Three Nexus addresses, published as supplied. No labels, no ranking, no claim any of them opens right now.

Address typos are landing Nexus readers on lookalike sites

over the past quarter ยท readers

Typo-squat onions targeting Nexus are now close enough to the real ones that a single misread character lands the reader on a working lookalike, not a broken page.

How it read before

For a long time, a typo in a Nexus onion mostly gave you a failed load. The character space is wide and the odds of any given wrong string being registered were low. A reader who mistyped saw a "connection failed" screen and knew to try again. The failure was doing useful work: it was telling them their address was wrong.

The typo squats that did exist were noticeably different from the real onion. The differences were not just in the string; the pages themselves looked off. A missing font. A stretched banner. A login form that behaved wrong. The reader felt the wrongness before they typed anything.

How it reads now

Squat onions have got closer. There are more of them, they are registered at more of the near-neighbour strings around the real address, and the pages they serve are near-clones of the market front end. A single character swap or a dropped character now often takes the reader not to a failure page but to a working-looking market that will accept a login attempt and hand it to whoever is running the squat.

The visible difference between the real and the squat is now small. Sometimes it is only a missing signal. The checkout address confirmation is absent. The PGP key in the listing header is missing or corrupted. The PGP signed invoice block does not render. To a reader who is not looking for those exact signals, the squat feels like the real market.

The squats that are worth worrying about also do not try to sell anything. They collect. A login. A deposit address. A vendor PGP key that the reader typed by hand. Whatever comes in stays. The reader who has typed once will often not realise until the credentials show up being used somewhere they did not expect them.

Why this probably shifted

A few things are pulling in the same direction. Cloning the front end has got easier because most of what the front end does is static HTML that can be lifted with a single scrape. The vanity-onion pipeline is cheaper than it was, so registering a near-neighbour of a target string is less painful. And more readers now arrive by typing the address from memory or from a printed source, so the population of typos entering the market space is larger.

The result is that the failure that used to catch typos is no longer catching them. A wrong string used to be its own alarm. Now the wrong string returns a working page, and the alarm has to come from somewhere else, which usually means the reader.

What to change on your side

Stop typing from memory, and start using the reference every visit.

  • Open the addresses reference in a second tab and copy from there. Do not type.
  • When you paste, look at both ends of the pasted string. Typos and squats both often target the middle where readers do not look. Reading the first and last three characters of the onion is a fast and reliable check.
  • If you have to type, type slowly and read the address back one character at a time. A slow read finds swaps that a fast read misses.
  • Do not save Nexus addresses in browser bookmarks that autocomplete. An autocomplete of an old typo is worse than a fresh look at the reference.

What this entry is not claiming

The entry does not claim that every failure to load is a squat. Most connection failures are still just the network. The entry also does not claim any particular alternate address is a squat; the reference page carries the list. It only names the shift, which is that a typo now lands you on a working-looking page more often than it used to, so the reader has to do the alarm work that the failure page used to do for them.