Warning — Active Phishing Campaign Against Nexus Users
Community security researchers issued a warning in late September 2025 regarding an active phishing campaign targeting Nexus Marketplace users. Multiple fake onion addresses appeared in circulation across clearnet forums and Telegram channels.
How the Nexus Onion Phishing Campaign Operated
Attackers created visually identical replicas of the Nexus Marketplace interface at different .onion addresses. These fakes were distributed through posts on Reddit, Dread, and Telegram groups using accounts with established histories to appear trustworthy.
The fake sites captured login credentials on the first visit and silently relayed sessions to the real marketplace in some cases — preventing immediate detection by appearing to function normally.
How Users Were Affected
Victims who logged in on phishing sites had credentials compromised. Subsequent logins to the real Nexus Darknet using the stolen credentials resulted in account takeovers and loss of deposited cryptocurrency.
Verification is the Only Protection
The attack was sophisticated — visual inspection of the site alone could not detect the fake. The only reliable defences are:
- Using only bookmarked addresses saved from verified sessions
- Verifying the PGP signature on market announcements before using a new address
- Never following links from any external source
- Checking the full 56-character onion address character-by-character against a known trusted reference
Verified Nexus onion addresses are listed on the Enter page of this resource. The anti-phishing guide covers complete verification procedures. Confirmed losses from this campaign ran into hundreds of thousands in cryptocurrency value based on community reports.
Published: September 23, 2025 | Category: Darknet Research | ← Return to Chronicle