GENUINE // CLONE // SIGNAL

WeTheNorth vs the Clones

This board does one job. It helps you decide whether the WeTheNorth address in front of you is the real one or a copy built to pass for it. WeTheNorth, written we the north and shortened to wtn, is a Canadian darknet marketplace. It is not the basketball chant. Match the whole onion, check the signature, and drop anything that fails either test.

1Genuine onion
56Chars to match
PGPPending Phase 0
TorOnion only
VERIFIED ONION ADDRESSChecking
http://hn2paw7hljeihrk7qm2toniay5bb4cfz46cav5iywnsv64klm45mypqd.onion

One confirmed reference address. The pill is a probe reading, never a guarantee. Copy it, compare all 56 characters, verify the key, then open it only in Tor Browser.

See the diff ↓Why the key wins ↓Compare every character before you connect.
VERIFIED SOURCEFingerprint pending (Phase 0)Trust the key, not the domain name. A clone can rent a tidy domain and copy every pixel, but it cannot sign with the operator key. That signing key lands in Phase 0.
WHAT THIS IS

What WeTheNorth is, and what it is not

WeTheNorth is a Canadian darknet marketplace that runs as a Tor hidden service. There is no clearnet storefront and no phone app. The name happens to echo a Toronto basketball slogan, yet the two share nothing beyond the words. On this board, we the north, wtn, and wethenorth all point at a single onion market.

Honest limit: we publish the reference and the checks. We do not run the market, we cannot see your account, and we never promise a mirror is up at the second you read this.

GENUINE vs CLONEdiff view

Read it like a diff

A clone rarely looks wrong. It usually differs by one character buried in the middle of the string, or by the absence of a signature you never thought to check. Lay the real address next to the one you were sent and the gap shows up fast.

Same-looking, one character apart. The genuine string on top, a clone on the bottom:

+

Genuine WeTheNorth

The full 56-character v3 onion, letter for letter. A signature that matches the published fingerprint. A row on the signed list. All three, or you stop.

Swapped character

One letter changed where the eye skips, often past the tenth character. The page still loads and still looks right, which is exactly the trap.

Unsigned paste

An address lifted from a forum reply or a search result, with no signature standing behind it. Popular is not the same as verified.

Login-first clone

A page that wants your wtn login before you ever reach the onion. The real login only exists inside the market, on Tor.

HOW THE CHECK RUNSdetector

How a link gets checked before you trust it

Every candidate address takes the same short path. It is not enough that a mirror answers; it has to survive a character compare and a signature check. Here is where each test happens.

WeTheNorth clone detection flowAddress inwhat you holdCompare56 chars + keyVerdictgenuine or clone
1 · Take the addressWhatever you were handed, from a message, a post, or a search hit. Nothing is trusted yet.
2 · Compare itEvery character is lined up against the signed canon, and the signature is checked against the fingerprint.
3 · Read the verdictA full match on both is genuine. Any mismatch, and it is treated as a clone and dropped.
THREE SIGNALSno shortcuts

Three signals, and no shortcuts

Full address

All 56 characters match, not just the first handful. Clones bank on you checking the start and stopping.

Matching signature

The PGP fingerprint lines up with the published one. A copied look cannot forge a signature.

On the signed list

The address sits in the signed directory, not in a forum reply or a paste someone swears by.

Honest status

A marker reads Checking until a probe confirms it. We never hard-code a green light we cannot stand behind.

MIRRORSupdated 2026-08-21

The one verified WeTheNorth mirror

WeTheNorth runs a single confirmed onion right now. One row, on purpose.
RoleOnion URLStatusAction
Primaryhttp://hn2paw7hljeihrk7qm2toniay5bb4cfz46cav5iywnsv64klm45mypqd.onionChecking
Failoveradditional signed mirrors are being provisionedPendingn/a

Last checked . When a second mirror is signed, it appears here and nowhere else.

PGP KEYtrust layer

Verify the address before you connect

Canon key fingerprint:pending (Phase 0)

Honest limit: the signing key is not published yet. Until it lands in Phase 0, this page cannot prove the address by signature, so compare all 56 characters by eye and cross-check the canon first.

Show PGP key and verification command
-----BEGIN PGP PUBLIC KEY BLOCK-----
(pending publication, offline key, Phase 0)
-----END PGP PUBLIC KEY BLOCK-----
gpg --import canon-pub.asc
gpg --verify mirrors.json.sig mirrors.json
ACCESS PATHsafest route

How to reach the genuine WeTheNorth market

  1. Open Tails, or set Tor Browser to the Safest level.
  2. Import the published WeTheNorth key before you pick a link.
  3. Compare the signed address and read the fingerprint.
  4. Copy the exact onion from the verified box above.
  5. Paste it into Tor. Never follow a search result.
FAQplain answers

Genuine vs clone questions

How do I tell a genuine WeTheNorth onion from a clone?

Match every one of the 56 characters, confirm the PGP signature against the published fingerprint, and find the address on the signed list. A familiar layout proves nothing.

Is WeTheNorth the same as the Toronto Raptors slogan?

No. Here WeTheNorth is a Canadian darknet marketplace. The basketball chant shares the words by coincidence and does not belong on this board.

Are nexus, torzon or vortex WeTheNorth mirrors?

No. Those are separate markets. Any page that dresses one of them up as a WeTheNorth mirror is a clone.

Why does the status read Checking?

Availability changes hour to hour. Checking is an honest probe state, not a promise that the address is up or safe.

Is WeTheNorth up or down right now?

The marker on the address above shows a live probe. It moves through the day, so read the pill, then confirm the signature before you rely on it.

A clone loaded fine for me. Does that make it safe?

No. A clone can load, look correct, and still harvest your login. Only an address that both loads and matches the signature is safe.