Staying safe

The scams that keep coming back

The same handful of frauds have been catching people on Tor for over a decade. They recur because they work. Here is what each one looks like.

The frauds on the Tor network aren’t especially inventive. The same small set has been running for over a decade, going quiet when attention gets uncomfortable and coming back under new names a few months later.

They recur because they work, and they work because each one exploits something structural about how the network operates rather than a mistake the victim could obviously have avoided. Learning the shapes is more use than any list of sites to avoid, because the sites change constantly and the shapes don’t change at all.

The lookalike address

Oldest and most dependable.

An onion address is fifty-six characters of noise. Nobody verifies one by reading it, so people check the first few and the last few and assume the middle is fine. Attackers generate addresses matching at both ends, stand up a copy of the real site, and get it into circulation.

The copy is often a working mirror, passing your traffic through to the genuine site so everything behaves exactly as expected, while quietly recording your credentials and swapping payment details in transit. There may be no symptom at all until the money doesn’t arrive.

Defence: addresses come from the organisation that owns them, on the ordinary web, over an encrypted connection. Nowhere else, ever.

Every time a batch of addresses breaks, demand for replacements spikes. The 2021 retirement of the old address format was the largest such event by far, and directories offering fresh, verified, updated links appeared in quantity to meet it.

A directory is the ideal delivery mechanism for the previous scam. Trusted by default, carrying enough entries that only one needs poisoning, and visited precisely by people who had no other way to check.

Defence: treat any third-party list of addresses as unverifiable, however professional. Scam warnings on a directory are not evidence the directory is safe. They’re cheap to write.

The swapped clipboard

Malware watching for anything resembling a cryptocurrency address being copied, and silently replacing it with the attacker’s before you paste.

Devastating because the address is meaningless to you either way. You copied a string you can’t read and pasted a string you can’t read. Nobody notices, and payments don’t reverse.

This runs on your own computer and has nothing to do with Tor, which is exactly why routing your traffic doesn’t help in the slightest.

Defence: check the first and last several characters after pasting. Every time. Tedious, and the only thing that reliably catches it.

The fake browser

Modified copies of Tor Browser distributed through download aggregators, search adverts and mirror sites. They install and run normally while reporting where you go, or substituting addresses you copy.

Some have operated for years and taken very large sums. Adverts impersonating the Tor Project turn up in search results repeatedly, which is its own small commentary on search advertising.

Defence: torproject.org/download, and nowhere else. Never pay for it — it’s free.

The exit scam

A marketplace or escrow service operates honestly for a long stretch, building real reputation and accumulating deposits. Then one day it stops paying out and vanishes.

The honest phase isn’t good intentions that went wrong. It’s the investment, and its length is proportional to the eventual take. Reputation earned over years is exactly what makes people comfortable leaving larger balances sitting there.

Defence: reputation on an anonymous platform predicts nothing, because the operator’s incentives invert the moment leaving becomes more profitable than staying.

The recovery service

Last, because it’s the nastiest.

Somebody loses money to one of the above and starts looking for help. Services appear offering to trace or recover stolen cryptocurrency for a fee, paid upfront.

They can’t do it. The blockchain is public, so anyone can watch where funds went, but watching isn’t retrieving. No mechanism exists to reverse a transaction or compel a wallet holder to hand anything back.

These operations specifically target people who’ve just been defrauded, on the sound reasoning that someone who lost money once is motivated enough to pay again. Some appear to be run by the same people responsible for the first loss.

Defence: if it’s gone, it’s gone. Anyone promising otherwise for a fee is taking the second bite.

Why the same handful keeps working

Three structural facts, none of which look likely to change.

Addresses can’t be checked by eye. Every impersonation attack rests on this. It’s a consequence of the design, not a bug in it.

Payments don’t reverse. No chargeback, no intermediary, no appeal.

Victims mostly don’t report. People defrauded while doing something they’d rather not explain tend to say nothing, so patterns take far longer to become visible than they otherwise would. Which buys the operators time they haven’t earned.

The one habit that helps most

If you keep a single thing from this: where an address came from matters more than anything about the site it leads to.

A convincing site reached through an address you can’t verify is worth less than a plain one reached through an address you can. Nearly every fraud here starts at the moment somebody accepts an address from a party with an interest in which address they get.

Next

The Hidden Wiki, then and now follows one directory through this decay in detail. Is Bitcoin anonymous covers why payments made in these situations are a good deal more traceable than people assume.

Leave a note