News Feed
  • DrugHub has agreed to fully refund all users who lost money in the SuperMarket exit scam.  
  • Retro Market has gone offline. Circumstances of the closure unknown.  
  • SuperMarket has closed following an exit scam by one of the admins.  
  • The admin of Incognito Market, Pharoah, has been arrested by the FBI several months after exit scamming.  
  • Silk RoadTorhoo mini logo
  • darknet markets list
  • Popular P2P exchange LocalMonero has announced it is closing.  

Scientific breakthrough: When monkeys discover the Internet and learn to speak, they DDoS Archetyp. : CafeDread | Torhoo darknet markets

I was debating whether to post it in https://torhoo.cc/go.php?u=TDJRdlpHRnlhMjVsZEcxaGNtdGxkSE09# or in https://torhoo.cc/go.php?u=TDJRdmJtVjNiV0Z5YTJWMGN3PT0=# but it seemed appropriate to be https://torhoo.cc/go.php?u=TDJRdlkyRm1aV1J5WldGaw==# since they aren't a market on Dread and Bazaar (BreakingBad) admins are jesters.

Another user who is working as undercover for Bazar market HarrierDoBois posted a topic where the Bazaar admins made a post on their own forum BreakingBad. In the post they outlined how they were allegedly DDoSing Archetyp and delusions of grandeur, a copy available for your entertainment https://torhoo.cc/go.php?u=TDNCdmMzUXZOalF4TmpaaFpERmhZMkV4T0dNeE0ySTVZems9#.

How do I know HarrierDoBois is working for them? Easy. Look at the image he linked on dumpli in his post. Notice the a moment ago text at the bottom? Standard for the forum software they're using means literally some seconds ago. HarrierDoBois was told to quickly screenshot it and in their rush to expose their stupidity they added another stupidity. Physically no way to have screenshotted it without waiting and refreshing every second on the forum. Now everyone knows who he works for. Since we're talking about this let me also add palecafe and deepweb as owned by Bazaar/Breakingbad and they have been pushed on Dread a couple of times. Be aware.

The jesters at circus Bazaar/BreakingBad Forum were quick to disable their javascript captcha shortly after reading my response https://torhoo.cc/go.php?u=TDNCdmMzUXZOalF4TmpaaFpERmhZMkV4T0dNeE0ySTVZems9#/#c-e08aad2504911956ae to their funny Rome delusions. Now their registration is broken and you can't hack their Laravel application. But you don't need to hack or bothering with hacking them because they aren't on the level of the lowest tier markets which appear for few weeks in https://torhoo.cc/go.php?u=TDJRdmJtVjNiV0Z5YTJWMGN3PT0=#. Let me explain.

When you enter their market what is the first thing we should check? The source code. Immediately you see information is sent to

stat bazaar **


<script>
(function(){
var loader = document.currentScript;
var domain = window.location.hostname;
// var statHost = 'stat.' + domain;
// var statOrigin = window.location.protocol + '//' + statHost;
var statOrigin = '*****stat.bazaar.**';
var url = statOrigin + '/js/script.js';

fetch(url)
.then(function(response) {
return response.blob();
})
.then(function(blob) {
var blobUrl = URL.createObjectURL(blob);
var s = document.createElement('script');
s.defer = true;
s.src = blobUrl;
s.setAttribute('data-domain', domain);
s.setAttribute('data-api', statOrigin + '/api/event?rid=*****-***-**-****-******');
document.head.appendChild(s);
})
.catch(function(err) {
console.error('Error loading stat script:', err);
});
})();
</script>

or the onion equivalent

r2e7xc6s6fnmn5jblnmedwtrljzfzgwp34qw45bmri5ljl3kc********onion


var statHost = 'r2e7xc6s6fnmn5jblnmedwtrljzfzgwp34qw45bmri5ljl3kc********onion';
if (!isOnion) {
statHost = 'stat.bazaar.**';
}

var statOrigin = window.location.protocol + '//' + statHost;
var url = statOrigin + '/js/script.js';

hosting their Plausible analytics platform. Because they don't have the skills their own one they have used a ready product. If you like tracking like Google and the rest of the Internet track you, you would say yeah the move to use another product for analytics is tasteless and shows lack of skill but what the hell, right?

But hold on for a ride. Not only the entry is tracked but every page you go and everything you do, all actions on the platform. If you're visiting their clearnet domain (full site on there, genius)

curl --include "r2e7xc6s6fnmn5jblnmedwtrljzfzgwp34qw45bmri5ljl3kc********onion/api/event?rid=%27"
HTTP/1.1 404 Not Found
Date: Thu, 29 May 2025 **:**:** GMT
Content-Type: text/html; charset=utf-8
Content-Length: ****
Connection: keep-alive
access-control-allow-credentials: true
access-control-allow-origin: *
access-control-expose-headers:
cache-control: max-age=0, private, must-revalidate
referrer-policy: strict-origin-when-cross-origin
x-content-type-options: nosniff
x-download-options: noopen
x-frame-options: SAMEORIGIN
x-permitted-cross-domain-policies: none
x-request-id: *******-********
x-robots-tag: noindex, nofollow
Server: awselb/2.0

A level of stupidity we haven't seen in the darknet yet. Logging and tracking all of your user movements and requests and for extra easy steps for police to get the data, they are hosting it on AWS. If I didn't know they were this stupid I would say this market is a honeypot.

More smart moves? Yes please! Using Minio to store your pictures.

storage.bazaar.**/media/

and equivalent

storage.bazaarboom567hsuxjspmwurpl7lyx23p7r2byg22vwfhv5yu********onion/media/

I don't have any proof for this one here but given how technically inept they are, I wouldn't be surprised if the Minion bucket itself is hosted on AWS too.

Want to try Minio default creds (minioadmin:minioadmin) or other exploits? Be my guest.

Want to know how they make up their authentication cookie? No problem decode the base64.

{"iv":"oVE09nuOgS45kRgYGZY33g==","value":"NTWPR3agRofCyJn/yju5vx26ew5cHF0UBzgu6hu4W4Zffcd0T1LZQ5b3ENEpcnZt","mac":"220f6b87e732ac927f18964c95f6ba8c091fd5cee9400bf4187c10704a09bf83","tag":""}

Bazaar offers more! Instead of PGP recommendation or PGP enforcement, Bazaar has fields for orders directly to put your address, name and other details. But don't worry and think of extortionists like Incognito admin who put everyone on the line, Bazaar promises to use SHA256 encryption on your notes and store them only for short period of time. Pinky promise.

I didn't personally bother to look at their website and infrastructure for more than an hour as the more I found the more I was in disbelief. The level of security and care for the users is minus, minus 100.

A post like this isn't good without an IP leak. Not to be within doxxing rules I'll tease a small part of it

77.110.10*.***

This is one of their IPs. Ubuntu server (yes unique TCP packets confirmed not only). Could it be the Ubuntu server where their analytics is hosted? I'll let the readers do their own homework/have fun.


curl --include "r2e7xc6s6fnmn5jblnmedwtrljzfzgwp34qw45bmri5ljl3kc********onion"
HTTP/1.1 403 Forbidden
Date: Thu, 29 May 2025 **:**:** GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive
Server: awselb/2.0

<html>
<head><title>403 Forbidden</title></head>
<body>
<center><h1>403 Forbidden</h1></center>
<hr><center>nginx/1.24.0 (Ubuntu)</center>
</body>
</html>

Vulnerable nginx, OpenSSH (remote) and so many other vulnerable services on that IP. How is Fastpanel fellas? Is it good or is it a difficulthorse hint hint?

Should we discuss other IPs and services you have from Aeza? I do hope you are paying them well because your stupidity will come out of their nose unfortunately.

Let's do a recap of Bazaar Market/BreakingBad fails.

1) Using Cloudflare and running directly full clearnet mirror. Let's send our data to Cloudflare without PGP... what a bunch of geniuses!
2) Requiring to solve javascript captcha for accessing the website.
3) Requiring javascript for main site functionality.
4) Tracking and logging every user request/event to analytics platform.
5) Tracking and logging every user request/event to analytics platform and sending it to AWS bucket.
6) Promoting server side encryption on the server (AES 256) instead of the age old market standard of PGP.
7) Exposing network IPs to clearnet.
8) Vulnerable services running on servers allowing further exploitation and identifiction of other servers within their hosting provider (Aeza).

They have no interest in keeping users safe at any level. That was most clear to me when I saw javascript everywhere. Bazaar team, learn your history, you aren't in ancient Rome. But these people think they are building Rome. The same people who think dead drops are innovation or putting everyone at risk with taxi service (get your drugs fast delivery, nice way for police to catch everyone). You should read their posts you will have a good laugh how beginners build empires.

Bazaar don't have vulnerabilities, they don't have DDoSable services? Laughs in the audience. In all honesty English markets also claim this is the last DDoS they will ever receive or have unphishable markets both of whom are bullshit and speaks of degree of lack of understanding/skill. However the security standard is much higher than what is displayed by Bazaar.

Now https://torhoo.cc/go.php?u=TDNVdlFtbG5RbTl6YzBOb1pXWlBaa0Z5WTJobGRIbHc=# can take this information and blast it over the Internet so when someone searches Bazaar Market they will be redirected to Monkeys with Delusion of Grandeur Running Servers.

The post should serve as a reminder don't use Bazaar market if you value security and privacy and trust the superlist process of Dread created by https://torhoo.cc/go.php?u=TDNVdlNIVm5RblZ1ZEdWeQ==# and https://torhoo.cc/go.php?u=TDNVdlVHRnlhWE09# It exists for a reason to remove security risks to user who truly care about their security. It's all fun and games until people are facing 20 years in prison. Don't trust your life to ignorant admins.

However if you would like to use a market where PGP isn't recommended, you get your requests logged to Amazon buckets and your personal details saved by these morons, visit Bazaar Market they are definitely not Retaards.
/u/Yugong 📢 P
2 points
1 month ago
Shoutout to /u/Solar and /u/valor98 for discovering this several days prior /post/41586f78a2e32484e207 I only took notice of them when they started to have delusions of grandeur. I'll leave the post up regardless as the element of them claiming the Archetyp attack had been under reported (and response to their lies) but given their level of skill that can be put under question.

Someone allegedly from the market team had responded /post/41586f78a2e32484e207/#c-f7ca3bf12f8662c2d0 claiming generic response. Notably according to them it isn't a AWS bucket and a awselb/2.0 header

curl --include "r2e7xc6s6fnmn5jblnmedwtrljzfzgwp34qw45bmri5ljl3kc********onion"
HTTP/1.1 403 Forbidden
Date: Thu, 29 May 2025 **:**:** GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive
Server: awselb/2.0

<html>
<head><title>403 Forbidden</title></head>
<body>
<center><h1>403 Forbidden</h1></center>
<hr><center>nginx/1.24.0 (Ubuntu)</center>
</body>
</html>

is their own application not AWS. They're so advanced they clone AWS to fool us but forget to alter or change the server headers everywhere else. Laughter in the audience for incompetence.
/u/valor98
3 points
1 month ago
LMFAO you raped them again and brutally... Hats off 🫡💦:)
/u/smoker247365
1 points
1 month ago
Gang bang!
/u/valor98
1 points
1 month ago
The real question is was it good enough to leave em breathless, or are we still warming up? /u/Yugong ( ͡° ͜ʖ ͡°)
/u/Yugong 📢 P
1 points
1 month ago
I have bad news. Judging from how they (mis)handled the situation on their forums and the continuous gaping issues with their market it seems we have been fucking a corpse.

Shouldn't be giving them more attention at all, no credit for the Archetyp DDoS either as there is no proof it was them. They are too stupid to realize how stupid they are.
/u/SudoSubo
3 points
1 month ago
These are next level idiots - the kind evolution regrets.
/u/smoker247365
1 points
1 month ago
aws? Hole crappin shit. If i read my market uses java and aws i would bake last one before cops come. Perma ban for bazaar retaards xDD
/u/crackitup
1 points
1 month ago
yeah i read your post on bbgate and logged to dread you posted it here too. my team will limit use of bazar i didnt know their issues were bad on high level... sorry to sound stupid question but what way is there to stop java exposure to browser?

breakimg bad is good talking forum for drugs manufacture but admins inhaling fumes too much got to their head reality check... I dont like they attacked dread markets hurting sellers too our sales were affect!

I pray for peace between forums and markets war not good for buyers or sellers
/u/Yugong 📢 P
1 points
1 month ago
No way to stop the exposure. You must have it disabled to counter many of the fingerprinting techniques. When you have it disabled it gives you at least some level of defense as there are tricks with CSS too.
/u/worriedlurker
1 points
1 month ago
javascript in markets :< ban hammer time!
jewvascript* ftfy

This comment was posted automatically by a bot. All AutoModerator settings are configured by individual communities. Contact this community's Moderators to have your post approved if you believe this was in error.
/u/worriedlurker
1 points
1 month ago
useful
/u/rotSchmetterling
1 points
1 month ago
Caught that post too.
The one flapping his mouth the most was the first one to hit the floor.
/u/rotSchmetterling
1 points
1 month ago
Caught that post too.

The one flapping his mouth the most was the first one to hit the floor.
Some people are still living in the stone age.
/u/HarrierDoBois
1 points
4 days ago
Didn't have the sense to call me through the tag? Or should I show you the original screenshot where it was taken from minute to minute in a Telegram channel about Darknet?
/u/BAZAAR_ADS P
-1 points
1 month ago*
Hello everyone!

There’s so much noise about us, yet in reality, you haven’t really uncovered anything substantial.

The server you found on Shodan and Censys is not related to us, and we’re glad you’re such testers. You might want to consider reclassification.

Let me tell you a bit about our technology. The reason you see nginx, AWS, OpenResty, Apache2, and a number of other names associated with our web server is that we use a method of substitution and masking of our servers, confusing attackers by presenting ourselves as different software. We appreciate your efforts to hack our platform, but we see that your attempts are quite poor. We’re very sorry that you haven’t written or said anything meaningful.

We are Bazaar Market. we stand for simple and anonymous work.

We care about our users and sellers because we love and value them, and unlike all other markets, we have top-notch cybersecurity specialists and an excellent team.

P.S. I would like to add that no one can explain why JavaScript is bad and why it shouldn't be used. JS does not harm users if it is in the hands of professional developers. So, don't pay attention to the silly comments in this post.
/u/Yugong 📢 P
2 points
1 month ago
/u/Beelzebub /d/DreadMoments worthy response.

They don't mask any instances but specifically masked those which were exposed very convenient. They don't think javascript is bad because they don't like to read history or understand basic security fundamentals.

They are Retaard Market, they stand for simple way to get you busted. They also like to claim DDoS attacks which weren't theirs as professionals do.

This is the result IQ of a child whose mother has drank bleach all her life.

You already have a ban from https://torhoo.cc/go.php?u=TDJRdmJtVjNiV0Z5YTJWMGN3PT0=#. I have never advocated for a ban for anyone on Dread but you are a special exceptional case as you are a safety hazard for new comers who don't know better. Promoting javascript as safe and you have gem comments /post/41586f78a2e32484e207/#c-07d9061b98db6203fc


Dread uses LUA JS in its DDoS protection,

I will tag the admins and let them deal with you as they see fit as I can't read any more of your amoeba level intelligence comments. https://torhoo.cc/go.php?u=TDNVdlNIVm5RblZ1ZEdWeQ==# https://torhoo.cc/go.php?u=TDNVdlVHRnlhWE09#
/u/BAZAAR_ADS know when to accept you fucked up, before you get arrested and get users arrested too. You should not be operating a market. You can't make up technical jargon to excuse evidence like this when anyone with actual knowledge on the subject can see right through it..
/u/BAZAAR_ADS P
1 points
1 month ago
First, present your arguments instead of thoughtless words like "know when you'll get arrested." There's a saying: "Do it well, and it will be fine." That's why we are the ones to turn to, and we will remain the best and win regardless. We love and appreciate you, know that! Especially you.
But... he did, right there in the comments.
/u/BAZAAR_ADS P
1 points
1 month ago
All-knowing, because of your advice, you exposed Archetyp and he got arrested, and you still talk about safety. Just be simpler, and everything will work out; for every smart person, there is someone smarter
In what way, shape or form did I expose Archetyp? You're just proving my point.
/u/BAZAAR_ADS P
1 points
1 month ago
With their advice about moving the servers, it turns out they exposed themselves that way. It's better not to help anyone to avoid being blamed.
Lmao, the DoS attack is what would have exposed the servers, moving them would have ensured that, if so, they wouldn't be identified. He didn't move servers. From their post under his account, it seems to suggest that maybe they didn't identify them at all and rather they only gained access at the time of arrest, but we will see when any more information comes out.
/u/BAZAAR_ADS P
0 points
1 month ago
How could a DDoS expose the servers? What are you smoking to think that way?

When servers are moved and configured incorrectly, it exposes the servers, so you need to work carefully and think about what you're doing.
You're showing your lack of knowledge with every comment.

An attack at a large scale against a single service is capable of exposing the guard node on the network under most circumstances through correlation of unavailable/congested guards at the time of the attack. Bursts of attacks at specific times can make it clear which guard a hidden service is using and has likely been used on multiple occasions to deanonymize services. With Archetyp seemingly being the only known service to be under attack, specifically on April 29th and the spike of traffic on the network visibly increasing in that moment from around 2 million active users on the network, up to over 5 million, that is a huge spike and as per his words, his guard was dying. Aside from that, it is also unknown whether Law Enforcement have a way of tracking where that mass of traffic is heading on the network, but they are known to run a large amount of nodes.
/u/one1time
1 points
1 month ago
For this reason, the scene need allot different captchas so A.I can not crack them. right?
/u/BAZAAR_ADS P
-1 points
1 month ago
This concerns clear web sites, not Tor.
I recommend familiarizing yourself with the mathematical part and the concept of Proof-of-Work (PoW).
https://torhoo.cc/go.php?u=TDNVdlNIVm5RblZ1ZEdWeQ==# A ssassin
4 points
1 month ago

1
Awards Received
Diamond
1
Oh you're a lost cause.
[removed]
Please send message to ModMail - explain why your link should be approved.

This comment was posted automatically by a bot. All AutoModerator settings are configured by individual communities. Contact this community's Moderators to have your post approved if you believe this was in error.
/u/amicursed Baby Bottle is Gone
1 points
1 month ago
contact me if needed i can fix it ....
/u/BAZAAR_ADS P
1 points
1 month ago
Thank you very much, but we don't need help for now =)
jewvascript* ftfy

This comment was posted automatically by a bot. All AutoModerator settings are configured by individual communities. Contact this community's Moderators to have your post approved if you believe this was in error.
/u/4echelon
0 points
1 month ago
Denialism is intolerable to us.

Our post, which demonstrates everything you said from A to Z, was deleted by the moderators of CafeDread or Dread, it doesn't matter.

We will re-upload the deleted post to our BBGate forum and humiliate you in doing so so that you understand your true role in this "attack."

Sorry for you, but your adventure in defaming BBGate and Bazaar ends here, Yugong.

Thank you for writing this post; we see this as an opportunity to disgust anyone who tries to attack us.

Any insulting comments from you or your supporters will be ignored; we are taking this discussion seriously.
/u/Yugong 📢 P
1 points
1 month ago*
I didn't see it but it was probably deleted because it most likely was a vomit of alphabet letters like everything you write. You will see this as opportunity to disgust anyone who tries to attack you? With phrases like that I'm now convinced you are a child with special needs for whom I'll explain it once more.

You don't comprehend basic security measures or why javascript hasn't been used on the darknet for over 10 years. Denialism is intolerable to you and yet you deny all the proof and facts. Those who don't learn from history are bound to repeat it. Keep living in your head.
jewvascript* ftfy

This comment was posted automatically by a bot. All AutoModerator settings are configured by individual communities. Contact this community's Moderators to have your post approved if you believe this was in error.
jewvascript* ftfy

This comment was posted automatically by a bot. All AutoModerator settings are configured by individual communities. Contact this community's Moderators to have your post approved if you believe this was in error.
/u/BAZAAR_ADS P
0 points
1 month ago
Explain why it's not allowed
/u/[deleted]
0 points
1 month ago*
[removed]
/u/BAZAAR_ADS P
1 points
1 month ago
So it's a cult? At the server level, it's easiest to find out the user's IP, no matter where they are, whether through TOR or a regular browser, and you still talk about security, it's funny))