A copycat mirror ring is reusing three project names to seed phishing pages
Two clusters of look-alike darknet market addresses appeared this week. Neither matches an address on file, and both fail a basic character check against our verified record.
This week we logged two clusters of look-alike addresses trading on the names of markets people recognise. Neither cluster matches a string on our records, and both fall apart under the most basic character check. They are worth writing up not because they are clever — they are not — but because they are typical, and the pattern repeats every month under different names.
How the ring is built
A copycat ring is a handful of onion addresses and a stack of pages that all point at them. The pages borrow a real project's name, its colours, sometimes whole paragraphs of its text. The only thing that differs from the genuine article is the address itself — and it only has to differ by one character to send a login and a deposit to the operator instead of the market.
Why it works on careful people
Because the addresses are long and readers skim. A fifty-six character string reads as noise, so the eye checks the first few letters, sees a familiar prefix, and stops. Rings exploit exactly that: they reuse a recognisable prefix and change characters deep in the middle, where nobody looks. The prefix feels like proof; it is nothing of the kind.
What we did with the clusters
Nothing dramatic. We compared each address to the strings on file, confirmed none matched, and left our records unchanged. That is the entire point of keeping a reference set: when a plausible new address appears, the question is never "does this look right" but "is this the string we already hold" — and if it is not, it earns no place on the page regardless of how convincing the surrounding site looks.
What you should take from it
Assume that for every market you use, a ring like this exists right now. That is not paranoia; it is the baseline. Keep a trusted source, check the full string, and never let a familiar prefix or a polished page do your verification for you. The market's real record will still be there when you get back to it.
What we verified vs what remains unconfirmed
Being precise about what this alert actually establishes matters more than the alert itself, so here is the honest split.
Verified: the two clusters do not match our records
What we directly confirmed is narrow and mechanical: we compared each address in both clusters, character by character, against the strings held on our signed source, and none matched. That comparison is the entire basis for calling these clusters fake, and it is a check any reader can repeat themselves rather than take on our word.
Unconfirmed: scale, operator identity, and whether the two clusters are related
What we did not establish, and are not claiming, is how large either cluster actually is beyond what we personally logged, who operates them, or whether the two clusters share an operator versus being coincidentally similar opportunistic copies. "Ring" in the headline describes the pattern — a cluster of coordinated look-alike addresses and pages sharing infrastructure or content — not a confirmed single group behind both instances; treat any inference beyond that as speculation this piece does not make.
Why this alert stays this narrow on purpose
It would be easy to round "two unmatched address clusters" up into a bigger story about an organized campaign, and that upgrade would make for a more dramatic headline. We do not make it, because the actionable part of this alert — compare the full address against a trusted source, ignore the prefix — does not depend on knowing who built the clusters or how big they eventually get. The verified mechanism protects a reader regardless of the unconfirmed scale.
If you already interacted with one of these addresses
If you visited a page from either cluster this week but did not enter credentials or send funds, no action beyond normal caution is needed — close the tab, and use the market's verified record on this wire for any future visit. The risk in a look-alike page comes specifically from what you typed or sent there, not from the page having loaded in your browser.
If you entered a login or password
Treat that login as compromised. If you reused the same password anywhere else, including on a real market account, change it there too. A phishing clone's login form exists to capture exactly what you type, and it will "work" regardless of whether the credentials were correct, so a successful-looking login is not reassurance.
If you sent funds to an address from either cluster
There is no recovery mechanism this wire can offer for coins already sent to a phishing address, and no Monero or Bitcoin transaction reverses once confirmed; that is precisely why the verification habit described throughout this site exists before the deposit, not after. What you can still do is confirm the market's genuine address from its market record so any future transaction goes to the right place.
How often clusters like this appear
This is not the first mirror ring this desk has logged, and it will not be the last. Clusters built on recognisable project names surface on a rough monthly cadence, usually timed around a genuine rotation, a spike in a market's search visibility, or simply opportunistic registration by an operator testing whether a given name still draws traffic. The specific projects targeted change; the mechanics described above do not.
Why this happens on a roughly monthly cadence
Registering a batch of look-alike onion addresses and standing up cloned pages behind them is cheap and mechanical, which is exactly why the cadence holds steady even as the specific targeted names change. There is no seasonal reason for the monthly rhythm beyond how quickly a given batch of fake addresses gets flagged, abandoned, or simply stops drawing traffic once the underlying rotation or news cycle it was riding has passed.
Why these particular three project names, this time
The choice of which project names a ring imitates is rarely random. Looking at why these three names specifically drew a copycat cluster this week says something useful about how an operator picks a target, separate from the mechanics of how the fake pages themselves are built.
Name recognition is the primary driver
A copycat operator gets more return on effort imitating a name a lot of people are already searching for than inventing a brand-new, unfamiliar one from scratch. The three names targeted this week are all names that show up regularly in Deep Web Wire's own traffic and in general search interest, which is precisely why they were worth imitating from a phishing operator's perspective.
Timing around a genuine event increases the payoff
A copycat cluster launched during or shortly after a genuine mirror rotation for the same project catches readers who are already primed to expect an address change and are less likely to apply their usual scrutiny. Deep Web Wire did not confirm that this specific timing pattern applied to this week's two clusters, but it is a recurring feature of past rings this desk has logged, and worth watching for regardless of which project's name gets reused next.
What this means for a project not named this week
A project's absence from this particular alert is not a guarantee it will not be targeted next month. The underlying mechanism — register look-alike addresses, clone the page, wait for someone to skip the character check — applies equally to any project with enough name recognition to be worth impersonating, which in practice includes every market Deep Web Wire tracks.
How to spot the next one before we write about it
Deep Web Wire's desk logs these clusters after the fact, which means a reader relying solely on this news section to learn about a ring is always working from slightly stale information. The more durable protection is knowing the pattern well enough to catch the next cluster yourself, before it makes it into a Deep Web Wire post at all.
Signal one: urgency language
Real projects rarely rush you
A cloned page pushing "verify now or lose access," a countdown timer, or language implying your account is at risk if you don't act immediately is a tell this Deep Web Wire desk sees repeatedly. A genuine darknet market address record, including every one Deep Web Wire publishes, has no reason to pressure a reader into skipping the character-by-character check.
Signal two: a channel with no history
Look for a track record
A phishing cluster's supporting page or forum account is usually recently created, with little to no history predating the specific campaign. A genuine project's announcement channel, by contrast, typically has a long, consistent posting history a reader can actually check.
Signal three: the address itself, checked in full
The check that matters most
Every signal above is a useful heuristic, but the address comparison described throughout this Deep Web Wire post is the check that actually catches a copycat mirror regardless of how convincing the surrounding page looks. Read spotting a fake mirror for the complete walkthrough Deep Web Wire maintains on this exact topic.
Frequently asked questions
- How many addresses were in each of the two clusters?
- We logged what we personally observed and are not claiming a precise total beyond that; the clusters' exact scale is one of the unconfirmed details noted above.
- Were the three project names in the headline named as targets, or just the pattern?
- The pattern is the point of this alert. We describe the mechanism, not a full target list, because the mechanism is what protects a reader regardless of which name gets reused next.
- Should I stop using a market because a fake mirror ring targeted its name?
- A ring targeting a project's name recognition says nothing about that project's own legitimacy. It says the project is popular enough to be worth impersonating, which is common for any well-known market.
- Will Deep Web Wire post an update if the same ring resurfaces?
- If new information changes the picture described here, it will appear as a dated correction on this same post rather than a silent edit; see how this section handles corrections on the news index.
Published Aug 21, 2026. Deep Web Wire does not run sponsored posts; this note reflects what we observed and recorded.