Knowledge Base

Critical operational details regarding market security, financial protocols, and vendor standards. Read carefully before transacting.

Last Updated: Nov 14, 2024 Version: 2.4.1

Platform & Access

DrugHub Market is a next-generation darknet marketplace architected for maximum operational security. Established in August 2023, we facilitate the anonymous exchange of goods using Monero (XMR) and enforce strict cryptographic standards.

Our platform features passwordless PGP authentication, a 2/3 multisig escrow system, and a decentralized mirror network to resist censorship and DDoS attacks. We maintain a zero-tolerance policy for scams, ensuring all vendors undergo rigorous vetting including proof of inventory and sample verification.

Access requires the Tor Browser. For optimal security, disable JavaScript by setting your security slider to "Safest". This mitigates browser-based exploits that could compromise your anonymity.

Always verify the .onion address against our PGP-signed message. The primary address is drughub33kngovqzkhf6gqjyudzak44gcnfrrh4ukllicsuduraw3did.onion. Once registered, bookmark your unique Private Mirror found in the dashboard. Private mirrors are isolated from the main network load, offering faster speeds and protection against DDoS attacks.

The Tor network is subject to latency and occasional instability. Additionally, marketplaces are frequent targets of Distributed Denial of Service (DDoS) attacks. If the main URL is unreachable, please utilize one of our rotational mirrors listed on the /links page.

We implement a proof-of-work captcha system to mitigate these attacks, but downtime can occur. Check established darknet forums like Dread for official status updates signed with our admin PGP key.

Cryptography & Security

We do not store user passwords in our database, eliminating the risk of credential dumps if the server is compromised. Instead, we use a challenge-response mechanism.

To log in, the server presents a random message encrypted with your public PGP key. You must decrypt this message using your private key (which never leaves your device) and paste the result to verify your identity. This ensures that only the holder of the private key can access the account.

Verification is non-negotiable for security. Import the DrugHub Admin Public Key into your PGP software (GPG, Kleopatra, etc.). When visiting a mirror, look for the signed message usually found in the footer or /verify page.

Verify the signature against our public key. A valid signature confirms that the site is authentic and not a MITM (Man-in-the-Middle) phishing proxy. Never enter credentials or deposit funds on a mirror that fails PGP verification.

While DrugHub encrypts database entries, client-side encryption is the only way to ensure true privacy. You must encrypt your shipping details using the Vendor's Public PGP Key before submitting the order.

This ensures that only the vendor can read your address. Even if the marketplace servers were seized by law enforcement, your shipping information would remain an unreadable block of encrypted text.

Financial Operations

Bitcoin and other public ledger cryptocurrencies are transparent; every transaction is traceable by chain analysis firms. Monero is the only major cryptocurrency that is private by default.

XMR utilizes ring signatures to hide the sender, stealth addresses to hide the receiver, and RingCT to hide the transaction amount. We prioritize user safety over convenience, and thus will never support transparent chains like BTC.

Our escrow system uses a 2-of-3 multi-signature protocol. Three keys are generated for each order: one for the buyer, one for the vendor, and one for the market.

  • Normal Flow: Buyer receives goods -> Buyer & Vendor sign -> Funds released to Vendor.
  • Dispute Flow: Issue arises -> Admin investigates -> Admin signs with winning party -> Funds released to winner.

This structure ensures no single party can steal the funds, preventing market exit scams and vendor theft.

Monero transactions require 10 confirmations on the blockchain before they are credited to your order balance. This typically takes 20-30 minutes. Do not panic if it doesn't appear instantly.

If 60 minutes have passed, check the Transaction ID (TXID) on a block explorer (like xmrchain.net) to verify it has been mined. If confirmed on-chain but not on DrugHub, open a support ticket with your TXID and the deposit address used.

Yes. To minimize risk, we encourage a "pay-per-order" workflow. When you checkout, a unique subaddress is generated specifically for that order. You send the exact amount required.

Once confirmed, the order status updates to "Paid" automatically. We advise against keeping large balances in your market wallet; treat the market as a payment processor, not a bank.

Vendors & Orders

Vendor status is a privilege, not a right. Apply via the "Join Vendor Program" link in your dashboard. Requirements include:

  • Payment of a Vendor Bond (tiered from 1.5 to 5 XMR based on category).
  • Proven track record on other established markets (Recon/Dread verification).
  • Submission of product samples for quality testing by our verification team.

Scammers are banned immediately and their bonds are forfeited to the community insurance fund.

If an order fails to arrive or is significantly different from the description, you must open a dispute before the auto-finalize timer expires (usually 14 days).

During a dispute, a moderator will review chat logs and evidence. Vendors are required to provide proof of shipping. If the vendor is at fault, the multisig funds are signed over to the buyer's refund address. Always set a refund address in your settings before ordering.

Support is available 24/7 via the ticketing system in your dashboard. We do not use email or any clear-net communication channels (Telegram, Discord, etc.) for market support.

When opening a ticket regarding a transaction, please include the Order ID and TXID. Please allow up to 24 hours for a response due to high volume. Messages are encrypted by default.