Security & OpSec Guide

CRITICAL DOCUMENTATION: Mandatory operational security protocols for authenticated network interaction. Failure to adhere to these guidelines results in catastrophic exposure.

01. Identity Isolation

Operational security begins with absolute separation. You must never mix real-life identity (clearnet presence) with your Tor network identity. A single overlapping data point can lead to total deanonymization.

  • No Reuse: Do not reuse usernames, monikers, or passwords from any clearnet sites.
  • Data Silos: Keep your darknet activities strictly confined to a dedicated operating system environment (such as Tails OS or Whonix).
  • Zero Real Contact: Warning against giving out personal contact info. Never provide real email addresses, phone numbers, or social media handles under any circumstances.

02. Interception Defense & Verification

Man-in-the-Middle (MitM) attacks are the most prevalent threat on the network. A malicious proxy node intercepts your connection, silently rewriting digital interfaces and cryptocurrency addresses to siphon funds.

MANDATORY PROTOCOL: Verifying the PGP signature of the onion link against the official market public key is the ONLY definitive way to be sure your connection is authentic.

Never trust links obtained from random wikis, public chat forums, or Reddit threads. Always verify the signature block manually. If the cryptographic signature fails, terminate the connection immediately.

03. Tor Browser Hardening

The standard Tor Browser requires manual hardening before accessing resilient hidden services. Default settings are insufficient for high-threat environments.

Security Slider

Must be set to "Safer" or "Safest" to disable dangerous web features.

Disable JavaScript

Utilize NoScript to block JS execution where possible to prevent exploits.

Window Sizing

Never resize the Tor browser window; it creates a unique fingerprint.

04. Financial Hygiene

Blockchain ledgers are permanent and publicly auditable. Poor transactional practices will leave a permanent trail connecting your real identity to the market.

Rule 1: Never send Bitcoin directly from a centralized exchange (e.g., Coinbase, Binance, Kraken) to Prime Market. You must route funds through a personal intermediary wallet, such as Electrum or Monero GUI.

Rule 2: The use of Monero (XMR) is highly recommended over Bitcoin (BTC). Monero provides obfuscation at the protocol level, hiding sender, receiver, and transaction amounts.

05. PGP Encryption (The Golden Rule)

"If you don't encrypt, you don't care."

Cryptography is your absolute final line of defense against infrastructure seizure or database leaks. All sensitive communications and shipping addresses must be encrypted.

  • Client-Side Only: Encryption must happen on your own computer using software like Kleopatra, GnuPG, or Tails' native tools before pasting text into the site.
  • Never Auto-Encrypt: Never check the "Auto-Encrypt" box on a marketplace website. Server-side encryption requires you to trust the server and eliminates the point of end-to-end security.

Official Archive Key Reference