Why clones work
Onion-service hostnames are difficult to memorize and easy to truncate visually. A copied website can therefore look exact while using a different destination. The attacker may reproduce logos, menus, status messages, reviews, and even old announcements.
A clone often succeeds before the page loads: the reader accepts the address because it appeared in a familiar directory or search result.
Common clone patterns
Copied design, changed address
The entire site is copied, but the onion hostname differs. The clone may update payment details, login forms, or download links while leaving the rest unchanged.
“Emergency mirror” claims
A page announces that the original service was seized, attacked, or moved and instructs users to switch immediately. The claim may be real, false, or impossible to verify.
Paid or manipulated directory placement
A directory may place a link prominently because someone paid for inclusion, supplied a reciprocal link, or created many favorable reports. A high position is not evidence of ownership.
Lookalike clearnet pages
A normal domain can imitate the official site and publish a false onion address. Check the history and identity of the clearnet domain, not only its design.
Search-result substitution
A snippet or advertisement can resemble the expected result. Open the organization’s known domain manually or use a trusted bookmark whose origin you documented.
Warning signs
- The service asks you to ignore an official clearnet announcement.
- The displayed address and the link target differ.
- The page tells you to disable Tor Browser protections.
- A deposit is required before any support response.
- A “mirror checker” recommends only one commercial destination.
- The directory cannot explain where the address came from.
- Every positive review repeats identical wording.
- The page claims permanent safety or guaranteed legitimacy.
A verification response
When you suspect a clone:
- Stop before entering credentials or making a transaction.
- Preserve the claimed address as text.
- Find the operator’s established first-party source.
- Compare the full hostname.
- Check whether the operator published a warning.
- Record the source and date.
- Report the discrepancy to the organization and directory.
Do not contact the suspected clone to ask whether it is genuine.
Directory responsibility
A responsible directory should not simply remove a false link without documenting the correction. It should record:
- what changed;
- when the incorrect address was first seen;
- how the correct address was established;
- whether other entries were affected;
- whether paid placement or automation contributed;
- what review process will prevent recurrence.
The corrections policy describes how this publication handles such reports.
Sources and further reading
- Onion services in Tor Browser
- Tor Browser fingerprinting protections
- Report a SecureDrop Directory error