News Feed
  • DrugHub has agreed to fully refund all users who lost money in the SuperMarket exit scam.  
  • Retro Market has gone offline. Circumstances of the closure unknown.  
  • SuperMarket has closed following an exit scam by one of the admins.  
  • The admin of Incognito Market, Pharoah, has been arrested by the FBI several months after exit scamming.  
  • Silk RoadTorhoo mini logo
  • darknet markets list
  • Popular P2P exchange LocalMonero has announced it is closing.  

Nightmare OpSec is UNACCEPTABLE : DarkNetMarkets | Torhoo darknet markets

I've been using the market for some time now, and there are some glaring OPSEC related issues I wanted to bring up.

1: Vendors can't delete the PGP encrypted address after an order is completed. If LE seizes nightmare or a vendor, they have full access to either the auto-encrypted addresses or EVERY ADDRESS that has ever purchased from the vendor. A vendor has told me that this could be a huge problem if it gets seized.

Unacceptable.

2: It's impossible to delete previous orders from your order history. Again, could become an OPSEC issue.

3: Site uses Java Script for the icons.

https://torhoo.cc/go.php?u=TDNVdmJtbG5hSFJ0WVhKbGJXRnlhMlYw# PLEASE fix these crucial issues, ASAP.

If you have other opsec issues with Nightmare, please comment below, so that they can get fixed.
An attempt to make a comprehensive list of everything that is just plain fucked up about the Nightmare market.

1. The fee. 4% to vendors for normal escrow, 8% for multsig. An ADDITIONAL 3% markup of prices that the customer pays, both escrow and multisig. So on a multisig transaction Nightmare is taking ELEVEN FUCKING PERCENT.

2. Autofinalization timer. A FUCKING MONTH.

3. Support sucks ass.

4. Multisig is currently broken.

5. Jabber notifications only if you use their server.

6. Ignoring vendor Terms of Service and Refund/Reship policy.
See: http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/00c2ca72e73f3d507af7/

7. Forcing XMR deposits to use a Payment ID even when Monero says that Payment ID's are obsolete

8. Cancelling orders despite vendor and customer wishes.

9. SLOW AS FUCK, NO VENDOR MIRRORS!

10. Why slow? Idiotic front end design. http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/187c25782d17c9852bbe
/u/AutoModerator M
0 points
6 years ago
[removed]
/u/duderugs
2 points
6 years ago
I take issue with point 4, and 9. Last time you posted here you didn't understand how multisig works and I feel you still have NFA.

Vendor mirrors are a very bad idea. You just have to look at SR2 and several arrests made due to the site being compromised and vendor mirrors. As only a small amount of users access a market using a vendor only mirror correlation attacks are easy and the Feds know they are getting vendors so worthwhile.
I don't need to understand how multisig works to know its broken on Nightmare because

1. A customer tried to place a MS order and I got an error stating **I** needed to deposit like 97 BTC to cover escrow or something.

2. When messaging Support THEY told me multisig was broken.


Just like you don't need to know how a car works to say its broken when it won't run.
/u/duderugs
0 points
6 years ago
Being a vendor you should know this basic shit.
/u/AutoModerator M
0 points
6 years ago
All onion links require approval to be posted.

This comment was posted automatically by a bot. All AutoModerator settings are configured by individual communities. Contact this community's Moderators to have your post approved if you believe this was in error.
/u/FrankWhite
2 points
6 years ago*
Auto encrypted addresses won't actually be stored in the database in clear text and unless they have the vendors key LE are screwed.

Manually encrypting is best though obviously just in case of malicious market or LE take over and code modification to store auto encrypted addresses in plain text, like what happened when LE took over Hansa. Order thing yeah, but unless they know who the account belongs to it means nothing.

The JS for icons is very annoying, agreed. Makes no sense either..
/u/NoOneHear
2 points
6 years ago
Instead of fixing something that is clearly run by incompetent people why not just go to another marketplace?

you can't polish a turd.
/u/duderugs
1 points
6 years ago
You shurely can, Empire did that with the code they bought that was Alphabay.
/u/NoOneHear
1 points
6 years ago
alphabay was solid. Nightmare is not. I'm not talking aesthetics but functionality and security.

Fuck nm they use Javascript...
/u/duderugs
1 points
6 years ago
Only to warn you you have Javascript enabled...
/u/YoungMind
1 points
6 years ago
If the only thing you have to say is that the auto encryption sucks, you're right.

Tho it's basic OPSec to know they suck. thats why people always tell u to manually encrypt it.

About the javascript well, you can still use it without it activated, so i don't see any big deal here.

Also they coming back better soon https://ibb.co/SJLRZVJ
/u/[deleted]
1 points
6 years ago
These are nothing new evolution did the same thing in regards to msgs and pgp addresses.
So yeah it is not a good thing and maybe best to try another market.
/u/[deleted]
1 points
6 years ago
YEAH man whats the explanation for this , simple over site, I have an order that has even changed fk nos how , i haven't been phished as i didnt even pay for what it says ive received , but if it did get seized of no doing by me looks like i have a sniff habit , cheers for that . There isnt any similar alternatives thats the issue .
/u/bluedonald
1 points
6 years ago
Not only vendors, customers can't delete the PGP encrypted address after an order is completed as well. I think that both vendors and customers must be able to do that!
/u/NewDisposableIdentity
1 points
6 years ago
remove auto encryption, if the message is not encrypted it won't be sent. you can use xmpp for chit chat, which is secure.
/u/sleevey
1 points
6 years ago
Still why I haven't ordered. The image downloads are insane and are unecessary! It's obvious we all are looking for someting different, but we're wasting time/bandwitdth/privacy for what should be simple compression. I mean they put in the work to making an actual site but fuck, don't be lazy about it. Also, can we at least get a favorite/save feature? No way anyone bookmarks every single thing out there.
/u/joemoms
0 points
6 years ago
YEAH their system doesn't know when coin has been delivered. they don't have a logging system or accounting for how much they've made. it seems like a dash zcash shill scamming site. why vendors aren't really there or support. expecting by the quality it will tank out. coinbase got all the autistic OCD tools for manual