Verifying Mars Market with PGP
The single most common way a Mars visitor loses money is not a server breach. It is a near identical onion standing up a copy of the storefront to harvest a passphrase or a deposit. The defence is a two minute check: match the address you are about to use against the signed canary, and compare the PGP fingerprint to the one you pinned the first time.
This page walks through the whole process, where to get the key, how to read the signature, and what a lookalike looks like when it forgets to be perfect.
The canary and the fingerprint
The operator signs a short message with its PGP key. That message, the canary, lists every live onion address. A mirror that is real will appear in that signed list. A clone will not, because the attacker does not hold the private half of the key that signed it.
The fingerprint is a compact form of the public key, printed in the storefront footer. Verify it once from a source you trust, write it down, and keep it. From then on, any page that shows the same fingerprint is serving the same key, and a lookalike cannot reproduce it without also holding the private key.
The current fingerprint is 9F4C 2A81 77DE 0B3C 55A9 1E6F 8D24 C7B0 3A19 6E5D. It has not rotated since launch, which is deliberate. A rotation is announced with a signed note, so an unexpected change is a reason to stop and check, not to push through.
Reading the signature
Export the signature from the canary and check it against your imported copy of the public key. If it verifies, the list is genuine and the address you want is on it. If it fails, the canary was not signed by the operator you trust and the list is worthless.
You do not need to be a cryptographer for this. Import the key, run the check, read the result. The cost of skipping it is the entire deposit, which makes the two minutes worthwhile every single time.
Spotting a lookalike
Lookalikes usually differ by one or two characters in the middle of the address, where the eye is least likely to catch the swap. The genuine storefront also serves a static header that has not changed in a long time, and it signs every deposit address it issues. A clone copied from a screenshot rarely matches the spacing exactly, and it cannot sign a deposit address without the private key.
If anything looks subtly off, an unfamiliar layout, a missing footer key, a request to re enter your mnemonic on login, close the tab, fetch a fresh address from the mirror page, and try again from a clean circuit. The genuine storefront is patient. An attacker is patient too, until the moment you submit the credential.
Frequently Asked Questions
Where do I get the PGP key?
From the storefront footer on any verified mirror. Import it once, pin the fingerprint, and keep it offline.
What is a canary?
A short message signed by the operator that lists the live onion addresses. If your address is not in the signed canary, it is not real.
Do I need to verify every visit?
Not every visit, but the first time you use a new address, and any time the set rotates. The check is cheap and the mistake is expensive.