Phishing
Fraud that mimics trusted sites or messages to steal credentials, seeds, or deliver malware — equally common on clearnet and Tor.
Phishing is the most profitable attack in the onion ecosystem precisely because of what makes onion services secure: a 56-character Onion Address cannot be memorized, so users copy it — and whoever controls the copy controls the destination. Clone sites reproduce a market or forum pixel-for-pixel and harvest logins, deposits, and one-time codes in real time.
The usual shapes
The classics are lookalike addresses that share a short prefix with a known service, “mirror lists” on forums and search engines that swap every address, and messages imitating support staff — Social Engineering with a login form attached. A phished password plus a relayed one-time code defeats most logins; a PGP-based challenge does not relay as easily, which is why it became the stronger norm.
Why the defense is procedural
Tor Browser has no safe-browsing list for onion clones, and no certificate authority vouches for an address. Verification is therefore a habit: addresses from primary sources, signed where possible, bookmarked once verified. The detailed checklist is in the phishing detection guide; the mindset belongs to OPSEC.
Category: Threats