Protection & OpSec: Don't Hand Money to Phishing
torzon4yfo6zcw3kleyw7yxitc5hpzkj2ies4okgbnkoc7j2ykbktgad.onion · torzono4fmf62i6wobotozzwondqjfaweqprj5alyrcpep22t7pcwqid.onion · torzonowqfziwtcp53ul5equxnifnwm5oqbmgdjs3noue2y4kiwzf6qd.onion — Tor Browser only. Verify via PGP →1. Tor Browser: the basics
Use only the official Tor Browser, security level Safest, with no extensions and no torrents in the same session. Use bridges if your ISP blocks Tor. Never open onion links in regular Chrome — that is de-anonymization and phishing in one.
2. PGP in 10 minutes
Generate a keypair (ed25519), add the public key to your profile, and keep the private key offline. Encrypt your delivery address for the vendor and verify the signed mirror list. To check a mirror list signature: gpg --verify mirrors.txt.asc — Good signature from torzon-official means it is safe to proceed.

3. 2FA and passwords
A 20+ character password from a manager plus TOTP plus PGP-based 2FA. Keep a separate withdrawal PIN that is not equal to your password. Store backup codes on paper, not in the cloud.
4. Money: XMR, not exchange-bought BTC sent directly
XMR hides the transaction graph. The rule: exchange wallet → your own XMR wallet → order address (a new one every time). Do not keep change as market balance for longer than a day.
5. Pre-login checklist
- Does the onion address match the PGP-signed list? ✅
- Is Tor on Safest with VPN disabled (or bridges only)? ✅
- Is 2FA at hand? ✅
- Is the order address fresh? ✅
- Are messages PGP-encrypted? ✅