SCREENING METHOD · WHAT VERIFIED MEANS · 2026

How We Verify a Darknet Market in 2026: Mars Screening Criteria

Short answer: a market earns a place here when its onion is PGP-signed, its canary is current, and its mirrors answer their own probe. Popularity buys nothing. This page is the screening method itself — the fixed criteria a project has to clear before it earns a row anywhere on this network. For the plain listing of every project we currently track, see the network directory on mars-review.com. Below is how the screen runs, which projects we watch, and what to check yourself before you trust any darknet market link in 2026.

CANON POINTERThis directory does not restate the full mirror table. The verified address and the full signed list live on the Mars canon (home).
WHAT COUNTSfour signals

What makes a darknet market "verified"?

Verified is a narrow word here. It does not mean safe, legal, or good. It means the address ties back to a key you already hold, so a clone cannot slip in wearing the same name. Four signals carry that weight.

Signed mirror list

The onion set ships with a PGP signature, so you check the list against a fingerprint instead of a logo.

Live canary

A dated, signed note the operators refresh. A stale canary is a reason to wait, not to log in.

Honest status

Mirrors read as checking or dead until a probe says otherwise. A hard-coded green light is a warning sign.

Escrow on Monero

Orders hold in escrow and settle in Monero. A page that wants a direct deposit is not the market.

Why we won't loosen these four

It would be easy to widen this list — add "has a Reddit thread," "has been up a while," or "looks professional" as extra signals. We don't, because none of those three actually stop a clone. A phishing page can have a Reddit thread praising it (sometimes written by the same operator), can stay up for weeks before the exit scam, and can look more polished than the real market it is copying. Signature, canary, honest status, and a real escrow model are the four things a copy-paste clone cannot fake convincingly, which is exactly why they are the bar here.

What "verified" does not promise

Verified on this page never means we vouch for a market's staff, its vendor quality, or the outcome of any specific order — those are things no directory can check from outside. It means, narrowly, that the address in front of you traces back to a key that has been consistent over time. That is a meaningfully smaller claim than "safe," and we keep the two separate on purpose so nobody reads a checkmark here as a guarantee about what happens after you log in.

SELECTIONour method

How a market gets onto this list

Nothing is hand-waved onto the page. Each candidate runs the same short gauntlet before it earns a row, and it leaves the moment a signal goes quiet. This is the shape of that screen.

How we screen a darknet market into the listCandidatea named marketScreensignature + canaryListedor dropped
1 · CandidateA market gets named, usually from a forum lead. The name alone buys it nothing here.
2 · ScreenWe look for a signed mirror list and a current canary. No signature, no row.
3 · ListedIt goes on watch, and comes off the second the canary stalls or the key changes.
ON WATCHnamed plainly

Which markets we monitor for 2026

These are projects we track, written as plain text on purpose. We do not paste a live link to a market we cannot sign, so read every name as a lead to verify on its own signed directory, never as a click-through. Each entry below breaks down the same three things: what we track for mirror count, what we know about escrow model, and where PGP verification actually happens for that project.

Mars — the reference we sign directly

Mirror count: five reference entries tracked on this site — one primary, two failovers, one additional mirror, and one retired legacy address kept visible so it is not mistaken for live.

Escrow model: orders settle on-chain and hold in escrow until they clear; this directory never touches funds or processes orders itself.

PGP practice: a canon fingerprint slot is published on the home page and the verify page, pending Phase 0 signing — always check the fingerprint against the mirror list before trusting an address.

Torzon — large, cross-checked, not tracked here

Mirror count: not tracked on this site. Torzon runs its own mirror list, which is why our compare table on the home canon points outward rather than repeating a number we did not verify ourselves.

Escrow model: covered on Torzon's own reference, not restated here — we do not carry secondhand escrow claims for markets we do not operate.

PGP practice: confirm any Torzon address against Torzon's own signed source before use; a name match on this page is not a substitute for that.

Nexus — watched for uptime and canary freshness

Mirror count: not tracked here; status shown elsewhere in our monitoring means "monitored," not "verified by us."

Escrow model: not restated on this page — check Nexus's own directory entry for current escrow and payment details.

PGP practice: treat any Nexus link the same way you treat a Mars link: no signature match, no trust.

Vortex — mirrors rotate quickly

Mirror count: not tracked here. Vortex mirrors have historically rotated on a shorter cycle than some peers, which is exactly why a name match alone is never enough to trust a Vortex link.

Escrow model: not restated here — verify on Vortex's own signed source.

PGP practice: same rule as every entry on this list — fingerprint first, address second.

WeTheNorth — region-focused, often offline

Mirror count: not tracked here; WeTheNorth publishes its own status board, and we mark our listing down whenever a probe from our side also reads down.

Escrow model: not restated on this page — WeTheNorth's own reference is the source for current terms.

PGP practice: WeTheNorth's canary and key belong to WeTheNorth's own directory, not to this Mars-first page.

Omega — listed, not independently tracked

Mirror count: not tracked here. Omega is named on our compare table as a project we watch by name only.

Escrow model: not restated on this page — check Omega's own signed source before you rely on any escrow claim.

PGP practice: apply the same fingerprint-first rule; we hold no Omega key here to check against.

DrugHub — listed, not independently tracked

Mirror count: not tracked here. DrugHub appears on the compare table as a pointer only, with the caveats above.

Escrow model: not restated on this page — confirm current terms on DrugHub's own reference.

PGP practice: we do not sign or hold a DrugHub key; verify any address against DrugHub's own canon.

New to the category? Read what a darknet market is, then the honest Mars review.

RED FLAGSclone patterns

What separates a listed darknet market from a phishing clone

Every project on the watch list above has, at some point, had a phishing clone built against its name. That is not a Mars-specific problem — it is the default state of any darknet market popular enough to be worth impersonating. Clones are cheap to stand up: copy the HTML, register a lookalike domain or spin up a fresh onion, change the deposit address, and wait for someone to skip the verification step. The patterns below are what we watch for when screening a candidate, and what you should watch for yourself before trusting any link, ours included.

The domain or onion is new but the branding is identical

A market that has been operating for a year does not suddenly appear on a brand-new onion address with no prior mention anywhere signed. If a link surfaces that looks pixel-identical to a market you recognize but the address does not match anything in a signed mirror list, treat the mismatch as the finding, not the branding as reassurance.

The PGP key changed without an announcement

Operators who rotate their signing key do so with a signed transition message from the old key to the new one. A silent key change — where the new key simply appears with no chain back to the old one — is functionally indistinguishable from someone else taking over the identity. This is the single most common failure point across every darknet market we have tracked over multiple years, and it is why the canary and signature checks above exist as a pair rather than either one alone.

Escrow terms quietly loosen right before a shutdown

A market that has run standard escrow for months and then starts pushing "finalize early" prompts, shortens its dispute window, or asks for direct wallet-to-wallet payment outside its own system is showing the classic pre-exit-scam pattern. This is not unique to any one project in the network above; it has happened across the category repeatedly, which is why "escrow on Monero, held until release" is one of the four non-negotiable signals rather than a nice-to-have.

The mirror list looks copied, not signed

A real signed mirror list is a short, dated, PGP-signed block of text — usually a handful of addresses, not dozens, and it changes rarely. A page presenting fifty "mirrors" with no signature attached is not a mirror list; it is a link farm, and link farms are one of the most common vectors for driving traffic toward a clone. If a source cannot show you a signature over its list, the list itself carries no more weight than a random forum post.

SignalVerified patternClone pattern
PGP key historyRotations are signed and chained to the prior keyKey appears with no signed transition
Canary cadenceDated, refreshed on a visible scheduleMissing, static, or copy-pasted from elsewhere
Escrow behaviorHolds funds until release, consistent over timePushes early finalization or off-platform payment
Mirror list formatShort, dated, PGP-signed blockLong unsigned list or third-party aggregator page

None of this replaces checking the fingerprint yourself. Read how to verify a Mars onion link for the exact steps, or start from how to access Mars if you have not connected yet.

QUESTIONSplain answers

Questions about the 2026 list

What makes a darknet market verified?

A signed onion list you can test against a PGP fingerprint, plus a current canary. Verified means traceable to a key, not safe or endorsed.

How do you choose which markets to list?

Each candidate needs a signed mirror list and a fresh canary before it earns a row. It drops off when either signal goes quiet.

Is a bigger market a safer market?

No. Size draws clones and exit-scam risk. A small market with a current signature is easier to trust than a busy one without one.

Are these darknet markets still active in 2026?

Some are, some stall between checks. Addresses rotate and mirrors drop, so confirm each link on its own signed source first.

Why don't you list a mirror count for Torzon, Nexus, Vortex, WeTheNorth, Omega, or DrugHub?

Because we don't operate them and haven't built a signed mirror table for them the way we have for Mars. Publishing a number we can't back with our own signature would be exactly the kind of unverified claim this page exists to warn against, so we point to each project's own reference instead.

What should I do if a market on this list has no PGP key published?

Treat that as a reason to wait, not a detail to skip past. A market without a published, checkable key is asking you to trust its domain name alone, and domain names are exactly what phishing clones copy first.

Does this list rank markets against each other?

No. This is a screening method, not a leaderboard. A market either passes the four signals above or it doesn't; we don't score one passing market as "better" than another passing market.