Skip to content

How to verify a Nexus Market mirror with PGP canary

Published October 7, 2026 · Nexus Mirror Desk

Phishing attacks target darknet markets daily. Attackers register domains that look almost identical to the real one. One letter difference is enough. You cannot trust your eyes alone. You need cryptographic proof. Nexus publishes a PGP signed canary file on every official mirror. This file contains a static string and a timestamp. It proves the server holds the private key. To verify, download the canary file from the mirror. Save it to a safe directory. Then, retrieve the public key from a trusted source. Do not copy the key from the same website you are verifying. That defeats the purpose. Get the key from the official GitHub repository or the initial announcement thread. Import it into your GPG client.

On Linux, use gpg --import filename.pub. On Windows, import it via GPG4Win. Once imported, run the verification command. Point gpg --verify at the downloaded canary file. The output will show Good signature if everything matches. Read the message content. It states the current valid addresses. Compare them with what is displayed in your browser. If the text differs, you are on a clone. Close the tab. Do not proceed. The signature checks authenticity, not necessarily freshness. Always check the date inside the canary. If it is older than forty-eight hours, the mirror might be outdated. Switch to another mirror. This process takes about three minutes. It is tedious but essential.

Many users skip it after the first successful login. They assume the site remains real forever. Attackers change tactics. They might hijack a DNS record or take over a hosting provider. Re-verify before every major transaction. Before sending large amounts of Monero or Bitcoin, run the check again. Habit beats memory. Make it part of your routine. If you forget, you risk paying a vendor who does not exist. The cost of caution is low. The cost of error is total loss.