News Feed
  • DrugHub has agreed to fully refund all users who lost money in the SuperMarket exit scam.  
  • Retro Market has gone offline. Circumstances of the closure unknown.  
  • SuperMarket has closed following an exit scam by one of the admins.  
  • The admin of Incognito Market, Pharoah, has been arrested by the FBI several months after exit scamming.  
  • Silk RoadTorhoo mini logo
  • darknet markets list
  • Popular P2P exchange LocalMonero has announced it is closing.  

DrugHub login process suspecious - would like second opinons : DarknetMarketsNoobs | Torhoo darknet markets

During DrugHub's login process they ask for your public PGP key that is used to encrypt a 2FA token message to login. This process raises alarm bells to me because of the possibility of a man it the middle attack, specifically changing deposit addresses after logging in. You might say I should check the username and profile data after logging in, I think its possible to proxy a login and display the correct information and marketplace while also changing the wallet address. I will always encrypt my messages outside the marketplace but it does stop wallet address substitutions.


After going to https://torhoo.cc/go.php?u=TDJRdlpISjFaMmgxWWc9PQ==#, I grabbed their public key and mirrors from their distribution link. With it being a clearnet site I am being cautious.
Does this login style raise concern with anyone else or am I crazy or over thinking it? Detailed answers are appreciated to help ease the mind
/u/DrugHub P DrugHub Market Staff
3 points
21 hours ago
Lmao. Do some more (well a lot more) research. Until you do use a different market, you will avoid lots of grief.
/u/ImpactMarket
1 points
19 hours ago
Brutal! You are supposed to help him not roast him 😂
/u/DrugHub P DrugHub Market Staff
2 points
18 hours ago
Help how ? By copy and pasting the information already available all over the place ? We don't do that.
/u/bitemytongue1 🍼
2 points
21 hours ago
What are you paranoid from depositing 500 xmr? You overshot the moon. Keep your private key.....private.
/u/Bartolo 🍼
2 points
20 hours ago
The big problem with Drughub is the inability to speak to vendors
/u/KonaCokeHead
1 points
20 hours ago
UI is a little hard to get used too. I prefer how you communicate to vendors though PGP only is smart. Dont be lazy man
/u/Preska 🍼
2 points
20 hours ago
the PGP only communication is the smartest thing they could have done!
/u/ImpactMarket
1 points
19 hours ago
[removed by moderators]
/u/BlackHoof 🍼
1 points
21 hours ago
[removed by moderators]
/u/Greycious
1 points
21 hours ago
You're tripping. DrugHub is actually pretty secure in their approach, probably the most out of any market right now?

The invoice based system means your money is never really sitting in a hot wallet for too long, this reduces the risk of loss of funds for people who for whatever reason leave money on markets in the case of an exit scam, hack, LE, whatever.

The login system is perfectly fine in my opinion, it skips the bullshit of making up usernames and just relies on your PGP. You could argue that having usernames, pins, etc would make it less likely LEO could get into a vendors account if they were to make a bust, but if they have the vendors PGP I feel like they're probably gonna squeel on markets, their username, etc anyways so it's not a huge concern for me. I've never used the recovery system on any of these websites, I know usually its a seed phrase but I'd imagine having the PGP key helps too. All this to say nothing about the login is increasing your risk of anything.

You might say I should check the username and profile data after logging in, I think its possible to proxy a login and display the correct information and marketplace while also changing the wallet address. I will always encrypt my messages outside the marketplace but it does stop wallet address substitutions.


I don't know what this even means. Nobody can falsely sign a signature with your address, invoice, etc, using the drughub master key aside from drughub, there is no secret attack, if there was PGP is useless as fuck. If you just verify messages/signatures like you should, even if you do get phished somehow, you can at least realize it and get a new URL / account.
/u/cilantr0
1 points
19 hours ago
If (big if) you understand how PGP works, so as long as you trust the key of the Drughub .onion URL you are connected to, your whole question/suspicion (suspEcion?) makes absolutely no sense.
/u/ignorantmonkey
1 points
19 hours ago
I suggest you read up on how asymetric encryption works. You're not exposing your private key. It is not possible to "calculate" your private key even if anyone were to snoop all of the public key, encrypted message and the content of the decrypted message. At no point during this process is your private key exposed.
/u/brokenbox
1 points
17 hours ago
I think? your saying... that because you volunteer your public PGP key, it could be anybody on the other side sending you false verification via a PGP-encrypted message. Which is possible I guess. The safeguard against this has already been gifted to you my son. The address you use to connect MUST be verified by YOU, using their provided, and most importantly, legitimate certificate, aka the Master Key. If you can verify the link then you should be good.