BlackOps Adversary Register Who takes money off buyers, and what actually stops them No ads, no affiliates
Register › Who is after you

BlackOps addresses

Three published addresses for the same market. Copy rather than retype, and verify the signature once you are through.

Mirror 1 blackops5l63qnwnmlnsfvtlu66md3x3vp3fdtpna42eq7ozujr67hid.onion
Mirror 2 blackops6kignp3eddmvqcfkjzf6qr6haxbmkypc2xtqlnhuu4ak4dqd.onion
Mirror 3 blackops27m32abqvbhnyswgazqawxqbznbzkkkv5sjo7gve2ndpsdad.onion

This site publishes the list and does not monitor it. An address that opens is not an address that is genuine, and the check that settles it takes under a minute.

The clipboard swapper

The only adversary here who is already inside, and the only one that verification does not help against.

What they want
A payment sent to their address instead of the intended one, by replacing what you copied with something that looks similar.
How they earn
Whole payments, occasionally. The approach costs nothing to run against many machines at once, so a low success rate is still profitable.
What it costs them
Nothing per target. The software watches for anything address shaped and substitutes.
How you meet them
Something already running on your machine, installed alongside something else you wanted. Frequently the thing that promised to make Tor faster or easier.
What gives them away
The address in the field is not the address you copied. That is the only signal, and it is completely reliable if you look.
What stops them
Reading what actually landed in the send field before confirming, every time. And not installing convenience software in this area at all.

Why this one is different

Every other adversary in the register is defeated by verification. This one is not, because verification establishes that the destination you reached is genuine and says nothing about what your own machine did with a string afterwards.

It also inverts the usual advice about reading addresses. Elsewhere on this site the guidance is to compare the middle, because forgeries match the recognisable ends. Here the substitution is wholesale, so checking the first and last several characters catches it immediately. This is the one place where the quick check is the right check.

The honest limitVerification assumes a trustworthy local machine and cannot establish one. Nothing on this site fixes a compromised computer, and pretending otherwise would be the most dangerous thing it could say.

Where it comes from

The check that catches it

Before confirming any payment, look at the address in the field and compare the first and last several characters against the source. Not the middle, the ends, because a swap replaces the whole string rather than resembling it. It takes about three seconds and it is the only thing standing between this attack and a completed payment.

The same applies to an address you paste into the browser. If what appears in the bar is not what you copied, stop and treat the machine as the problem rather than the page.