FAKE MIRROR // ANATOMY

How to Spot a Fake WeTheNorth Mirror: Technical Clone Fingerprints

A clone rarely looks wrong. It gives itself away at the character level — a substituted homoglyph, a forbidden digit, an encoding trick in the string — and at the behavioural level: a login demanded too early, a painted-on uptime badge, a deposit pointed at the wrong wallet. Learn both layers and the copy stops fooling you.

4Common tells
0Clearnet logins
1Genuine onion
TorOnion only
GENUINE REFERENCEChecking
http://hn2paw7hljeihrk7qm2toniay5bb4cfz46cav5iywnsv64klm45mypqd.onion

Keep this string beside whatever page you landed on. If the mirror in front of you differs by one character, or behaves in any way listed below, close the tab.

WHY THEY EXISTfollow the money

Why anyone bothers cloning it

A fake mirror is not vanity. It is a small business with two products: your login and your deposit. Harvested credentials get sold or drained, and a swapped wallet takes a payment that never reaches the market. Building the copy costs an afternoon. As long as one visitor in a few hundred connects without checking, the clone turns a profit, and that arithmetic is why they keep reappearing under fresh domain names.

BEHAVIOUR, NOT LOOKSdiff view

Genuine board vs clone, side by side

Judge the two by what they ask of you, not by how they look. The real board sits on the plus row. The tells of a fake fill the rest.

+

Login stays inside Tor

The genuine market never asks for a username on a clearnet page. You reach the login only after the onion opens in Tor Browser.

−

Login demanded up front

A clone puts a sign-in box on the web page itself, before any onion loads. That box exists to copy your credentials, nothing more.

−

Onion quietly altered

The address runs a character or two off the genuine string, betting that you read the opening letters and stop there.

−

Badge painted green

A bright online marker with no probe behind it. The image never moves because it is baked into the page rather than measured.

−

Deposit address changed

The wallet shown for a top-up belongs to whoever runs the fake. Your coins land with them and never credit an account.

TECHNICAL FINGERPRINTScharacter-level tells

The technical fingerprints, underneath the behaviour

Behaviour is what you notice first. Underneath it, a clone's onion string almost always carries one of a few technical fingerprints, and every one of them is mechanically checkable — no judgment call required.

−

Character substitution

One letter swapped deep in the 56-character string, usually past the point most people stop reading. The full method for catching this lives on the verify address page.

−

Homoglyph / lookalike characters

A capital O standing in for a digit, or a character chosen for how it looks rather than what it is. Onion v3 addresses are lowercase base32 only — anything outside a–z and 2–7 is disqualifying on sight.

−

Forbidden digits

A 0, 1, 8 or 9 anywhere in the string. Base32 excludes all four, so their presence alone proves the address was typed or altered by hand.

−

Checksum mismatch

A v3 onion encodes a checksum over its own key material. An address that fails the checksum was never a valid key at all — it is either a typo or a deliberately confusable near-miss, not a functioning alternate service.

HOW A FAKE PAYS OFFanatomy

How a fake mirror turns a visit into a loss

The path is short and always the same. You arrive believing the page, you hand something over, and the operator behind the copy keeps it. Drawn out, the trap has three moves.

Fake WeTheNorth mirror anatomy flowLand on copylooks rightHand it overlogin or depositThey keep itgone for good
1 · You landA link from a post, a search hit, or an old bookmark drops you on a page dressed as WeTheNorth.
2 · You hand overA login box or a deposit address collects what you type. It feels routine because the copy is careful.
3 · They keep itCredentials get resold or drained and coins go to the wrong wallet. Nothing reaches the real market.
FOUR TELLSquick read

Four tells you can read at a glance

Lookalike domain

A tidy clearnet name that promises the market without Tor. The real board answers only as an onion.

Login first

A username field before the onion ever opens. The genuine login exists only inside the market.

Forged uptime

A green badge that never moves. An honest status reads Checking until a probe confirms it.

New wallet

A deposit address that differs from your last visit. Treat any changed wallet as a reason to stop.

NEXT STEP

Confirm the address before you act

If a mirror clears these tells, you still owe it a character check. Compare the onion string end to end, then verify the operator key on the detector home page before you type anything.

Check the address
THE WIDER PATTERNnot unique to WeTheNorth

Fake mirrors are a darknet-wide pattern, not a WeTheNorth-specific one

A fake WeTheNorth mirror is one instance of a pattern that plays out across essentially every active darknet market. Understanding the pattern, not just this one brand's version of it, makes the tells above easier to apply anywhere.

Why this happens to every popular darknet market eventually

Any darknet market with real trading volume becomes worth impersonating. A clone that captures even a small fraction of WeTheNorth's login attempts can drain wallets or harvest credentials for later account takeover attempts. The economics favor the phisher: building a convincing clone costs little, and even a low success rate against a busy darknet market pays for the effort.

What stays constant across different darknet market clones

The mechanics repeat with almost no variation regardless of which darknet market is targeted: a near-identical layout, a slightly altered onion address, and urgency designed to short-circuit the verification step. Whether the target is WeTheNorth or any other darknet market, the defense is identical — verify the exact address against a signed record before trusting anything on the page.

Why this WTN darknet reference exists in that context

This page exists specifically to break that pattern for WeTheNorth: a maintained, signed record that a visitor can check a candidate mirror against, rather than relying on how convincing the page looks. Treat every darknet market mirror, WeTheNorth included, as unverified until it clears that check.

AFTER YOU SPOT ONEwhat to do next

You found a fake WeTheNorth mirror. Now what?

Spotting a fake WeTheNorth mirror is only useful if what you do next actually reduces the harm it can do to the next visitor, not just to you. A few concrete actions matter more than others here.

Do not engage with it beyond confirming it is fake

Once the signature check or the address diff fails, close the tab. There is no reason to poke around a suspected WeTheNorth clone further — a convincing fake can carry exploit code aimed at deanonymizing or fingerprinting visitors who linger, and nothing you would learn by exploring it further changes the verdict you already have.

Report it where it can actually get taken down or flagged

A fake WeTheNorth mirror hosted at a clearnet domain can usually be reported to the domain's registrar or host for a phishing violation, which is a faster path to takedown than reporting an onion address, which has no equivalent central authority. If you found the fake linked from a specific forum thread or aggregator listing, flagging it there directly helps the next visitor who follows that same link before search engines or hosts catch up.

Warn through a channel that will not itself get spoofed

If you want to warn others, do it through a channel you can verify belongs to you — a PGP-signed forum post under an established account, not an unsigned one-liner that a bad actor could just as easily post pointing the other direction. Ironically, an unverified "this WTN mirror is fake, use this one instead" post is exactly the same trust problem this whole page is about, just aimed at redirecting rather than phishing directly.

The one link worth trusting after a warning is the same signed WeTheNorth record this page already points to — not a fresh link pasted into the same thread where the fake was reported, since that thread is now exactly the kind of unverified channel a follow-up phishing attempt would target next.

DEEP DIVEa full case study

A full case study: anatomy of a fake WeTheNorth mirror

The signals listed above cover individual tells. Walking through a full, realistic case — how a fake WeTheNorth mirror gets built and pushed, start to finish — makes it easier to recognize the same pattern the next time it shows up in a different shape.

How a WeTheNorth clone site actually gets built

A convincing WeTheNorth clone almost never starts from scratch. The fastest path for whoever builds one is scraping the real WeTheNorth market's public-facing pages — the login screen, the landing page copy, any visible branding — and rehosting that scraped HTML on a new onion address the clone operator controls. This is why a fake WeTheNorth mirror can look pixel-identical to the real thing: it is, quite literally, a copy of the real thing's front end, with only the backend swapped out.

What the scrape cannot copy is the signing key. The real WeTheNorth operators hold a private PGP key that never leaves their control, and every legitimate WeTheNorth mirror address is signed with it. A clone operator can copy every pixel of the WeTheNorth login page but cannot produce a valid signature for their own onion address using a key they do not have — which is exactly why this whole reference leans on signature verification rather than visual inspection as the actual test.

How a fake WeTheNorth mirror gets pushed to victims

Distribution follows a predictable handful of channels. Search engine results are one — a paid or SEO-optimized listing for "WeTheNorth market" or "WTN onion link" that ranks above or alongside the genuine reference sites, banking on the fact that most people click the first plausible-looking result rather than verifying anything. Forum posts and comment sections are another, often posted by a throwaway account claiming the "real" WeTheNorth address changed and helpfully providing a new one — which is precisely the unverified-rotation-claim pattern covered elsewhere on this site. A third channel is a fake WeTheNorth mirror directory page itself, listing several addresses where only one or two are genuine and the rest quietly route to clone infrastructure, betting that a visitor copies one at random rather than checking each individually.

Every one of these channels shares the same weakness from a defender's perspective: none of them can forge the PGP signature covering the genuine WeTheNorth mirror record. That single check, run every time regardless of how the address reached you, is what makes every distribution channel above equally survivable — search result, forum post, or link list, the test does not change.

FAQplain answers

Fake mirror questions

A fake mirror showed a green online badge. Does that make it real?

No. A clone hard-codes that badge, so it is a picture rather than a probe. Only a full address compare and a matching signature carry any weight.

The page looked exactly like last time. Is that proof it is genuine?

No. A clone copies the whole look, pixel for pixel. Appearance is the cheapest thing to fake, so on its own it proves nothing.

A mirror asked me to sign in on a normal web page. Is that how it works?

No. The real login lives inside the market over Tor. A page that wants your WTN username before the onion opens is harvesting it.

Why would anyone bother cloning WeTheNorth?

Stolen logins and redirected deposits pay for the work. A convincing fake earns more than it costs to build, which is why clones keep coming back.