Nexus Handbook handbook · signed 0A9D · v2026.17

FAQ

Common questions, with the actual answers given by support and the dispute desk. Pulled from a year of tickets, edited for clarity.

#Mirrors and access

What is the current official Nexus Market URL?
Three v3 onion mirrors listed on the Mirror Roster. All three carry the same PGP signature with fingerprint ending in 0A9D. The roster is republished daily.
How do I open a mirror?
Hit Copy on the mirror card, open Tor Browser pulled directly from torproject.org, paste into the URL bar, set the security slider to Safest, then load the page. Verify the PGP timestamp before submitting credentials.
Mirror 1 is timing out, what now?
Try Mirror 2, then Mirror 3. Tor congestion is routine, single-mirror outages happen weekly. If all three fail past 30 minutes, reload the Mirror Roster. Never search for replacement URLs on the clearnet.
Are clearnet links to Nexus legitimate?
No. Nexus Market does not run a clearnet frontend. Clearnet domains claiming to be Nexus are phishing operators. Use the handbook, verify the PGP signature, then enter credentials only on the v3 onion.
Can I bookmark a mirror in Tor Browser?
Yes. The mirror addresses rarely change and the bookmark will work across sessions. Even with a bookmark, run the PGP verification flow on every login. The bookmark proves the address has not changed, not that the page is fresh.

#Cryptography

What is the PGP fingerprint and where do I get the key?
RSA 4096, key ID 0x7F2A0A9D, full fingerprint 7F2A 9C41 66B8 E1D5 4832 19A4 88F3 BD2C 1E5A 0F77 ... 0A9D. The public key is published on each mirror under /pgp.key and cross-signed by three independent witnesses.
How do I verify a mirror with GnuPG?
Import the master key once. On the mirror login page, copy the signed timestamp block between BEGIN and END markers, save into a local file, run gpg --verify timestamp.asc. A clean Good signature with the matching fingerprint is the only clearance to log in. See Getting Started step 4 for the full flow.
GPG says "key is not certified", is that bad?
No, that is the trust web warning. If the message reads Good signature followed by WARNING: This key is not certified with a trusted signature, the signature itself is cryptographically valid. After confirming the fingerprint matches, sign the key locally to silence the warning on future runs.
Has the master key ever rotated?
The master key has not rotated since the platform opened in late 2023. Subkeys for support, vendor desk, and other functions rotate quarterly, signed by the master and witnessed independently. A future master rotation would be announced 30 days in advance and signed by the outgoing key.

#Money

Why Monero by default?
Bitcoin transactions are public and indexed by chain analysis vendors in real time. Monero ring signatures, stealth addresses, and ringCT hide sender, recipient, and amount. For a market whose entire purpose is privacy, only one of those defaults makes sense.
Is Bitcoin still supported?
For legacy balances only. Accounts created before the 2024 currency rotation can still hold and withdraw BTC. New deposits route to XMR on signup. The platform does not encourage ongoing BTC use.
Which Monero wallet should I use?
Feather Wallet for desktop, the Monero CLI for hardened sessions, hardware wallet support through Trezor and Ledger for cold storage. Avoid web wallets entirely. Avoid any tool that asks for a seed phrase in a form field.
How does multisig escrow work?
Each order creates a 2-of-3 Monero multisig contract. Buyer, vendor, and platform each hold one key. Two of the three must sign to release funds. The buyer signs on receipt of goods. The vendor signs on dispatch confirmation. The platform signs only in dispute resolution. No single party drains the contract alone.

#Vendors

How do I become a vendor?
Apply through the in-market vendor portal after a buyer account in good standing exists. The application requires a PGP key, a vendor handle, a category list, a description, and an upfront bond denominated in XMR. The bond is held in multisig, refunded after probation closes cleanly, forfeit on the first confirmed scam complaint.
Why is there a bond?
The bond is a commitment device. It signals that the vendor expects to operate long enough to recover the deposit, which selects against single-shot scammers. The amount tracks category risk, higher for goods that draw more disputes.
Can I import reputation from another market?
Yes. Signed feedback exports from Empire, Dream, AlphaBay, and other markets that issued cryptographic signatures shorten the probation window. They never waive it entirely.

#Disputes

How do I open a dispute?
Inside the order ticket, after the listed delivery window has lapsed and after at least one good-faith message to the vendor has gone unanswered for 48 hours. Premature disputes are dismissed without prejudice. The order ticket is the only legitimate dispute channel.
What evidence carries weight?
Photos timestamped against shipping deadlines, tracking screenshots, signed message logs from the in-market system, and PGP-signed buyer statements. Anonymous external claims and clearnet screenshots are ignored. The dispute panel only acts on evidence that exists inside the order context.
Can rulings be reversed?
No. Rulings are written, signed, and attached to the vendor profile permanently. The only recourse is appeal to a fresh panel within 14 days. Even on appeal the original ruling stays on the profile, only the appeal outcome is added.

#Contact and reporting

How do I reach support?
Encrypted onion email only. Addresses for general support, vendor desk, dispute panel, and security disclosure are published on each active mirror under /contact. Nexus does not run a clearnet support inbox, a Telegram bot, a Discord server, or any other clearnet messaging surface.
I think I found a phishing clone, what do I do?
Report it to the security channel with the URL and any messages received. The more reports we collect, the faster the impersonation network gets burned. Do not engage with the phishing site, do not enter test credentials, just report and move on.
Is there a bounty for vulnerability reports?
Yes, paid in XMR after the fix is deployed. Verbal NDA, no contracts. Reports go to the security channel encrypted under the security subkey, with a working callback handle for follow-up.
nexus market faqnexus market common questionsnexus market supportnexus market urlnexus market mirrornexus market loginnexus market pgpnexus market escrownexus market disputenexus market vendornexus market moneronexus market bitcoin