Knowledge Base
Operational security protocols, platform mechanics, and troubleshooting.
Access & Routing
DarkMatter is a decentralized infrastructure layer operating exclusively on the Tor network. We facilitate secure, anonymous peer-to-peer transactions using Monero multisig escrow. This site serves as the cryptographically signed gateway to our hidden services, ensuring you bypass phishing attempts and access verified entry nodes.
Verification is mandatory for OpSec.
1. Import the DarkMatter Public Key (available on /mirrors).
2. Upon accessing a market URL, locate the signed PGP message.
3. Decrypt/Verify this message using GPG/Kleopatra.
4. Confirm the signature matches our key ID exactly.
If the signature is invalid or missing, you are on a phishing site. Leave immediately.
1. Import the DarkMatter Public Key (available on /mirrors).
2. Upon accessing a market URL, locate the signed PGP message.
3. Decrypt/Verify this message using GPG/Kleopatra.
4. Confirm the signature matches our key ID exactly.
If the signature is invalid or missing, you are on a phishing site. Leave immediately.
Javascript is a primary vector for de-anonymization attacks. DarkMatter functions entirely without client-side scripts to prevent browser fingerprinting and XSS vulnerabilities. We strongly recommend setting Tor Browser security to 'Safest' to disable JS globally.
The Tor network is subject to latency and occasional DDoS attacks. If a specific mirror times out:
1. Refresh your Tor circuit (New Identity).
2. Attempt a different mirror from our verified list.
3. Ensure your system clock is synchronized (UTC).
We rotate mirrors every 6 hours to mitigate targeted attacks.
1. Refresh your Tor circuit (New Identity).
2. Attempt a different mirror from our verified list.
3. Ensure your system clock is synchronized (UTC).
We rotate mirrors every 6 hours to mitigate targeted attacks.
Account Security
Registration is open but requires a captcha solution. You must provide a username, password, and a 6-digit withdrawal PIN.
CRITICAL: Immediately upon registration, upload your PGP Public Key in settings. This enables 2FA and allows vendors to encrypt shipping data. Accounts without PGP keys are purged after 7 days of inactivity.
CRITICAL: Immediately upon registration, upload your PGP Public Key in settings. This enables 2FA and allows vendors to encrypt shipping data. Accounts without PGP keys are purged after 7 days of inactivity.
Two-Factor Authentication (2FA) via PGP is the gold standard for account security. When enabled, the login page presents an encrypted challenge message. You must decrypt this message using your private key to reveal the verification code. This prevents access even if your password is compromised.
1. Use Tails OS or Whonix.
2. Never reuse usernames from other platforms.
3. Strip metadata (EXIF) from any images uploaded.
4. Encrypt all shipping addresses locally before pasting into the order form.
5. Never discuss market activity on clearweb platforms (Reddit, Discord).
2. Never reuse usernames from other platforms.
3. Strip metadata (EXIF) from any images uploaded.
4. Encrypt all shipping addresses locally before pasting into the order form.
5. Never discuss market activity on clearweb platforms (Reddit, Discord).
Financial Operations
Bitcoin is a transparent ledger; every transaction is traceable. Monero uses Ring Signatures, Stealth Addresses, and RingCT to obfuscate sender, receiver, and transaction amount. We refuse to compromise user safety by accepting transparent surveillance coins.
1. Buyer deposits XMR into a unique order address.
2. Market holds funds; Vendor is notified to ship.
3. Buyer receives goods and clicks 'Finalize'.
4. Funds are released to Vendor.
5. Auto-finalization occurs after 14 days if no dispute is raised.
2. Market holds funds; Vendor is notified to ship.
3. Buyer receives goods and clicks 'Finalize'.
4. Funds are released to Vendor.
5. Auto-finalization occurs after 14 days if no dispute is raised.
To prevent scamming, new vendors must pay a non-refundable bond of 2.00 XMR. This establishes commitment. Established vendors with verifiable history on other markets (Recon/Dread verified) may apply for a waiver via the support ticket system.
If an order does not arrive, the buyer can open a dispute. This freezes the auto-finalize timer. A moderator will review the trade chat logs and vendor history. Decisions are final. Note: FE (Finalize Early) orders are not protected by escrow.
Verified Mirrors
[ONLINE]
xibpmlaex4uwsw3oifqfs25lvzcpffb7rrwm6c4tvzhmfx472r.onion
[ONLINE]
cl5vrr5tuwanwhnsr62z62u72k7fwohwtyqmthhyfboornjfyu.onion
[ONLINE]
3srb5xvlwshubkmzzbvh4im3ey5pz5aacrkn6stu7o3frsn5j7.onion
[ONLINE]
num7jkqwveqp2ubbyuvxo26udiu3tefymrizru7dkv5mdmayo6x22pyd.onion
OpSec Protocol
! Never share your private PGP key.
! Disable JavaScript in Tor Browser.
! Use a clean OS (Tails/Whonix).
! Verify every link you click.
Term Glossary
- FE (Finalize Early)
- Funds released to vendor before delivery. High risk - for trusted vendors only.
- PGP 2FA
- Two-Factor Authentication using public/private key encryption.
- DDoS
- Distributed Denial of Service. Common attack causing site slowness.
Still need help?
If your issue is not resolved, open a ticket. Encrypt sensitive data.
Contact Support