Monitors tracking English-language Tor hubs flagged a sustained Torzon phishing wave from June into mid-July 2026. Operators combine typosquat clearnet domains with near-identical onion strings. The goal is credentials, seed phrases, and deposit addresses — not “helpful mirrors.”

Torzon phishing wave: fake mirrors still active

Clone kits recycled from earlier market exits now wear survivor branding. Search ads, forum DMs, and “updated link” pastes still push landers that never match a PGP-signed list. A polished UI is not a trust signal; missing anti-phishing phrase is.

What changed this week

Volume stayed high on exact-match “torzon link” queries. Some clones deliberately load faster than real rendezvous circuits so impatient users skip verification. Others pad a fake list with one live onion so the whole paste looks plausible.

Practical rule

  1. Open onions only from a saved Dark Markets page — not from ads.
  2. Check the anti-phishing phrase before any password field.
  3. If the phrase is missing, leave. Do not “try anyway.”

This desk does not repeat onion strings in every headline. Keep the vault on Dark Markets and treat urgency as hostile.