The clones, how they look, and how to catch them
Why there are so many clones
The market is young. It launched in January 2025. It is drug-focused, which means the people looking for it are looking hard. And it sits behind Tor, so the only way most of those people find it is through search engines and chat channels.
That is exactly where clones are planted.
Every "working link" post is a business opportunity for someone who runs a lookalike. You do not need to be clever to find the market. You need to be the person who posted the link. The clones are not an accident of the market being hard to find. They are the business model of the people who made it hard to find on purpose.
What a clone copies
The UI. The purple planet. The login form. The exchange rate widget. The welcome text. Sometimes the gate, the black card with the red monospace text, down to the layout.
A clone built from a good screenshot is indistinguishable from the real market by design. That is the point of cloning. If you can tell them apart by looking, the phisher is doing it wrong. You are not supposed to tell them apart by looking. You are supposed to tell them apart by checking.
What a clone cannot copy
Three things, and they are the whole game.
- The address itself. A clone lives at its own onion. Your address bar holds the clone's string, not the market's. This is the one that beats 90% of phishers, because it requires nothing but looking up.
- The PGP signature. The operator's key signs the real set. The phisher does not hold the key, so he cannot produce a signature that verifies against the real fingerprint. He can paste a signature that looks right. He cannot make it verify.
- The gate check. The gate prints your address bar string back at you, with six characters masked. On the real market, the masked string matches what is in your address bar. On a clone, it prints the clone's string, and if you actually read the characters it shows you instead of just hitting the ones you expect, you will see the mismatch.
The patterns
- Prefix-only match. The first several characters are identical, the tail is random. The
marsstart is the bait. - An extra or missing character in the middle of a 56-character string. The copy-paste killer. You copy it, you paste it, you log in, and the address is one character off. Nobody reads 56 characters by eye. That is why it works.
- A clearnet domain that "opens the market for you." That domain sees your traffic. You are not using Tor at that point. You are visiting a website that happens to look like a mirror page.
- Links pasted in chats and forum replies without a signature. The person who pasted it may be the phisher, or the phisher's bot, or a victim who did not check.
- "Official mirror" Telegram channels. Read that again. Official. The market is behind Tor. It does not run an official Telegram channel that hands out mirrors.
The checks, in order
- Address bar. Starts with
mars. 56 characters before.onion. Last six match what you copied. - Gate. The printed string matches your address bar.
- PGP. The signed list, full chain, as on verify.html.
Any one of the three failing means stop. Not "be careful." Stop. Close the tab.
If you already deposited on a page you now think is a clone
Do not log in there again. Do not top up to "test it." The more you touch a page you suspect, the more surface area you give it.
Note the address you used. Then wait for the real set to load, get to a verified address, and check the account there. The money question is a transaction-chain question, not a feelings question. If the deposit shows up on your account at the real address, the money moved to the right place and the page was a mirror you misjudged. If it does not show up, you have a different problem, and you want to know that from the balance, not from the clone's "order history" page.
Is Mars Market a scam
A market that launched in January 2025 has a short public track record. That is a fact, and it is the fair version of the worry.
The clones are real. The market is real. The two keep getting confused in search results, and the confusion is not your fault. Search engines do not know Tor, and the people who post links in the comments do not always know the difference either.
The way out is the checks, not trust. You do not have to decide whether the market is a scam. You have to decide whether the address in your address bar is the one in the signed list. Those are different questions, and only the second one is answerable.