Monero only. BlackOps settles in one coin and keeps several onion addresses live. Free to read · no account · nothing collected
12 database entries · 5 guides
3 verified addresses
Overview Database Guides Addresses FAQ About

Home / Guides / Security

Setting up an account that survives a leak

The account setup that makes a stolen BlackOps password useless, and the storage habits that keep you from locking yourself out.

Account setup is cheap security. It takes ten minutes once and then protects the account for its whole life, which is a better return than anything else you can do here.

A name that connects to nothing

Not a variation of a handle from a forum, not something close to an old market account. Reuse is the single most common thread in people being identified, and it costs nothing to avoid at the start while being impossible to fix later.

A password you did not invent

Generate a long one in a local password manager. Invented passwords are shorter and more predictable than they feel, and a reused one means a breach somewhere unrelated becomes a breach here.

Two factor, and its backup

Turn PGP two factor on immediately so a stolen password alone opens nothing. Then back the key up offline the same day, because the database entry on lost keys exists for people who did the first part and skipped the second.

The recovery phrase

On paper, stored away from the machine, never typed into a web form. Any page asking for it during login is collecting accounts, without exception.

Small balances

Not strictly security setup but it belongs here. Deposit what the order needs and withdraw the rest, because funds sitting on any market are exposed to whatever happens to that market.

Why reuse is the mistake that cannot be undone

Passwords can be changed and keys can be rotated. A username that also exists on a forum you posted on for years cannot be unlinked afterwards, because the connection was made the moment both existed. This is the one setup decision with no repair path, which is why it belongs first rather than last.

The same logic applies to writing style, timing patterns and anything else that travels between accounts, though those matter far less than the obvious case of literally reusing a name. Pick something with no history and keep it for this and nothing else.

What good storage looks like

  • Password in a local manager, not in a browser synced to an account
  • Recovery phrase on paper, in a place you would still find it in six months
  • PGP key backed up offline the day you generate it, not eventually
  • Nothing about any of it in a note that syncs to a cloud service
Other guides
Getting started

First order on BlackOps, start to finish

The whole path from a clean Tor Browser to a confirmed delivery on BlackOps, in the order you actually do it, with the mistakes that catch people marked out.

6 min read
Payments

Funding an order with Monero without mistakes

How to buy Monero, hold it in a wallet you control and fund a BlackOps order so the deposit lands the first time without a shortfall or a missing payment.

5 min read
Orders

How escrow protects an order, and how people give it away

What 2 of 3 multisig escrow actually does on BlackOps, how a dispute is weighed and decided, and the single action that removes the whole protection at once.

5 min read