Short answer: Online fraud exploits trust and urgency. Typical patterns: phishing clones (fake login or download pages), social engineering (the attacker poses as support), fake software (malware-infected “Tor Browser”). Defense: primary sources, PGP verification, no time pressure.
Fraud in a Tor context follows the same psychological patterns as on the clearnet — except that .onion addresses are harder to check and trust in directories is often unearned.
Phishing clones
A phishing clone copies the design of a known page under a different address. Goal: login data, wallet seeds, or malware downloads. Especially common around Tor:
- Fake Tor Browser downloads (not from torproject.org)
- Fake onion mirrors of known services
- Imitation support pages
Defense: Only torproject.org for downloads. Addresses from primary sources, not wikis. Details: Detecting phishing.
Social engineering
Attackers contact users directly — by email, forum, or chat — and pose as support, a vendor, or a “friend.” They create urgency (“your account will be locked”) or trust (“I am from the team”).
Defense: Legitimate organizations do not ask for passwords or seeds in a random message. Do not accept time pressure.
Fake software and malware
Malware is packaged as a “safer Tor Browser,” “VPN bundle,” or “wallet tool.” A compromised device makes every network — including Tor — worthless.
Defense: Check installer signatures (the Tor Project publishes PGP signatures). Official sources only. At high risk: Tails or Whonix.
Exit scams (context)
Exit scams — operators disappear with deposited funds — are documented in the context of online marketplaces. TorBible lists no markets and gives no buying instructions. For general understanding: when a service centrally holds trust and payments, the structural risk of an exit scam is present — independent of the network.
Checklist
- Download only from torproject.org — verify the signature
- .onion addresses only from primary sources
- No personal data to strangers
- HTTPS on every page — an exit can read unencrypted traffic
- Know your threat model: OPSEC fundamentals
- Do not let the device be compromised — OS updates, no dubious installers