Clone teardown // tells // 2026
Anatomy of a Fake Mirror
A convincing fake does not look wrong. It looks exactly right, because it copied a page like this one character for character and changed the single thing you cannot eyeball: the onion. This teardown shows how a clone is put together, and the tells that surface before you ever type a password. The one string a clone cannot hold is the signed one on the card.
torzonguqmlfy2kfi5tjbnt4bp3idtkjzi4qtupmhpdihjftomjtdzqd.onionOpen the cardHow a clone earns a login it should never get
A phishing mirror is not clever, it is patient. It leans on the fact that people trust what a page looks like. Three moves take it from a copy to a stolen account, and none of them touch the part that actually matters.
Five tells that give a clone away
- The string is off. One or two characters differ from the signed onion. This is the only tell that always holds, and the only one worth trusting.
- No real signature. A key block that will not verify, a fingerprint with nothing behind it, or a page that skips PGP and tells you to just trust the link.
- Everything is green. Fake sites love a wall of Online badges. An honest board shows Checking far more than it shows a live node.
- Urgency at the door. Countdowns, a login that demands money before you are in, or a missing captcha where the real gate should be.
- Pay off-market. Any push to send coin outside the market escrow, to a wallet pasted in chat or on the page, is the clone showing its hand.
Only the first tell is decisive. The rest raise suspicion, but a careful clone can dodge them. The string, checked against the signed set, cannot be faked.
The real card next to a clone
Lined up, the difference is not in the pixels. It is in what each one can prove and what it asks of you.
The signed card
- Shows the full 56-character onion that matches the signed record.
- Leaves statuses on Checking until a probe actually answers.
- Points every payment through the market escrow in Monero.
- Never handles your funds or asks for a keystroke it cannot justify.
A phishing clone
- Carries a near-identical string with a few characters swapped.
- Paints everything Online to look busy and trustworthy.
- Rushes you with a countdown or an upfront payment demand.
- Steers coin to a wallet it controls, outside any escrow.
Clone questions people ask
It looked identical, so how was it fake?
Identical is the point. A clone copies the markup, so the look tells you nothing. What it cannot copy is a valid signature over the real onion, which is why the check happens on the string, never on the page.
Can a clone fake the PGP signature?
No. It can paste a key block and a fingerprint that look the part, but it cannot produce a signature that verifies against the real signing key. That is the whole reason the key outranks the domain.
There is a padlock and https, doesn't that prove it?
No. A certificate only says the connection is encrypted, not that the site is Torzon. Onion services do not use it the way clearnet does. A padlock has never verified an onion address.
Prove a string in one command
Now that the trick is clear, put the defence to work. The bench turns "looks right" into a hard pass or fail.