Short answer: Download software only from torproject.org or the official app store. A .onion address proves key possession, not legitimacy. Abort when rushed, when support chats push links, or when someone offers a “portable Tor” bundle.
Phishing in the Tor ecosystem uses the same psychology as on the clearnet: urgency, fear, and an address that looks almost right. The difference: long v3 addresses are hard to memorize, so people rely on directories — and that is exactly where clones appear.
Official software from the source only
Tor Browser comes from torproject.org. Do not download installers from ad blogs, Telegram channels, or “mirror” sites without verifiable signatures.
Check:
- The domain is spelled exactly (no
tor-project,torproject.netimitations). - HTTPS and the expected certificate in the browser.
- Signatures and checksums per official documentation.
Setup instructions: Tor Browser setup.
Why .onion is not a trust guarantee
A third-generation onion address is a public key. It proves whoever holds the matching private key runs the service. It does not prove that operator is honest, competent, or legal.
Typos usually produce an invalid address. Targeted lookalikes remain possible when attackers promote a similar string. Signed mirror lists help only after you bind the signing key independently — PGP for Tor users.
Practical checks without market directories
- Did you arrive via a source you already trust (authority, newsroom, Tor Project, your own notes)?
- Is the address PGP-signed on a page whose key you know independently?
- Did login, design, or fee demands suddenly change?
If any answer is uncertain: do not sign in, do not enter data, stop. How directories and v3 prefixes fit that check: Finding verified onion links.
Common tricks
Urgency. “Account deleted in 20 minutes.”
Authority. Fake support chats.
Convenience. Pre-built “portable Tor” packages with extra software.
Third-party portable bundles are a classic infection vector. Use the official installer.
Limits
No guide replaces a threat model. Protecting sources also requires OPSEC fundamentals and a clean device. TorBible does not publish market lists or “verified mirrors.”
Sources
- Tor Project: How to download Tor Browser
- EFF: Phishing
- Tor Specifications: Onion Services v3