Link directories and dark.fail: what verified onion lists actually prove
When Empire Market went dark in August 2020, an estimated $30 million in escrowed bitcoin vanished with it, and users faced a flood of conflicting links claiming to be the real site. Services like dark.fail exist for exactly that moment. They are not search engines; they are curated address books with a cryptographic backbone.
A phishing economy built on downtime
Every hour a major onion service stays offline, clones multiply. dark.fail has estimated that phishers running fake mirrors of a large market can collect up to 100,000 euros per hour while the official site is unreachable, according to Vice's coverage of the Empire collapse. The stolen deposits then fund more attacks. It is a self-sustaining cycle. The scams are rarely crude. During Empire's final weeks, fraudsters posted warnings about phishing that linked to phishing sites, complete with working captchas and login pages. Only the PGP signature gave them away, as DarknetLive documented at the time. Visual inspection is worthless here.What dark.fail actually does
dark.fail maintains a short, manually vetted list of official .onion addresses for major services, alongside uptime statistics. Its operators stay in contact with service administrators, so when a site rotates addresses to shake off a DDoS attack, the list updates quickly. Non-commercial design matters too: the site carries no affiliate links, which became a fatal conflict of interest for its predecessor DeepDotWeb when US prosecutors charged its founders over referral commissions in 2019. Crucially, the project also publishes standards rather than just links. Its Onion Mirror Guidelines specify that participating sites must host a /pgp.txt key list, a PGP-signed /mirrors.txt file, and a /canary.txt statement refreshed every 14 days. Sites that do not comply get marked unverified and sink down the list.The PGP signing model, briefly
The core mechanism is simple asymmetric cryptography. A service operator signs a message containing all official mirrors with their private PGP key. Anyone holding the operator's public key can confirm the signature, and any tampering with even one character breaks it. An attacker would need the private key itself to forge this proof, and anyone holding that key effectively owns the service anyway. dark.fail summarizes it bluntly:"The only way to know if a site is authentic is to PGP verify its signed URL proof."The site ships its own PGP verification tool for pasting in signed messages, though it explicitly encourages users to learn command-line verification independently rather than trusting any web tool blindly.
The limits nobody should forget
Directories have real weaknesses, and pretending otherwise invites trouble:- They are single points of failure. A compromised directory could swap every listed link for phishing ones.
- They are prime DDoS extortion targets precisely because users depend on them, which is why dark.fail itself goes offline periodically.
- Ownership changes happen quietly. DarknetLive was later revealed to have been acquired by the Incognito Market admin shortly before that market's exit scam and his arrest.
- A verified address proves authenticity, not honesty. Empire Market was correctly listed until the day its admins allegedly disappeared with user funds.