Anubis Market Phishing

Clone pages are the main way accounts get drained, and they appear every few weeks. We track them, close them when we can, and publish what we learn here. The good news is that almost every clone follows the same script, which means they are easy to spot once you know the pattern.

These are the only addresses that belong to the market. Anything else is a copy.

  • anubisq6kqiq5ttmrrnj3pyxssmnaxurl76flaegbtzbcwtes3vomiid.onion
  • anubisqdpukalgiyxlb7rtcya3u6grun2mcozonmb57c54qrt7sqh7qd.onion
  • anubisqe2yramasw5yvlnipaknraza5rzb5uxb7zqhxuxroobvvm6aid.onion

All three addresses open the same market with the same account and balance. Checked .

How the clones are built

A clone starts with a screenshot of the real login page. The builder reproduces the layout pixel for pixel, usually pulling the same fonts and colors, and swaps the address for one that looks almost identical. One or two characters differ, often buried in the middle of the string where the eye skips. On a phone screen the difference is nearly invisible.

Distribution is the second half of the job. Clones spread through Telegram channels, pinned Discord messages, X and Twitter bots, and forum comments under recent threads. The message always carries urgency: verify your account within twenty-four hours, your balance needs migration, a new security layer requires a one-time check. Urgency is the product. If you act fast, you never compare the address character by character.

Some clones go further and load the real market through a proxy, so the page behaves exactly like the original. Even then, the address in your browser bar is not ours, and the session you open belongs to whoever runs the proxy.

Red flags

  • The address in the browser bar does not match, character for character, one of the three addresses on this page. Check the tail of the string first; that is where typos hide.
  • The page asks for a private key, a seed phrase, or a code you were not asked to generate.
  • An unexpected bonus, airdrop, or account upgrade offer appears on a page you did not request.
  • The favicon or logo looks slightly off in size or color.
  • A countdown timer or a limited time banner pushes you to decide now.
  • The page asks for an email address or a phone number. The market does not collect either.
  • No PGP-signed announcement explains the change, and the signature on the message does not match our key.

If two or more of these appear, close the tab. You do not owe the page a second look.

If you already entered your password

Work in this order, and do not skip steps:

  1. Log out of the suspicious page or close the tab completely.
  2. Open the market from one of the verified addresses above and change your password.
  3. Check your balance and your open orders. Note anything that is not yours.
  4. If coins moved to an address you did not create, write to support via PGP with the order IDs and the timestamps. The key is on the PGP page.
  5. Funds sitting in escrow for open orders are covered by the dispute panel, so a clone stealing your login does not automatically steal those coins.
  6. Move whatever remains to a fresh wallet address and keep the old one empty.

Most losses happen in the first hour after a takeover, when the attacker moves coins before the owner notices. The faster you complete steps one and two, the more of your balance survives.

The one rule

Addresses come only from this page, and announcements are trusted only when they carry a signature that verifies against our public key. Everything else is a rumor until proven otherwise. When in doubt, close the tab and come back later; the market will still be here, and your account will still be yours. If the page you need will not load at all, the order of checks is in Anubis Market down.