nexuscheckVerification checklists for Nexus Market, with pass criteria
18 checks across 5 moments
3 verified addresses
Overview Full checklist First time setup Every session Before funding On delivery Periodic review Addresses FAQ Scope

Checks > Every session > C-07

C-07: Login screen address matches the browser address bar

IdentifierC-07
Weightcritical
AppliedEvery session (M2), Each time you sign in
StatementThe onion address printed on the login screen is identical to the address shown by your browser, checked before anything was typed.
Grading criteria
PASSCompared in full and identical.
PARTIALCompared but only the first and last few characters.
FAILNot compared, or compared and different.
COSTThis is the check that separates the market from a copy of it. Failing it is how nearly every credential loss around markets happens.

The observation this rests on

Everything visible about a page can be copied, because it is served to whoever requests it. The stylesheet, the images, the wording, the captcha design. What cannot be copied is the address the page actually lives at, because that is reported by your browser rather than by the page.

Why a copy cannot pass

A clone has to be reachable somewhere, and that somewhere is what your address bar displays. It can print the genuine address on the page to reassure you, in which case the page contradicts the bar. It can print its own, in which case the mismatch is obvious. There is no configuration where a copy sits at its own address, shows the real one, and stays consistent.

Where the address appears

Nexus prints its onion inside the anti-phishing image on the login screen and again in the page header. Both are checked against the bar. The image matters because it is harder to alter dynamically than page text.

Why partial comparison is graded down

Checking the first six characters and the last four feels thorough and is not. Prefix generation is cheap, and clone addresses are produced specifically so the opening matches. The comparison has to cover the whole string, which is why copying rather than typing matters upstream of this item.

Required action on failure

  1. Close the tab without entering anything
  2. Do not reuse the history entry that led there
  3. Start again from a source held before the session
  4. If credentials were already typed, treat them as compromised and change them from a verified address

Frequency

Every session. A check performed only on a first visit is not a control, because the case it defends against is precisely the session where you arrived by an unfamiliar route.

Verified address set

Verified address set
[1]nexusb2l7fmqnefwphyy7m5zjhlkytlbo7qbb5lu5dlczr3azgii2gyd.onion
[2]nexusma2iqgauqqvjcgds4ckv5xbf272tkfagq4epojjhsgleqpwxiqd.onion
[3]nexusabcd6tyfhdwilyitaqiri6tisj2v2hueyjuj6qkvd6azvi5tuqd.onion

Run C-07 before you type anything. Open in Tor Browser only, then compare the onion printed on the login screen against your browser address bar. A mismatch means the page is a copy and the tab should be closed.

Other checks in this group

C-06high
Applies: Every session (M2)
Passes when: Copied and pasted from a source held before this session.
The address you opened was copied from a saved source rather than typed, retyped or corrected from memory.
C-08critical
Applies: Every session (M2)
Passes when: Only username, password and the two factor challenge were requested.
Nothing during sign in requested your recovery phrase, seed words or private key.
C-09high
Applies: Every session (M2)
Passes when: Bookmark or saved note held in advance.
The address you used came from a source you already held before this session began, rather than one located during it.