic key, not a rented domain, so WeTheNorth can generate a new one at any time without asking a registrar's permission — and legitimate operators do rotate, usually after a suspected compromise, a period of unusual downtime, or as routine hygiene. When that happens, this page updates its verified WTN record to the new address; a forum post or a chat message claiming a "new official WeTheNorth link" without a matching update here is not evidence of a real rotation. Bookmark this clearnet reference rather than a specific onion string for exactly this reason — the onion can change, but the verification process this page documents does not. See the rotation archive for the dated record of exactly when that has happened.
Common Tor Browser errors on WTN
Most access problems reaching the WeTheNorth darknet market are Tor Browser configuration issues or a stale address, not the market itself being down. The list below covers the specific errors that come up most often around a WeTheNorth session, roughly in the order a new visitor tends to hit them: first a connection issue, then a rendering issue once the page starts loading, then a captcha or login-flow issue once past both.
Tor Browser says the WTN onion can't be reached
Re-copy the address from the verified box on this page rather than a bookmark. A single wrong character in the onion string is a completely different, unreachable server. If a freshly copied WTN address still fails, wait for new Tor circuits and retry.
The WeTheNorth page hangs while connecting
Circuit negotiation over the darknet can be slow, particularly on congested paths. Give it up to a minute before assuming failure. Tor Browser's "New Identity" option forces fresh circuits if a WTN mirror still will not load.
WTN login loops through the captcha repeatedly
This is more often a browser security-level conflict than a submission error. Try the Safer level specifically for the captcha widget, then return to Safest once past login on the WeTheNorth market.
The WeTheNorth onion loads a blank white page with no error
A concrete example: the address resolves, Tor Browser shows a lock icon and a mostly blank layout, but no content renders and no error appears. This usually means the WeTheNorth mirror is serving a stripped page because JavaScript is disabled at the Safest level and the page has not been built with a working no-JS fallback for that specific route — try reloading once, and if the blank page persists on a WeTheNorth address you have already signature-verified, treat it as a mirror-side issue rather than a sign the address itself is wrong.
WeTheNorth loaded, but the layout looks slightly different than last time
A minor visual difference alone is not proof of a clone — legitimate WeTheNorth updates change layouts too. But combined with anything else off (a login field in an unfamiliar spot, a missing badge, oddly aggressive urgency language), a visual change is reason enough to stop and re-run the signature check on the verify page before entering any WeTheNorth credentials.
The WTN onion times out right after a Tor Browser update
A version update sometimes resets custom circuit or bridge settings back to defaults. If a WeTheNorth address that worked yesterday now times out consistently, check whether Tor Browser is still using the same bridge configuration you had before, and confirm the local clock is correct — a clock skewed by more than a few minutes can break the TLS handshake Tor relies on internally, producing exactly this symptom on any onion, not just a WTN one.
Antivirus or a corporate firewall silently blocks the WeTheNorth connection
Some antivirus suites and network-level firewalls intercept or drop SOCKS traffic on the port Tor Browser uses by default, which shows up as a WeTheNorth address that "just won't load" with no explicit error. Check the antivirus's own connection log rather than Tor Browser's error page in this case, and add a temporary exception for the Tor Browser process if the software allows it — do not disable Tor's own security settings to work around a block that is happening at the network layer, not inside Tor itself.
A WeTheNorth session logs out mid-browse with no warning
Tor circuits rotate periodically for anonymity reasons, and an unlucky rotation mid-session can occasionally drop an active WeTheNorth login along with it. This is a Tor-layer event, not evidence of a security problem on the WTN side specifically. Re-open the verified address, log back in, and if it happens repeatedly within the same short window, try disabling "New Identity" auto-triggers if you have any browser extension configured to fire them on a timer.
The WeTheNorth captcha image never finishes loading
At the Safest security level some image formats are restricted, and on rare WTN sessions this can affect the captcha widget specifically rather than the rest of the page. Drop to Safer only long enough to load and clear that one captcha, then raise the level back to Safest for the remainder of the WeTheNorth session — never leave a WTN session running at a lower security level than necessary once you are past the login gate.
WeTheNorth mirror history and hardening, in depth
The sections above cover the essentials of reaching WeTheNorth safely. The two panels below go further: how the WeTheNorth mirror set has actually changed over time, and what Tor Browser's security levels really turn off.
WeTheNorth mirror history: why the onion changes and what stays constant
WeTheNorth, like every Tor-only Canadian darknet marketplace of its scale, does not run on a fixed address forever. A v3 onion address is a self-certifying key, generated locally with no registrar and no certificate authority involved, which means the operators can rotate to a fresh WeTheNorth onion at will — after a suspected compromise, after unusual load consistent with a targeted denial-of-service pass, or simply as routine hygiene to limit how long any single WeTheNorth address stays a fixed target for abuse reports and takedown attempts.
What stays constant through every rotation is the verification method, not the address itself. The PGP key WeTheNorth's operators use to sign the canonical mirror record does not change nearly as often as the onion address does, which is exactly why this guide leans on signature verification rather than memorizing a specific WeTheNorth string. Bookmark the verification method — this page and the verify page — rather than a single WeTheNorth onion, because the address you bookmark today may not be the one WeTheNorth is running on next month.
A forum post claiming a "new official WeTheNorth link" without a PGP signature attached is not a rotation announcement — it is either stale chatter recycled from an old thread or an active phishing attempt riding on the fact that real WeTheNorth rotations do happen from time to time, which makes fake rotation claims sound plausible to someone who has not learned to check the signature first. The dated log of confirmed rotations lives in the rotation archive, not in a forum thread.
Tor Browser hardening for a WeTheNorth session
Tor Browser's security slider has three levels, and the gap between them matters more for a WeTheNorth session than casual browsing. Standard runs full JavaScript everywhere; Safer disables JavaScript on non-HTTPS pages; Safest disables JavaScript sitewide along with most video, audio, and font rendering. Safest is the only level this guide recommends for opening WeTheNorth, since JavaScript engines are historically the single largest attack surface used in real deanonymization exploits against Tor users, including ones documented in past law-enforcement operations against other darknet markets.
Beyond the slider itself, three habits matter almost as much for a WeTheNorth session specifically. Never resize the Tor Browser window — window dimensions are a fingerprinting vector that can narrow the pool of "similar" Tor sessions an observer would need to sort through to single yours out. Never add browser extensions; each one is unreviewed code running with page access. And never log into a WeTheNorth account from the same Tor session used for anything tied to a real identity — session isolation is the entire point of routing through Tor for this, and one slip breaks it permanently for that session, not just for the page you slipped on.
If a page claiming to be WeTheNorth pressures you to raise the security level before you have even finished verifying the onion address against the signed record, treat that as a strong signal you are looking at a phishing clone rather than a technical inconvenience to work around.
Genuine vs clone questions
How do I tell a genuine WeTheNorth onion from a clone?
Match every one of the 56 characters, confirm the PGP signature against the published fingerprint, and find the address on the signed list. A familiar layout proves nothing.
Is WeTheNorth the same as the Toronto Raptors slogan?
No. Here WeTheNorth is a Canadian darknet marketplace. The basketball chant shares the words by coincidence and does not belong on this board.
Are nexus, torzon or vortex WeTheNorth mirrors?
No. Those are separate markets. Any page that dresses one of them up as a WeTheNorth mirror is a clone.
Why does the status read Checking?
Availability changes hour to hour. Checking is an honest probe state, not a promise that the address is up or safe.
Is WeTheNorth up or down right now?
The marker on the address above shows a live probe. It moves through the day, so read the pill, then confirm the signature before you rely on it.
A clone loaded fine for me. Does that make it safe?
No. A clone can load, look correct, and still harvest your login. Only an address that both loads and matches the signature is safe.
Where can I see past WeTheNorth address rotations?
The rotation archive keeps a dated log of every confirmed change: what triggered it and how it was verified against the signed record.