ADDRESS CHECK // CHAR SCAN
Verify a WeTheNorth Onion, Character by Character
A version-3 onion is a fixed shape: fifty-six characters drawn from a small alphabet, ending in one known letter. Once you know the shape, a doctored address stands out. This page walks the compare block by block, and you can start without touching the signature.
http://hn2paw7hljeihrk7qm2toniay5bb4cfz46cav5iywnsv64klm45mypqd.onionThis is the reference every check runs against. Copy it, then hold any address you were handed up beside it, one block of characters at a time.
The shape of a real onion address
A modern onion is not random typing. It is a public key written in base32, so only the twenty-six lowercase letters and the digits two through seven are legal. The digits zero, one, eight and nine never show up, and neither does a capital letter. The string is always fifty-six characters long, and the final one is a version marker that reads d for every v3 address in use today. Any candidate that breaks one of those rules is broken before you reach the compare.
Compare it in blocks, not in a glance
Reading fifty-six characters straight through invites your eye to skate over the middle, which is where a swap likes to hide. Cut the string into four blocks of fourteen and check each block against the canon on its own. A change surfaces the moment one block fails to line up.
The canon block on top, a doctored copy underneath. One character is wrong:
Repeat for all four blocks. If every block matches and the shape rules hold, the string itself is clean.
From a pasted string to a verdict
The check runs in one direction. Split the address, compare each block, confirm the shape, then read the result. Only a string that clears every gate earns the signature step on the home page.
Three rules that reject a fake outright
Some fakes fail before a full compare. These three checks take a second each and rule out a whole class of doctored strings.
Contains 0, 1, 8 or 9
Base32 has no room for those digits. An onion showing any of them was typed or altered by hand and is not real.
Has a capital letter
Onion addresses run lowercase throughout. A stray uppercase character means the string has been touched.
Wrong length or ending
Not fifty-six characters, or not ending in the letter d, means it is not a valid v3 address at all.
Clears all three
Right length, legal alphabet, ends in d. Now the block compare and the signature decide the rest.
The five-step address check
- Copy the canon onion from the box above.
- Paste both strings into a plain text editor.
- Split each into four blocks of fourteen.
- Compare block against block, letter for letter.
- Confirm the shape rules, then verify the key.
Take it to the signature
Once the characters line up, the last question is who signed the address. The fingerprint and the signed directory live on the detector home page. Until the key lands in Phase 0, lean on the character compare and the canon.
Why address verification matters on any darknet market, not only WeTheNorth
The character-by-character method on this page is not a WeTheNorth-specific trick. It works because of how onion v3 addressing itself is built, which means the same discipline applies to every darknet market address you ever handle, not just this one.
The address is the identity, on any darknet market
Unlike a clearnet domain, a darknet market's onion address is derived directly from its cryptographic key. There is no registrar, no DNS, and no certificate authority standing between the string and the server it points to. That is exactly why a single altered character matters so much: it does not point to "a similar" darknet market server, it points to a completely different one, or nowhere at all.
What this method protects against on WeTheNorth specifically
Applied to a WeTheNorth address, this check closes the most common phishing vector against this particular darknet market: a clone operator registering or generating a visually similar onion and hoping a visitor compares by eye rather than character by character. A four-block scan defeats that trick reliably, regardless of how convincing the surrounding page looks.
Carry the habit to every other darknet market address you use
Once this method is second nature for verifying a WeTheNorth onion, apply it everywhere else too. Any darknet market worth using should publish a canonical address you can compare against, and the four-block scan plus the three instant-reject rules above work identically no matter which market's address you are checking.
Why a WeTheNorth onion v3 address looks the way it does
The 56-character string is not an arbitrary format someone picked — it is a direct encoding of cryptographic material, and understanding why makes the character-by-character check feel less like an arbitrary ritual and more like what it actually is.
The address is derived from a public key, not assigned
A Tor v3 onion address is built from an Ed25519 public key, a checksum, and a version byte, all encoded in base32. There is no registrar involved and nothing to purchase — whoever holds the matching private key controls the address, full stop. This is the entire reason a WeTheNorth onion address cannot be "bought" out from under the real operator the way a clearnet domain sometimes can; the address is mathematically tied to a specific key pair from the moment it is generated.
Why the checksum makes a single wrong character catastrophic
The checksum bytes baked into the address exist specifically to make a near-miss address fail rather than silently resolve to something plausible-looking. Change one character and the checksum almost never validates against the rest of the string — which is why a typo in an onion address does not quietly land you on a similar service, it simply fails to resolve at all, or resolves to whatever the attacker actually generated a matching key pair for.
Why this matters more for WeTheNorth than for a clearnet mirror
A clearnet WeTheNorth mirror can be typo-squatted with a domain that merely looks similar, because domain names are just strings a registrar sells with no cryptographic tie to anything. A WeTheNorth onion cannot be typo-squatted the same way — an attacker has to actually generate a full alternate key pair and host a convincing clone behind it, which is exactly why the character-by-character compare on this page is the check that matters most.
Worked WeTheNorth comparisons, byte by byte
Reading the rules above is one thing. Working through two real side-by-side comparisons — a genuine WeTheNorth address next to a doctored one — makes the pattern concrete in a way a rule list alone does not.
Example one: a single swapped character deep in the string
Take the reference WeTheNorth address at the top of this page: hn2paw7hljeihrk7qm2toniay5bb4cfz46cav5iywnsv64klm45mypqd. Now imagine a phishing page hands you this instead: hn2paw7hljeihrk7qm2toniay5bb4cfz46cav5iywnsv64klm45mypqe. Scan the two side by side and at a glance they look identical — same length, same opening block, same general shape. The difference sits in the very last character: a d in the genuine WeTheNorth address became an e in the fake one.
This is exactly the trap a rushed comparison falls into. Most people check the first ten characters, confirm they match, and stop — which is precisely why a competent WeTheNorth phishing clone puts its single altered character near the end of the string, where attention has already dropped off. The four-block compare method exists specifically to defeat this: split both strings into four equal chunks and check every chunk, including the last one, not just the first.
A single-character swap like this one is not a cosmetic difference. A v3 onion address is a public key fingerprint — changing even one character points Tor Browser at a completely different, unrelated hidden service, one a phishing operator controls rather than the real WeTheNorth market. There is no "close enough" with an onion address.
Example two: a forbidden digit substituted for a similar-looking letter
The v3 onion alphabet uses base32: lowercase letters a through z, plus the digits 2 through 7. It never contains the digits 0, 1, 8, or 9, because those digits are visually confusable with letters (0/o, 1/l, and so on) and base32 was deliberately designed to exclude them. A WeTheNorth phishing page exploiting this might present ...toniay5bb4cfzO6cav5iywnsv64klm45mypqd — note the capital letter O substituted where the genuine address has the digit 4 (or, in a subtler version, a lowercase l swapped for a genuine 1-adjacent character), banking on the visual similarity between certain letters and forbidden digits to slip past a casual read.
The rule check catches this instantly and mechanically, with no need to eyeball anything: does the string contain any character outside a-z and 2-7? A capital letter alone is disqualifying, since a genuine onion address is always lowercase. A forbidden digit is disqualifying on its own. Either violation means stop immediately — the address is malformed and cannot be a genuine WeTheNorth v3 onion, full stop, regardless of how convincing everything else about the page looks.
These two worked examples cover the two most common WeTheNorth clone tactics this reference has seen: a swap buried late in the string, and a visually-confusable substitution exploiting the base32 alphabet rule. Neither survives a full character-by-character or a alphabet-rule check — which is exactly why skipping either check, even once, is the actual risk, not a shortcut worth taking.
Run both checks every time you are handed a WeTheNorth address from a new source — a forum post, a search result, a message from someone claiming to be a WeTheNorth vendor. The reference WeTheNorth string on this page is the only one this guide vouches for directly; any other WeTheNorth address earns trust only after it passes the same comparison, not before.
Address check questions
How long is a genuine WeTheNorth onion?
Fifty-six characters, every time. A version-3 onion is a fixed length, so anything shorter or longer is not the real address.
Can a real onion contain the number one or a zero?
No. Onion addresses use base32, which leaves out zero, one, eight and nine. Any of those digits in a string means it is not genuine.
The first ten characters match. Is that close enough?
No. Clones copy the opening on purpose. A swap usually sits in the middle or near the end, so all fifty-six characters have to match.
Does a matching string mean the site is safe?
No. A correct address only proves it was not altered. Who controls it is settled by the signature, checked on the home page.