BlackOps Adversary Register Who takes money off buyers, and what actually stops them No ads, no affiliates
Register › Who is after you

BlackOps addresses

Three published addresses for the same market. Copy rather than retype, and verify the signature once you are through.

Mirror 1 blackops5l63qnwnmlnsfvtlu66md3x3vp3fdtpna42eq7ozujr67hid.onion
Mirror 2 blackops6kignp3eddmvqcfkjzf6qr6haxbmkypc2xtqlnhuu4ak4dqd.onion
Mirror 3 blackops27m32abqvbhnyswgazqawxqbznbzkkkv5sjo7gve2ndpsdad.onion

This site publishes the list and does not monitor it. An address that opens is not an address that is genuine, and the check that settles it takes under a minute.

The gateway operator

The only profile here where the exposure exists whether or not the operator intends any harm.

What they want
Traffic. Some want nothing else, which is what makes this profile awkward.
How they earn
Advertising, or credentials, depending on who is running it. From outside there is no way to tell which.
What it costs them
A server and a domain. The proxying itself is simple.
How you meet them
A site offering to open onion addresses in an ordinary browser, usually by appending a suffix, marketed as an easier way in.
What gives them away
Nothing, and nothing needs to. Everything you send passes through their machine in a form they can read.
What stops them
Using the proper client. A few minutes once, and the entire category disappears.

Why an honest operator does not fix it

A gateway that could not read your traffic could not forward it. The exposure is the mechanism rather than a flaw in it, so the question is not whether the operator is trustworthy today.

And an honest operator is still one who can be compromised, compelled or replaced. Any of those affects everyone who used the gateway, retroactively, because the traffic already passed through.

What else it costs

The lookalikesAnything on the clearnet asking for market credentials is collecting them. The lookalike domains marketed as gateways are usually not gateways at all, because if the goal is credentials there is no reason to build the proxying part.

Why people use them

Because installing a browser is an obstacle and people route around obstacles. That is a reasonable instinct in most contexts and a costly one here, because the obstacle was carrying the protection. The alternative is Tor Browser from the project directly with the installer signature checked, which takes a few minutes once and removes every item on this page.