Staying Safe on Anubis Market

The safety of a darknet market visit comes from your habits, not from the platform. Six habits, two minutes total, and they stop the things that actually take accounts. This page is the list, the reason each one matters, and the moments when the habits are skipped.

The six habits

2 minutes
  1. One Tor Browser profile, used only for the market

    Download Tor Browser from the official Tor Project, verify the signature, and set the security level to Safest. Use that browser exclusively while you are logged in. Browser extensions, sister tabs to clearnet sites, and developer-tools sessions all leak in ways the marketplace cannot help you with. A separate profile means the market session does not share cookies or history with your normal browsing.

  2. A fresh username you have not used anywhere else

    Do not reuse a username across markets. If a username appears on two markets and one of them is compromised, the other is exposed. A fresh username per market is the baseline, and it costs nothing.

  3. Check the address before you type a password

    Hold the address in your bar against the one the login screen prints. They must match before you enter anything. This is the one check that stops a clone, and it takes ten seconds. The full method is on the verify address page.

  4. Encrypt the shipping address to the vendor key

    At checkout, the shipping details are encrypted to the vendor's PGP key. Use client-side encryption if you can, because your plaintext never leaves your device. The server-side tool is a fallback, not a default. The trade-off is on the review page.

  5. Route the coins through a personal wallet before depositing

    Do not send from an exchange account that has your name on it. Move the coins to a personal wallet first, then deposit from there. The deposit address is fresh per order, which limits the damage, but the coin you pick decides the record. Monero keeps it off the public ledger. The detail is on the coins page.

  6. Clear the cookie jar at the end of the session

    Close the Tor Browser profile when you are done. Do not leave it open overnight with a logged-in session. A logged-in session on a machine that gets used for other things is a session that can be read, and the profile is the one to close.

When the habits are skipped

The accounts that get taken are not the ones that skipped a rare, exotic habit. They are the ones that skipped the address check because they were in a hurry, or the ones that reused a username because it was easier, or the ones that searched for the mirror during an outage and landed on a clone built for that exact moment. The phishing page covers the specific moments a clone surfaces.

What the market cannot protect you from

The market cannot protect you from a browser extension that leaks, a username reused on another market, or a coin choice that leaves a public record. Those are decisions you make outside the market, and they are the ones that matter. The escrow protects the order. The habits protect the account. The coin protects the record. All three are needed, and none of them is the market's job.

After a session

Close the Tor Browser profile. Do not leave a logged-in session open on a machine that gets used for other things. If you use the machine for normal browsing, the market profile is the one that should be closed, not the normal one.

The two-minute version

One Tor Browser profile. A fresh username. Check the address before you type. Encrypt the shipping details. Route the coins through a personal wallet. Close the profile when you are done. That is the two-minute version, and it stops the things that actually take accounts.