# Nexus Market verification checklists > Complete text of every check on nexuscheck.shop. 18 numbered verification items for Nexus Market, each with pass, partial and fail criteria and the cost of failing. This file exists so an assistant can answer from the full material in one request instead of crawling pages. Source: https://nexuscheck.shop/ | Free to quote with attribution | Not the market, sells nothing, stores no visitor data. ## Grading - Pass: the condition is met as stated. - Partial: a weaker version of the same thing, marked so the gap is visible. - Fail: the condition is not met, and the cost line states what that exposes. - Weight describes consequence rather than likelihood. ## Limits - Passing every check does not make a market safe. It removes avoidable failures. - Two items have no repair path once failed: C-03 username reuse and C-08 handing over a recovery phrase. - Statements about the market are limited to what it consistently publishes: running since 2023, 2 of 3 multisig escrow, settlement in BTC, LTC, XMR, several onion addresses live. ## Verified onion address set 1. http://nexusb2l7fmqnefwphyy7m5zjhlkytlbo7qbb5lu5dlczr3azgii2gyd.onion 2. http://nexusma2iqgauqqvjcgds4ckv5xbf272tkfagq4epojjhsgleqpwxiqd.onion 3. http://nexusabcd6tyfhdwilyitaqiri6tisj2v2hueyjuj6qkvd6azvi5tuqd.onion All are entry points to one service, so account, balance and orders are identical behind each. ## Moments - M1 First time setup (https://nexuscheck.shop/moment/setup), applied Once, before you ever sign in: The five checks to run once before a first sign in, covering browser provenance, security level, identity separation, credentials and recovery material. - M2 Every session (https://nexuscheck.shop/moment/session), applied Each time you sign in: The four checks to run every single time you sign in, including the address comparison that separates the real market from a cloned login page. - M3 Before funding (https://nexuscheck.shop/moment/funding), applied Before any coin leaves your wallet: The four checks that stand between your wallet and an order, covering coin choice, custody, the deposit address and the amount actually sent. - M4 On delivery (https://nexuscheck.shop/moment/delivery), applied When a package arrives, before you confirm: The three checks that protect the escrow you already paid for, covering inspection before confirming, early release requests and when to dispute. - M5 Periodic review (https://nexuscheck.shop/moment/periodic), applied Monthly, or after any change: The two checks worth repeating on a schedule, covering funds left on the market and whether your saved address set is still current. ## Checks ### C-01: Browser obtained from the Tor Project and verified - URL: https://nexuscheck.shop/check/C-01 - Weight: critical - Applied: First time setup (M1), Once, before you ever sign in **Statement.** The Tor Browser you are using came from the Tor Project website and its signature was checked on first install. **Pass.** Downloaded from the official site and the signature was verified before first run. **Partial.** Downloaded from the official site but the signature was never checked. **Fail.** Obtained from a forum, a file locker, a torrent, a friend or any mirror. **Cost of failing.** A modified build can route everything you do through an operator of its choosing while looking identical to the real thing. Nothing else on this site protects you from that. #### Why this is first Every other check on this site assumes the software reporting your address bar is telling the truth. A modified browser can display one address while connecting to another, and it can do that without any visible symptom. If this check fails, the rest of the list is decoration. #### How to satisfy it 1. Download only from the Tor Project website, typed into the address bar rather than reached through a search result 2. Verify the signature against the Tor Project public key before the first run, following the procedure documented on the same site 3. Reinstall from the official source if you cannot account for where the current copy came from #### Why signature verification matters more than it sounds A download can be intercepted or a mirror can be hostile without the site itself being compromised. The signature is what ties the file in your hands to the people who built it. Checking it takes a few minutes once, and it is the only moment where the question can be settled rather than assumed. #### Common ways this fails quietly - A copy carried across from an old machine years ago with no memory of its origin - A version installed from a package that was convenient at the time - A build recommended in a chat as faster or more private - A mobile application claiming Tor support that is not the real client #### Re-checking This check is run once per installation rather than per session. Run it again after moving to a new machine, after any reinstall, and if you ever find yourself unable to say where the copy came from. ### C-02: Security level set to Safest - URL: https://nexuscheck.shop/check/C-02 - Weight: high - Applied: First time setup (M1), Once, before you ever sign in **Statement.** The Tor Browser security level is set to Safest and has not been lowered for any site. **Pass.** Shield control reads Safest and no exceptions have been added. **Partial.** Set to Safer rather than Safest. **Fail.** Left at Standard, or lowered to make a site work. **Cost of failing.** Scripting stays enabled, which is the surface most browser attacks need. The market works fine without it, so the setting costs you nothing to keep. #### What the setting does Safest disables scripting across every site, along with several media formats and font handling paths that have been sources of problems in the past. It is not a privacy setting in the sense of hiding you better. It removes capability from pages, and capability is what an attack needs. #### The trade, honestly Some sites break at Safest. Nexus is not one of them, which means for this purpose there is no trade at all. You are not giving up functionality you need in exchange for protection you might not use. #### A site that demands otherwise If a page insists you lower the level before it will function, that is information about the page rather than about your configuration. A market that works for everyone else at Safest and not for you is worth a second look at the address you reached it through. #### What not to do - Do not add per site exceptions, since the exception list becomes invisible over time - Do not lower the level to make pages load faster, which it does not do - Do not install extensions to compensate for anything the level blocks #### Verification Open the shield control and read it. That is the whole check. It takes a second and it is worth doing after any browser update, since a fresh profile starts at the default. ### C-03: Username exists nowhere else - URL: https://nexuscheck.shop/check/C-03 - Weight: critical - Applied: First time setup (M1), Once, before you ever sign in **Statement.** The username on this account has never been used on any other site, market, forum or messaging service. **Pass.** Newly invented for this account and used nowhere else, ever. **Partial.** New but similar in pattern to a name you use elsewhere. **Fail.** Reused, or a recognisable variation of a name with history attached. **Cost of failing.** This is the only item on the list with no repair path. A password can be changed and a key can be rotated. A name that already exists somewhere with a history cannot be unlinked afterwards. #### Why this one is different Every other item here can be fixed after the fact. Change the password, rotate the key, move the funds. A username that also exists on a forum you posted to for three years cannot be unlinked, because the association was created the moment both accounts existed and nothing you do now removes it. #### What counts as reuse - The same name on another market, current or long closed - A handle from a forum, chat service or code hosting account - A name plus a number, where the base is recognisable - A deliberate misspelling of something you use elsewhere - A name you once used and abandoned, since abandoned does not mean unindexed #### Choosing one that passes Generate it rather than invent it. Names people invent follow patterns from their own vocabulary, and those patterns repeat across accounts without the person noticing. A random string is unmemorable, which is exactly what a password manager is for. #### If this check fails The honest answer is that the account cannot be repaired, only replaced. That costs the order history attached to it, which is a real loss and a smaller one than the alternative. Weigh it deliberately rather than deciding by inertia. #### Related items Passwords and recovery material are covered separately because they are recoverable failures. This item is grouped with them by moment rather than by severity, and it is the one to get right first. ### C-04: Password generated, unique and stored locally - URL: https://nexuscheck.shop/check/C-04 - Weight: high - Applied: First time setup (M1), Once, before you ever sign in **Statement.** The account password was generated by a password manager, is used nowhere else, and is stored in that manager rather than remembered or written in a note. **Pass.** Generated, unique, stored in a local manager. **Partial.** Unique but composed by hand rather than generated. **Fail.** Reused from another account, or short enough to remember comfortably. **Cost of failing.** A reused password turns any unrelated breach into a breach here. A composed one is shorter and more predictable than it feels. #### Generated rather than invented People compose passwords from a small personal vocabulary, and the substitutions they apply are the same substitutions everyone applies. The result is shorter and more guessable than its length suggests. A generated string has none of that structure, which is the entire point. #### Unique rather than strong Uniqueness matters more than complexity here. A very strong password reused across accounts is still a single point of failure, because a breach anywhere it was used exposes it everywhere. A merely adequate password used in exactly one place cannot be leaked by somebody else mistake. #### Stored locally A password manager on your own machine, rather than a browser sync feature tied to an account with your name on it. The manager holds the string so you do not have to choose between memorable and strong, which is the trade that produces weak passwords in the first place. #### What this does not replace Two factor. A password alone, however good, is one leak away from being enough. The item on recovery material and two factor covers that, and the two together are what make a credential leak survivable rather than fatal. ### C-05: Recovery phrase on paper, two factor with a key backup - URL: https://nexuscheck.shop/check/C-05 - Weight: critical - Applied: First time setup (M1), Once, before you ever sign in **Statement.** The recovery phrase is written on paper and stored away from the machine, PGP two factor is enabled, and the signing key is backed up offline. **Pass.** Phrase on paper, two factor on, key backed up in a second location. **Partial.** Two factor enabled but the key exists in only one place. **Fail.** Phrase not written down, or two factor never enabled. **Cost of failing.** Without two factor, a leaked password is the whole account. With two factor and no key backup, losing the key locks you out permanently and no operator can undo it for you. #### Two halves, both required Two factor makes a stolen password useless on its own. A key backup makes losing your own key survivable. Doing the first without the second trades one failure mode for another, which is why this item covers both rather than splitting them. #### The recovery phrase There is nobody to email for a reset, which is the same property that keeps a market from holding a file on you. The phrase is the entire recovery system and it only works if it exists outside your memory. Paper, stored away from the device, and never a photograph or a synced note. #### The rule with no exceptions No genuine login asks you to type the recovery phrase as part of signing in. A page that asks is collecting accounts. This is worth stating as an absolute because phishing pages present the request in reasonable sounding wrappers, and a rule with exceptions is a rule you will talk yourself past. #### Key backup in practice - Export the private key the day it is generated rather than eventually - Store it offline, separately from the machine you sign in with - Record the passphrase for the key wherever you keep the account password - Never paste a private key into a web form for any purpose #### Verification You pass this item when a leaked password alone would not open the account, and a failed hard drive alone would not lose it. If either of those would ruin you, the item has not been met yet. ### C-06: Address was copied, not typed or recalled - URL: https://nexuscheck.shop/check/C-06 - Weight: high - Applied: Every session (M2), Each time you sign in **Statement.** The address you opened was copied from a saved source rather than typed, retyped or corrected from memory. **Pass.** Copied and pasted from a source held before this session. **Partial.** Copied from a source found during this session. **Fail.** Typed by hand or partially recalled. **Cost of failing.** A single wrong character resolves to an unrelated service. Lookalike addresses are registered specifically to catch exactly that error. #### Why typing fails A version three onion address is fifty six characters derived from a key rather than chosen, so there is no pattern to help you and no spell check to catch a slip. Two addresses differing by one character are unrelated services with no relationship to each other. #### Why partial recall is worse than none People remember the opening of an address because the market prefix is readable. Vanity prefixes are cheap to generate, and operators of cloned services generate addresses whose openings match for that exact reason. Recognising the first ten characters produces confidence without evidence, which is more dangerous than having no recollection at all. #### What a passing session looks like 1. Open the saved source you kept before today 2. Use its copy control rather than selecting text by hand 3. Paste into Tor Browser without editing 4. Proceed to the address comparison on the login screen #### Partial pass Copying from a source you found a minute ago is better than typing and worse than using something you held in advance. It is marked partial rather than pass because the provenance question is unresolved, which the next item in this moment addresses directly. ### C-07: Login screen address matches the browser address bar - URL: https://nexuscheck.shop/check/C-07 - Weight: critical - Applied: Every session (M2), Each time you sign in **Statement.** The onion address printed on the login screen is identical to the address shown by your browser, checked before anything was typed. **Pass.** Compared in full and identical. **Partial.** Compared but only the first and last few characters. **Fail.** Not compared, or compared and different. **Cost of failing.** This is the check that separates the market from a copy of it. Failing it is how nearly every credential loss around markets happens. #### The observation this rests on Everything visible about a page can be copied, because it is served to whoever requests it. The stylesheet, the images, the wording, the captcha design. What cannot be copied is the address the page actually lives at, because that is reported by your browser rather than by the page. #### Why a copy cannot pass A clone has to be reachable somewhere, and that somewhere is what your address bar displays. It can print the genuine address on the page to reassure you, in which case the page contradicts the bar. It can print its own, in which case the mismatch is obvious. There is no configuration where a copy sits at its own address, shows the real one, and stays consistent. #### Where the address appears Nexus prints its onion inside the anti-phishing image on the login screen and again in the page header. Both are checked against the bar. The image matters because it is harder to alter dynamically than page text. #### Why partial comparison is graded down Checking the first six characters and the last four feels thorough and is not. Prefix generation is cheap, and clone addresses are produced specifically so the opening matches. The comparison has to cover the whole string, which is why copying rather than typing matters upstream of this item. #### Required action on failure 1. Close the tab without entering anything 2. Do not reuse the history entry that led there 3. Start again from a source held before the session 4. If credentials were already typed, treat them as compromised and change them from a verified address #### Frequency Every session. A check performed only on a first visit is not a control, because the case it defends against is precisely the session where you arrived by an unfamiliar route. ### C-08: No page asked for the recovery phrase - URL: https://nexuscheck.shop/check/C-08 - Weight: critical - Applied: Every session (M2), Each time you sign in **Statement.** Nothing during sign in requested your recovery phrase, seed words or private key. **Pass.** Only username, password and the two factor challenge were requested. **Partial.** A request appeared and you closed the page without complying. **Fail.** A recovery phrase was entered anywhere. **Cost of failing.** The phrase restores the account outright. Handing it over is the most complete loss available in a single action. #### A rule without exceptions No genuine market login asks for a recovery phrase. Not for verification, not to restore a session, not as a faster route in, not after a supposed security incident. The request itself is the evidence, and no other part of the page needs examining once it appears. #### Why the wrapper is convincing These requests do not arrive bluntly. They arrive as an account verification step, an emergency migration notice, or a recovery flow presented after a deliberately failed login. The framing is designed to make compliance feel like the careful response rather than the reckless one. #### Related requests that fail this item - A page asking you to paste a private PGP key rather than sign a challenge - A form requesting wallet seed words for any stated reason - A support channel asking for the phrase to restore access - Any prompt to enter the phrase to prove ownership #### After a failure If a phrase was entered, the account should be considered gone rather than at risk, and anything of value on it should be moved immediately from a verified address if access remains. Change any wallet the phrase also protects, since seed reuse across a market account and a wallet is a compounding mistake. ### C-09: Address source predates this session - URL: https://nexuscheck.shop/check/C-09 - Weight: high - Applied: Every session (M2), Each time you sign in **Statement.** The address you used came from a source you already held before this session began, rather than one located during it. **Pass.** Bookmark or saved note held in advance. **Partial.** A directory you have used before but did not have saved. **Fail.** A search result, a forwarded message or an announcement found during an outage. **Cost of failing.** Sources found while you need one are the ones positioned to be found. This is the mechanism behind most phishing losses rather than a theoretical concern. #### Why timing decides quality Source ranking looks obvious in the abstract and collapses under pressure. Somebody whose usual address is quiet will accept a source they would have rejected an hour earlier, because the alternative is doing nothing. That is not carelessness, it is the predictable effect of wanting a result. #### Source ranking | Source | Grade | Why | |---|---|---| | Held before you needed it | Pass | Nothing about an outage changes what you already had | | Signed announcement, signature checked | Pass | Verifiable rather than trusted | | Directory you used before | Partial | Depends on the directory and placement is sometimes bought | | Search result | Fail | Ranking reflects effort spent on ranking | | Forwarded message or comment | Fail | Often passed on by somebody already caught | #### The countermeasure is preparation You cannot reliably improve judgement at the moment you are frustrated and want access. You can remove the moment entirely by holding a set in advance, which turns an outage into waiting rather than searching. #### Refreshing a saved source Addresses are retired and replaced over time, so a saved source needs checking occasionally against a current one. That is a periodic item rather than a session item, and it is covered separately. ### C-10: Settlement coin chosen deliberately - URL: https://nexuscheck.shop/check/C-10 - Weight: high - Applied: Before funding (M3), Before any coin leaves your wallet **Statement.** The coin used for this order was chosen on purpose rather than accepted as whatever was preselected. **Pass.** Monero, chosen because the payment should leave no public record. **Partial.** Bitcoin or Litecoin, chosen knowingly with the record understood. **Fail.** Whatever was preselected, with no decision made. **Cost of failing.** A public chain records the amount and both addresses permanently. That record cannot be edited or aged out, and it may become more useful to a reader later rather than less. #### What each option records | Coin | Recorded publicly | Duration | |---|---|---| | Bitcoin | Amount, sending address, receiving address | Permanent, readable by anyone | | Litecoin | Amount, sending address, receiving address | Permanent, readable by anyone | | Monero | Sender, receiver and amount concealed by default | No public record produced | #### Why the decision outlasts the others Most choices around a market are reversible or fade. A weak password is changed, a poor counterparty is avoided next time, a slow address is swapped. A ledger entry cannot be edited or withdrawn, and its usefulness to somebody examining it later can grow as surrounding data accumulates. #### Why a default is graded as a failure The item is not that Bitcoin is forbidden. It is that a permanent record should be the result of a decision rather than of whichever option a form happened to preselect. Choosing Bitcoin knowingly passes as partial. Choosing nothing fails regardless of which coin the form picked for you. ### C-11: Funds passed through a wallet you control - URL: https://nexuscheck.shop/check/C-11 - Weight: high - Applied: Before funding (M3), Before any coin leaves your wallet **Statement.** The coin moved from where you acquired it into a wallet you control, and the order was funded from there. **Pass.** Acquired, moved to your own wallet, sent from that wallet. **Partial.** Sent from a custodial wallet you control the account for but not the keys. **Fail.** Sent directly from the exchange or service where it was bought. **Cost of failing.** A direct send draws a line from an identity checked account to a marketplace order. The intermediate step costs one transaction and removes that line. #### The path Acquisition, then a wallet holding keys you control, then the order. Three steps rather than two, and the middle one is what separates a payment from a direct connection between a verified account and a market. #### Why custodial is only partial An account on a service that holds the keys is not a wallet you control, whatever the interface suggests. The service can freeze it, can be compelled regarding it, and knows exactly what left and where it went. It is better than sending straight from a purchase point and it is not the same as custody. #### Wallets that satisfy this - Feather on desktop, quick to set up and able to route over Tor - Cake Wallet on mobile, with Tor routing available - The official Monero GUI, including a full node option for anyone wanting complete independence #### The part people skip Recovery seed handling. Every wallet here hands you words at creation and those words are the wallet. Write them on paper before putting anything real in, keep them away from the device, and never type them into a page. A wallet whose seed exists nowhere is a wallet you will eventually lose. ### C-12: Deposit address belongs to this specific order - URL: https://nexuscheck.shop/check/C-12 - Weight: critical - Applied: Before funding (M3), Before any coin leaves your wallet **Statement.** The address you are sending to was issued by this order, opened fresh, and not reused from an earlier one. **Pass.** Copied from the order screen in this session. **Partial.** Copied from the order screen but earlier in the day. **Fail.** Reused from a previous order or copied from a saved note. **Cost of failing.** Payment to a retired address reaches the market and not your order, which turns a simple purchase into a support case with an uncertain outcome. #### Why addresses are per order A fresh deposit address lets the market attribute an incoming payment to a specific order without you having to label anything. That is convenient and it means an address from last week belongs to last week order rather than to you generally. #### How this fails - Sending to an address kept in a note from a previous purchase - Reusing a wallet address book entry saved during an earlier order - Copying from a browser tab left open from a previous session - Assuming the address is stable because it looks familiar #### What happens on failure The coin is not lost in the sense of being gone. It reached the market. It is simply not attached to the order you wanted funded, which means resolving it requires support and evidence rather than a click. That is recoverable and it is slower and less certain than getting it right the first time. #### Passing reliably Open the order, copy from the order screen, send immediately. Do not save deposit addresses in a wallet address book, because the address book is what makes the mistake easy. ### C-13: Fee added on top and amount matches exactly - URL: https://nexuscheck.shop/check/C-13 - Weight: high - Applied: Before funding (M3), Before any coin leaves your wallet **Statement.** Your wallet is configured to add the network fee on top of the amount rather than deduct it, and the figure sent matches the figure requested. **Pass.** Fee added on top, amount identical to the request. **Partial.** Slightly over the requested amount. **Fail.** Fee deducted from the amount, so less arrived than requested. **Cost of failing.** A shortfall smaller than the rounding on the price leaves an order unfunded. The cause is a wallet preference rather than anything either party did. #### The setting that causes this Wallets differ on one small behaviour. Some treat the figure you enter as the total leaving your balance and subtract the network fee from it, so slightly less arrives. Others add the fee on top, so the exact figure arrives. Neither is wrong and only one of them funds an order correctly. #### Why it catches careful people The amounts are tiny. An order sits unfunded over a difference smaller than the price rounding, and nothing about the wallet interface suggests anything went wrong. The transaction succeeded, it just delivered slightly less than the order required. #### If you have already underpaid 1. Do not send a second payment to top it up before asking, since two partial deposits are harder to reconcile than one 2. Open a support message with the order reference and the exact amount sent 3. Wait for instructions rather than improvising a fix #### If you overpaid Usually the simpler case. The surplus generally lands on your balance and you withdraw it, which is why sending very slightly over is graded partial rather than fail. Raise it with support if it does not appear once confirmations complete. ### C-14: Package inspected before receipt was confirmed - URL: https://nexuscheck.shop/check/C-14 - Weight: critical - Applied: On delivery (M4), When a package arrives, before you confirm **Statement.** The package is physically in your hands and matches what was ordered, and only then was receipt confirmed. **Pass.** Inspected against the listing, then confirmed. **Partial.** Confirmed on arrival without a careful check. **Fail.** Confirmed before arrival for any reason. **Cost of failing.** Confirming releases escrow permanently and removes the dispute route in the same action. There is no way back from it. #### What confirmation actually does It releases the payment held in escrow to the vendor and closes the order. Both effects are permanent. The dispute route exists only while the order is open, so confirming is the moment your remaining protection ends. #### Inspect against the listing, not against memory Re-read what the listing stated and compare it to what arrived. Quantity, description, condition, anything the listing specified about packaging or timing. Memory drifts toward what you expected rather than what was written, which is why the listing is the reference. #### Why partial exists here Confirming on arrival without inspecting is graded partial rather than fail because the goods are at least present. It is still worse than it looks, since a discrepancy discovered after confirmation has no mechanism behind it and depends entirely on the counterparty goodwill. #### If something is wrong Do not confirm. Open a dispute instead, with the order reference and dates, and describe what arrived against what was ordered. The relevant item on disputes covers what a submission should contain. ### C-15: No early release was requested or agreed - URL: https://nexuscheck.shop/check/C-15 - Weight: critical - Applied: On delivery (M4), When a package arrives, before you confirm **Statement.** Nobody asked you to release payment before delivery, or if they did, you declined. **Pass.** No request, or a request declined as policy. **Partial.** Agreed with a counterparty holding a long clean record. **Fail.** Agreed with a counterparty you have not transacted with before. **Cost of failing.** Early release hands over the money and deletes the dispute route simultaneously. It is the only user action that voids escrow entirely. #### Why the request exists Escrow ties up a seller working capital until the buyer confirms. That is a genuine cost to them, which is why established vendors sometimes ask. It is also the standard opening move of somebody who does not intend to ship, and from your side the two requests look identical. #### Why a policy beats a judgement You cannot reliably distinguish the two cases, and the cost of getting it wrong is the entire order with no recourse. A blanket refusal costs you access to a small number of sellers who insist on it. That is a much better trade than being right most of the time. #### Declining without friction State it as policy rather than as suspicion. It is not a judgement about that counterparty, it is how you handle every order, and framing it that way removes the negotiation entirely. #### Why partial is still marked down Agreeing with a long established seller is a lower risk version of the same action and it is still the action that removes your protection. It is graded partial because the outcome is usually fine, not because the exposure is different. ### C-16: A problem was raised as a dispute rather than absorbed - URL: https://nexuscheck.shop/check/C-16 - Weight: high - Applied: On delivery (M4), When a package arrives, before you confirm **Statement.** Where an order did not arrive or did not match, a dispute was opened with dates and an order reference rather than the loss being written off. **Pass.** Dispute opened with a short factual submission. **Partial.** Raised with the counterparty only, without opening a dispute. **Fail.** Absorbed silently, or confirmed anyway to end the situation. **Cost of failing.** Escrow exists precisely for this. Not using it means paying for protection and then declining to take it. #### When to open one After the stated dispatch window has clearly passed with no dispatch, after a reasonable delivery period following dispatch, or when what arrived does not match the order. Not while a stated window is still running, since that produces a weak case and a poor record. #### What a submission should contain 1. The order reference and the relevant dates, stated first 2. What was ordered, what arrived, and when 3. Any listing terms that bear on it, quoted accurately 4. The outcome you are asking for #### What to leave out Characterisation of the other party, repetition of the same point, and description of how the situation feels. Arbitration compares two accounts against whatever the market recorded. Material that cannot be checked adds length without weight, and length reads as uncertainty. #### The evidence boundary Only what happened inside the market message system is visible to arbitration. A conversation moved to an outside channel effectively does not exist for the process, which is the practical reason to keep order discussion on the market rather than a matter of preference. ### C-17: No funds sitting on the market outside an active order - URL: https://nexuscheck.shop/check/C-17 - Weight: critical - Applied: Periodic review (M5), Monthly, or after any change **Statement.** Your market balance is zero or holds only what a currently open order requires. **Pass.** Balance withdrawn, nothing idle. **Partial.** A small residual left after a completed order. **Fail.** A working balance kept on the market for convenience. **Cost of failing.** Every documented loss when a market ended, for any reason, was money sitting there at the time. Escrow does not cover balances outside an order. #### What escrow does not cover Escrow protects a payment attached to an order. A balance sitting outside one is not protected by anything, and it is exposed to whatever happens to the market, including endings that have nothing to do with anyone acting badly. #### Why this item is graded critical Because it is the only measure that makes the worst case survivable. Every other item reduces the chance of something going wrong. This one determines what it costs when something does, and it is entirely within your control. #### A schedule rather than an intention Withdrawing when the balance feels large does not work, because the threshold moves. Withdraw after each completed order, or on a fixed schedule. The habit is what matters, not the amount. #### The convenience argument Keeping a balance saves a deposit wait on the next order. That is a real saving of perhaps twenty minutes, weighed against the entire balance in the event of an ending. People who lost funds in past market endings were overwhelmingly making that same trade deliberately. ### C-18: Saved address set checked against a current source - URL: https://nexuscheck.shop/check/C-18 - Weight: standard - Applied: Periodic review (M5), Monthly, or after any change **Statement.** Your saved addresses have been compared against a current published set within the last month. **Pass.** Checked recently and current. **Partial.** Saved but not checked in several months. **Fail.** No saved set at all, or a set of unknown age. **Cost of failing.** A saved address that has been retired teaches you to trust an address that may now belong to somebody else, and an absent set forces a search during the next outage. #### Why saved addresses go stale Operators rotate addresses to spread load and make sustained attacks harder to maintain. An address you saved a long time ago may simply have been retired, which looks identical from outside to an address that was never genuine. #### What to save Bookmark a source that publishes the current set rather than the individual addresses. A bookmark pointing at a retired onion is worse than none, because it trains you to open something that may no longer belong to the operator. A bookmark pointing at a maintained source survives every rotation. #### A monthly check 1. Open your saved source 2. Compare it against the set published there now 3. Replace anything that no longer appears 4. Confirm the source itself still looks maintained rather than abandoned #### Why this is graded standard A stale set is an inconvenience that becomes dangerous only in combination with the session items, particularly the address comparison on the login screen. Those items catch the failure. This one prevents you needing them to. ## Questions and answers **What is this checklist for?** It verifies that things were done correctly rather than explaining how to do them. Each item states what passing looks like, what failing looks like, and what a failure costs, so you can audit your own setup instead of reading a guide and assuming it applied. **Which check matters most?** C-07, comparing the address on the login screen against your browser bar. It is the one that separates the real market from a cloned page, and it is the failure behind nearly every credential loss around markets like this. **How often should I run these?** By moment rather than on a timer. Setup items run once, session items run every single sign in, funding items run before coin leaves your wallet, delivery items run before you confirm, and two items are worth repeating monthly. **Can I skip the setup items if I already have an account?** Run them anyway, since most can still be corrected. The exception is C-03 on username reuse, which has no repair path, and knowing that is more useful than not knowing it. **Why is leaving a balance graded as critical?** Because it decides what a market ending costs you rather than how likely one is. Escrow protects payments attached to orders and nothing else. Every documented loss when a market ended was money sitting there at the time. **What if a check fails?** Each item states the cost and the required action. Most failures are correctable. Two are not, which are handing over a recovery phrase and reusing a username that has history elsewhere, and both are marked accordingly. **Is this site the market?** No. It publishes checklists and the verified address set. It sells nothing, takes no payment, runs no accounts and stores nothing about visitors. **Should I trust the addresses listed here?** Verify them rather than trust them. Copy one, open it in Tor Browser, and run C-07 before entering anything. That instruction applies to this site exactly as it applies to any other source. **Does passing every check make me safe?** No. It removes the avoidable failures, which is most of them. Nothing here makes a market safe, and every market that ever ended was operating normally the day before it did. **Why are checks numbered rather than just listed?** So a specific item can be referred to and revisited. A checklist you read once is a guide. A numbered set you can point at is something you can actually audit against.