signature lab
torverifyverify before you connect
mirrors.json2-of-3sig pending

Verdict · project record

Is the Torzon Onion Link Real? torverify’s 2026 Verified Address Check

Torzon is one of the projects we keep an address of record for. Below is the exact onion covered by our source, printed as plain text so you copy it instead of clicking a link. A convincing clone can copy everything about Torzon except the private key that owns this address.

torverify exists to answer one question about Torzon: does this address match torverify’s signed source. torverify does not rank Torzon against other projects, does not take payment from Torzon or anyone else to publish this record, and torverify will update this page the moment torverify’s quorum has something new to confirm — not sooner.

?
UNVERIFIED

This string matches the Torzon record in torverify's source, but the 2-of-3 quorum signature is still being brought online — so the honest verdict is UNVERIFIED, not LEGIT. Re-check the PGP signature by hand before you trust it.

Onion of recordtorzonguqmlfy2kfi5tjbnt4bp3idtkjzi4qtupmhpdihjftomjtdzqd.onion
PGP fingerprint0000 0000 0000 0000 0000 0000 0000 0000 0000 0000

source: /mirrors.json · quorum 2-of-3 · live signature pending
The fingerprint is a placeholder until the offline signer keys are published on the PGP page. Until then, treat the address as provisional and confirm by hand.

What UNVERIFIED means here, and what it does not

UNVERIFIED says two things at once: the address above is the one torverify holds on record for this project, but torverify’s 2-of-3 signature quorum has not yet confirmed it.

What torverify’s UNVERIFIED explicitly does not claim

It is not a claim the market is dishonest, that an order will not arrive, or that the service is down right now — reachability is a job for a status board, not a torverify verdict. torverify’s Torzon entry means the onion service specifically, nothing wider — see below for the names it gets confused with.

Why the string changes, and why that is not alarming

Onion services rotate keys, add mirrors, and sometimes move outright. People who memorise a URL get caught out the day it changes. That is the whole reason the answer is a signature rather than a bookmark. Trust the signed source, compare the fingerprint, and let the old string go. If a forum post swears an address is the newest one, that claim is worth exactly nothing without a signature you can check.

Reading a Torzon mirror-list claim skeptically

A post listing "5 working Torzon mirrors" is optimizing for volume, not accuracy — more links means more chances one of them earns a click, including a phishing one mixed into a plausible-looking list. Treat every entry on such a list the same way: as a candidate string to compare against the signed source, never as a pre-verified link.

What a genuine Torzon rotation announcement looks like

A real rotation is reflected here once our 2-of-3 signature quorum confirms it, not the moment a screenshot of an announcement starts circulating. If you see a claimed new address anywhere else first, that is normal — our verification lag is deliberate, not a sign we missed something.

Why torverify won’t speed-run the re-signature step

It would be possible for torverify to publish a rotated Torzon address the moment a single channel claims one, and that would look more responsive. torverify deliberately doesn’t, because the entire value of torverify’s 2-of-3 quorum comes from not skipping it under pressure — a faster wrong answer is worse than a slower right one, and Torzon’s own history includes clone waves that only a patient signature check caught before wider damage.

Torzon-specific clone patterns torverify has catalogued

Torzon is popular enough to be worth impersonating, which means the address above is not the only thing calling itself Torzon on the open web or inside Tor. The patterns below are what every Torzon clone we have reviewed shares, regardless of how polished the copy looks.

The clone surfaces right after a real outage

When the genuine Torzon onion goes quiet for maintenance, a key rotation, or ordinary Tor network churn, that is exactly the window a clone operator times a push of "new Torzon mirror" links into forums and search results. The outage is real; the replacement address being offered almost never is. Treat any such gap as a reason to wait for this page to update, not a reason to go searching.

The address is close, never exact

A Torzon clone banking on a rushed glance will register or generate an onion that shares a visible fragment with the real address — a matching prefix, a similar length, sometimes even a matching first and last few characters. The full string in the record above is written out for exactly this reason: a fragment match tells you nothing, and only a character-by-character comparison against the signed source catches the substitution.

The signature check is missing, faked, or skipped entirely

The single most consistent tell across every Torzon clone: no working PGP verification path, or a key with no chain of custody back to a previously trusted Torzon signature. A visual copy of a page is inexpensive to produce; a signature that actually verifies against an established key is not. That gap is what this page exists to close — confirm the fingerprint on the PGP tool before you trust any Torzon address, including this one.

A clone that never had a working Torzon behind it at all

The rarest but most damaging Torzon clone pattern is a page that was never a mirror of anything real to begin with — it exists purely to harvest login credentials or wallet seed phrases from anyone who mistakes it for the market. There is no genuine Torzon behind it to be “close” to; the entire site is bait. torverify’s address check applies the same way regardless of which pattern is in play: if the string does not match the signed record above, why it doesn’t match is not the part that matters.

Torzon mirror history and why torverify keeps re-checking it

torverify does not treat a signed Torzon address as permanent. Active-market addresses get re-confirmed on a rolling basis, because a verdict from months ago is not one you should still be acting on today. Torzon’s last rotation showed up here only once our 2-of-3 quorum confirmed it — not the moment a forum thread claimed a new link.

Why buyers specifically ask torverify about Torzon

Torzon draws a steady stream of “is this real” questions because it is popular enough that impersonation is worth a scammer’s effort, and the market has no way to broadcast an authoritative answer on its own. torverify exists for exactly that gap: an independent, PGP-anchored check that does not depend on whichever forum post or search result a visitor landed on first.

What changes on this Torzon page between torverify re-checks

Between re-checks, assume nothing has silently changed — the address, fingerprint, and quorum status reflect the last confirmed state. If Torzon announces a rotation faster than torverify can re-verify it, treat the announcement as unconfirmed until this page updates, leaning on how to verify a .onion address in the meantime.

torverify’s Torzon verification process, step by step

The mechanics behind this verdict match every verdict torverify publishes: an address enters our source of record only after two of three independent signers confirm it against Torzon’s own published PGP key, not a screenshot, a forum claim, or a third-party listing. That quorum step exists because a single compromised signer cannot push a bad Torzon address into this record alone — it takes agreement from two.

None of that changes what a torverify verdict is not: not a review of Torzon as a market, not a guarantee about any vendor on it, and not advice on whether to use it. It narrowly answers one question — is this the address Torzon actually controls.

Cross-checking a Torzon claim outside torverify

torverify’s verdict is not the only signal worth having before you connect. Run the address through the Tor Browser distributed by the Tor Project itself rather than a repackaged build — a modified browser can leak information no address check would ever catch. torverify checks the string and the signature; it does not audit the browser you use to reach it.

Why Torzon earned a place on torverify’s list

torverify does not track every project that exists on Tor — the list stays deliberately short, and Torzon earned a place on it the same way every other entry did: enough visibility that phishing clones of it are already a real, documented problem, and a PGP key that torverify could cross-confirm through more than one independent channel before publishing anything.

What torverify would need to see to change this Torzon verdict

A change to the Torzon entry above — a rotated address, a status change — only happens after torverify's 2-of-3 offline-signer quorum confirms it, the same bar every other project on this site has to clear. torverify would rather this page lag an actual Torzon change by a day than publish an update sourced from a single unconfirmed announcement.

What this Torzon page does not attempt to answer

This record speaks to one narrow claim: the address above is the one torverify holds on file for Torzon. It is not a review of Torzon as a market, not a claim about escrow reliability, and not advice on whether to use it. For that broader context, torverify's legit markets page explains exactly where that line is drawn, and why torverify stays on this side of it.

Names that sound like Torzon but are not Torzon

Search results for “Torzon” surface more than the onion market torverify tracks, and conflating any of it with the address on this page is an easy, avoidable mistake.

Similarly spelled services and unrelated products

Torzon here is exclusively the Tor marketplace with the onion address printed above. It is not Tarzan, not a Tonzon-branded insulation product, not Toradex’s Torizon embedded Linux distribution, and not any clearnet SaaS tool that happens to share a few letters. None of those unrelated names have any connection to the onion service torverify verifies — they share a string of letters by coincidence, nothing more.

Why torverify still addresses Torzon lookalikes directly

It would be easy to assume a mismatch like this is too obvious to need stating, but a share of the traffic that reaches a Torzon verification page arrives from a general search rather than a direct recommendation, and a fast reader skimming a results page can genuinely confuse an unrelated result for the market they meant to check. Naming the confusion plainly costs torverify one short section and saves a reader a wasted click.

What a Torzon address check does not cover

Confirming the address above is the one torverify holds on file for Torzon answers a narrow, specific question. It does not extend to anything that happens once a connection to Torzon is actually made.

Escrow and vendor conduct sit outside torverify’s scope

Whether a specific vendor on Torzon ships what was ordered, whether an escrow dispute resolves fairly, and whether the market’s own moderation is competent are all questions a signed-address check has no way to answer. torverify confirms the operator’s infrastructure is genuine, not that every interaction on top of it will go well; the EFF’s Surveillance Self-Defense guide is a better starting point for the broader operational-security habits that sit outside torverify’s narrow scope.

Where to read about Torzon-adjacent market risk

For the broader context around what “legit” can and cannot mean for a market like Torzon, torverify’s legit darknet markets page draws that line in more detail, and is worth reading before treating a torverify-verified address as a green light for anything beyond the address itself.

Why torverify ignores forum threads and directory listings for Torzon

A Torzon address surfaces in a lot of places torverify does not control and does not treat as evidence on its own.

A forum post is not a signed source

A Reddit thread or forum post claiming to have “the real Torzon link” carries no cryptographic weight, no matter how many upvotes or replies agree with it. Popularity is not a signature. torverify’s source is signed by offline keys specifically because a large enough audience can be wrong together, and a convincing forum consensus has been the delivery mechanism for more than one Torzon phishing wave.

A directory listing is not a verification

A general-purpose Tor directory that lists a Torzon entry alongside hundreds of others is, at best, repeating a submission nobody independently checked. torverify does not treat inclusion on such a list as corroborating evidence, and recommends treating it the same way torverify does: as a candidate string to check against the signed source here, not as a pre-verified fact.

How often torverify re-checks the Torzon record

torverify does not run this check once and leave it alone.

What triggers a torverify re-check of the Torzon entry

A re-check runs whenever there is a specific reason to run one: a reported outage lasting longer than ordinary Tor churn explains, a rotation claim from multiple independent channels at once, or a routine pass through torverify’s full tracked list. A quiet, uneventful stretch does not trigger a re-check on its own, because there is nothing new for torverify to confirm.

Questions

Where is the current Torzon onion?

It is the 56-character string in the record above. Copy it as text. Do not lift a link from a search result, a chat message, or a random mirror list.

The Torzon address is different from last month. Which one is right?

The one in the signed source, always. Services rotate. A memorised URL ages badly, a verified signature does not.

A site looks exactly like Torzon but the address is slightly off. Safe?

No. A near-identical address with a copied layout is the classic phishing setup. One wrong character is a different service. Close the tab.

Verify it yourself

Do not take our word for it. Confirm the signature on the PGP tool, read the signed source directly, or learn the routine in how to verify a .onion address.