ADDRESS HISTORY // CHANGELOG
WeTheNorth Onion Address History: The Rotation Archive
Onion v3 addresses are cryptographic keys, not rented domains, so a market like WeTheNorth can rotate to a fresh one at any time with no registrar involved. This page is the dated log of that: when a WeTheNorth address was confirmed, what triggered a change, and how each entry was verified against the signed record — not just a mirror list of what currently works.
http://hn2paw7hljeihrk7qm2toniay5bb4cfz46cav5iywnsv64klm45mypqd.onionThe active entry in this log. When WeTheNorth rotates, the new address is added below with a date and a confirmation method — the old row stays, marked retired, rather than being quietly overwritten.
Every confirmed entry, in order
One row per confirmed state of the WeTheNorth onion, oldest first when there is more than one. A row is added only after the address has been checked against the signed directory — a forum claim of a "new official link" does not earn a row here until it clears that bar.
| Date | Event | Confirmed via | Status |
|---|---|---|---|
| Current canon entered into the signed record as the reference address. | Character compare + directory listing (PGP signature pending Phase 0) | Active |
Honest limit: this is a young log with one entry. It has not needed to record a rotation yet. The row above is real; the format below is how the next one gets added, not a claim that one has happened.
From a claimed change to a dated entry
Nothing gets a row in the log because someone posted it somewhere. A claimed address change goes through the same intake every time before it earns a date and a place in this archive.
Check it against the signed record
The signed directory holds the reference address this archive logs against. Compare any address you hold against the canon there, then verify the key on the home page before you connect.
What actually triggers a WeTheNorth address rotation
An onion v3 address is generated locally, with no registrar to notify, so a rotation is entirely the operator's call. In practice a handful of reasons account for nearly every legitimate rotation across Tor-only markets, WeTheNorth included.
Scheduled key hygiene
Rotating on a routine schedule, independent of any incident, limits how long any single address stays a fixed target for abuse reports and takedown attempts. A scheduled rotation is boring by design — it should show up here as a clean log entry with no drama attached.
Suspected compromise
If an operator suspects a private key or infrastructure has been exposed, rotating the address invalidates whatever an attacker learned. This is the highest-urgency trigger, and the one most likely to get a same-day log entry once confirmed.
Unusual load or a denial-of-service pass
A sustained flood aimed at a specific onion address is sometimes easier to shed by rotating than by riding out. This looks, from the outside, like unexplained downtime followed by a new confirmed address — which is exactly what a log entry exists to explain after the fact.
What does not count as a rotation, no matter how it's phrased
A rebrand rumor, a "new official mirror" post with no signature behind it, or a name variant covered on the market url page are not rotations. Only a change to the actual signing key's output — confirmed against the canon — gets a row in this log.
What a log entry has to contain
A row in this archive is not just a date and an address. To be added, an entry needs four fields filled in — if any one is missing, it stays a rumor, not a logged rotation.
Date confirmed
The date this reference verified the change itself, not the date a forum post claimed it happened. Those two dates can differ by days if a claim circulated before anyone checked it.
Trigger, if known
Scheduled hygiene, suspected compromise, load pressure — whichever of the categories above applies, or "unstated" if the operator gave no reason. Guessing at a cause is worse than logging none.
Confirmation method
Exactly how the new address was verified: character compare against the prior canon, PGP signature match once the key is live, and/or a listing in the operator's own signed directory.
Before / after
The retired address stays in the log, marked retired, next to the one that replaced it — so a reader can see exactly what changed, not just what is current today.
Format template, illustrative only — not a real WeTheNorth event:
[DATE] — rotated after [scheduled key refresh / suspected compromise / load event]
confirmed via [signature match / directory listing] within [N]h of the claim
previous address: retired, kept above for referenceWhy an unsigned "it moved" post never becomes a log entry
A search result or a forum post can say WeTheNorth's address changed, and rank well, and sound confident, without any of that being evidence. Ranking and confidence are not cryptographic properties — they say nothing about whether an address is genuine.
What a signed entry adds that a claim can't
Every row in this log traces back to a character compare against the prior canon and, once the key is live, a PGP signature over the new address. A clone or a rumor can copy the wording of a real rotation announcement; neither can forge the signature. When a claim and this log disagree, the log wins, precisely because it can be checked independently rather than taken on faith.
How to read any WeTheNorth rotation archive, including this one
A rotation log is only as trustworthy as the process behind it. The two panels below cover what a responsible archive does before adding a row, and how to weigh this one against any other WeTheNorth history you come across.
What should happen before an address earns a row here
A trustworthy rotation entry passes through two gates before it is worth publishing. First, the address has to actually resolve over Tor and serve the real WeTheNorth market, not a parking page or nothing at all — a dead or squatted address has no business getting logged as current regardless of where the claim came from. Second, the address has to match the canon that WeTheNorth's own signed record vouches for; one that loads and looks right but fails the check is a clone entry, not a rotation, no matter how functional it appears.
An archive that skips either gate is not a history, it is a liability. The fastest way to spot one that skipped these checks is the absence of any confirmation method next to each row — a log with dates but no stated verification method is asking you to trust it on style alone.
Weighing this archive against others you find
Never treat a single rotation log, including this one, as the sole source of truth. The useful habit is cross-referencing: does the entry this archive shows as current match what a second, independently maintained verification reference shows? Do both point to the same signing key once the fingerprint is published? Agreement across independently maintained sources is a stronger signal than any single archive's claims about itself.
Where archives disagree, the tie-breaker is always the signature, never which page looks more polished or ranks higher in search. Apply that standard here as much as anywhere else — the goal of this log is to survive that same scrutiny, not to be taken on faith.
Rotation archive questions
Has WeTheNorth's onion address ever actually rotated?
Not since this archive started logging. One entry exists, dated 2026-08-22. That is stated plainly rather than padded out with invented history.
Someone posted a "new WeTheNorth link." Is that a rotation?
Not on its own. It becomes one here only after it is compared against the canon and, once published, checked against the PGP signature. Until then it is an unconfirmed claim, not a log entry.
Where is the signature actually checked?
On the home page, where the fingerprint and the signed directory live. This archive logs when and how each confirmed change happened.
Why does the log only have one row?
Because the address has only had one confirmed state since this reference began tracking it. A short log is accurate; a long one padded with unconfirmed claims would not be.