Nexus Market Bureau est. 2026
Reference

Full reader checklist, first order to withdrawal

Everything the Bureau recommends, in the order you would do it.

By Editor · 16 July 2026 · 4 min

Before touching the storefront

  • Tor Browser installed from torproject.org with signature verified
  • Security slider set to Safest
  • Browser window not resized
  • No extensions installed
  • GnuPG installed on your operating system
  • Operator PGP key fetched from at least two independent sources and cross-checked, then imported into a fresh keyring
  • Current signed rotation verified against the operator key
  • Mirror reference page bookmarked in Tor Browser

First login

  • Copy mirror from the reference bookmark
  • Paste into Tor Browser
  • Wait through the anti-DDoS queue
  • Read the captcha string against the URL bar
  • Solve captcha, log in

Registration

  • Fresh username, never used elsewhere
  • Strong password, saved in encrypted local password manager only
  • Mnemonic seed written on paper, stored in exclusively-yours location
  • Personal PGP key uploaded to profile

Wallet

  • Feather Wallet or Cake Wallet installed for Monero
  • Monero acquired from non-KYC source (RoboSats, Bisq, Cake swap)
  • Deposit amount sized to first order plus small fee buffer, not more

Vendor selection

  • Dispute ratio under 5 percent
  • Finalisation ratio over 95 percent
  • Last twenty reviews consistent
  • PGP key published on vendor page
  • Reasonable average shipping time
  • Not FE-only

First order

  • Small quantity, cheap product, standard shipping, standard escrow
  • Address encrypted to vendor PGP key before sending
  • Polite factual messages only

Delivery

  • Photo of package on arrival
  • Check item against listing
  • Mark received when everything matches, or open dispute with clear evidence if not

After release

  • Withdraw remaining balance to a wallet under your own keys
  • Do not leave balance on the storefront
  • Close Tor Browser

Why the order is not arbitrary

Each step assumes the one before it. Verifying a download obtained from the wrong place proves nothing useful. Setting a security level inside a browser that was modified before installation protects nothing. Saving addresses is only worth doing in a browser you can trust. Working down the list produces a setup that holds, and picking the interesting items produces one that only looks like it does.

The two items that carry the most weight

Confirming the address on the login screen before typing, and using a password that exists nowhere else. The first is the only defence against a page that copies the storefront perfectly. The second is what stops a breach at some unrelated site from becoming a problem here. Everything else on the list prevents less than either of those.

What the checklist does not claim

That completing it makes anything safe. It removes specific, named ways a setup fails. It does not change what a marketplace is, and every one that ever ended was operating normally the day before it did, which is why the item about not leaving a balance outside an open order is on the list at all.