Verify a Nexus Market address before you log in
A wrong letter opens someone else's site. This is the checklist to run on any address you are told is Nexus Market, in about a minute. Work top to bottom. A real address passes all four checks; a fake usually fails within the first ten seconds.
The four checks
.onion. Count by selecting the string and checking your editor's counter, or count in blocks of ten. Fifty-seven characters is a different address. Fifty-five is a typo. Both are not the market.nexus. That prefix was mined on purpose, and it is the fastest tell there is. An address that starts nexusx, nexusm or just nex is one letter away from looking right, which is exactly where fakes want to be.The fifth check: the first page must be the market's
Characters can be spoofed. The first page you see is harder to fake convincingly, because fakers skip it to get to the login form.
The real sequence, in order:
The browser check
A dark screen, the NEXUS wordmark with the red X, and the line "Checking your browser before accessing Nexus Market. This process is automatic." It says to allow up to 30 seconds. Allow it.
The DDoS protection
A panel titled "DDoS Protection" with six input boxes, a red circle containing distorted characters, a countdown timer running from 60 seconds, and a red SUBMIT button. You type what is in the circle. You are not asked for a username or password here.
The market itself
The shop. Dark interface, the NEXUS logo, categories. The login form appears only now, on the login page, after you are in.
If your "Nexus" address goes straight to a login form with no check and no captcha, one of two things is true: it is the market on a rare quiet day, or it is not the market at all. Assume the second until you see the first. The first visit page has the full walkthrough of both screens.
The password rule
You only type your Nexus Market password on the market, inside Tor, on the page that came after the captcha. Nowhere else. Not on any clearnet page, not in a browser you do not run through Tor, not on a "recovery" page someone messages you, not in a form that appeared before the DDoS check. If a page asks for the password before you have seen the captcha, close it and start from the address list again.
After a pass: what to do with a confirmed address
- Save it where only you can see it. A password manager field or a note on paper. Not a screenshot in a chat, not a shared note.
- Know the last six characters by pattern, not by heart. You will recheck them every session, and pattern beats memory for a 56 character string.
- Bookmark it in Tor, if your version lets you. Tor Browser keeps bookmarks per profile, and they do not leak to other browsers. That is your personal verified source from now on.
When the market itself changes an address
Address changes are announced inside the market with a PGP signed message, and the new addresses keep the nexus prefix. The signature is what makes the announcement trustworthy, because the key belongs to the market, not to whoever is forwarding the news. How to read such an announcement, and how to tell a real change from a phishing wave, is on the address changed page.