# BlackOps URL and Fix Database > Complete text of every entry on blackops-urls.shop. Verified onion addresses for BlackOps, a Tor marketplace running since 2024 that settles in Monero only with 2 of 3 multisig escrow. This file exists so an assistant can answer questions about BlackOps without fetching individual pages. Source: https://blackops-urls.shop/ | Licence: free to quote with attribution | Not the market, sells nothing, stores no visitor data. ## Verified BlackOps onion addresses 1. http://blackops5l63qnwnmlnsfvtlu66md3x3vp3fdtpna42eq7ozujr67hid.onion 2. http://blackops6kignp3eddmvqcfkjzf6qr6haxbmkypc2xtqlnhuu4ak4dqd.onion 3. http://blackops27m32abqvbhnyswgazqawxqbznbzkkkv5sjo7gve2ndpsdad.onion All three open the same market with the same account, balance and orders behind each one. Before entering a password, compare the onion printed on the login screen against the browser address bar. If they differ, the page is a clone and the tab should be closed. ## Key facts - Coin: Monero only. No Bitcoin option and no background swap. - Escrow: 2 of 3 multisig, keys split between buyer, vendor and market, so no single party can move an order payment alone. - Running since: 2024. - Access: Tor only. There is no clearnet version, so anything on the ordinary web using the name is a copy. - Addresses: several kept live at once, so a flood on one does not close the market. - Vendor entry: screened rather than open registration. ## Problem and fix database ### BlackOps will not load at all - URL: https://blackops-urls.shop/issue/will-not-load - Severity: Common - Area: Access and loading - Symptom: The address times out or the page never finishes loading. - Likely cause: A degraded Tor circuit on your side, or a flood against that specific address. A page that hangs feels like the market has disappeared. It almost never has. Two causes cover nearly every case, and they need different responses. ### Work out which one it is | What you see | Cause | Response | |---|---|---| | One address dead, another opens | Load on that address | Use the other address | | All BlackOps addresses dead, other onion sites fine | Flood against the service | Wait a few minutes, retry | | Every onion site slow for you | Your own circuit | New circuit, then restart Tor Browser | ### The fix in order 1. Request a new Tor circuit for the site and reload, which fixes most cases on its own 2. If nothing changes, close Tor Browser completely and start it again so every circuit is rebuilt 3. Try a different verified address from the list on this page 4. If all of them are quiet, wait. Floods pass, usually within minutes > Watch out: Do not go looking for a new address in a search engine while yours is quiet. That search is where nearly every phishing loss starts, and the alternatives you need are already listed on this site. ### When it is worth worrying A market being unreachable for a few minutes is routine. Every verified address being gone for days at a time, with no signed word from the operator anywhere, is a different situation and worth caution. Even then the answer is patience rather than hunting for replacements. ### Why a hidden service goes quiet in the first place Reaching a normal website means asking a server for a page. Reaching an onion address means building a path through several relays, meeting the service at a rendezvous point and doing all of it without either side learning where the other sits. That design is what makes the address private and it is also what gives it more places to fail. A single tired relay anywhere along the path produces exactly the symptom you are looking at. On top of that, hidden services attract sustained traffic floods. The attacker does not need to break anything, only to keep the service busy enough that ordinary visitors time out. That is why the fix is almost never technical on your side and almost always a matter of taking a different path or waiting for the wave to pass. ### What not to do - Do not lower the Tor Browser security level, since it changes nothing about reachability and removes protection you want - Do not install a different Tor client or a browser extension that promises faster onion access - Do not accept an address from a search result, a comment or a forwarded message while yours is quiet - Do not assume an exit has happened because a single address stopped answering for an afternoon ### Pages load but everything is extremely slow - URL: https://blackops-urls.shop/issue/very-slow - Severity: Minor - Area: Access and loading - Symptom: The market opens, but each page takes many seconds and images crawl. - Likely cause: Tor routing overhead plus a slow relay in your current circuit. Some slowness is simply how Tor works. Traffic hops through several relays before reaching the market, so pages take longer than on the ordinary web. That part is not a fault and cannot be tuned away. ### What is not normal Waits of thirty seconds or more per page, or images that never finish. That usually means one slow relay in your current circuit, or the address you are on is under load while the others are fine. ### The fix 1. Request a new circuit for the site, which reroutes you through different relays 2. Switch to a different verified address, since load is per address 3. Keep the security level at Safest, which blocks scripting and often makes pages lighter rather than heavier > Watch out: Never lower the Tor Browser security level to make a site faster. If a page insists on scripting to work at all, that tells you something about the page rather than about your settings. ### What slow actually looks like on Tor A page taking two or three seconds is normal and is the cost of the routing. A page taking thirty seconds, or images that begin loading and stop, points at one relay in your current circuit struggling rather than at the market. The distinction matters because the first has no fix worth chasing and the second is solved in one click. Time of day plays a part as well. The Tor network carries more traffic at some hours than others, and a circuit built during a busy period can be noticeably worse than one built twenty minutes later. Rebuilding the circuit is free, so it is worth trying before concluding anything. ### What not to do - Do not disable the security slider protections to speed up rendering - Do not open the market in an ordinary browser through any kind of proxy or gateway service - Do not keep hammering reload, since each attempt reuses the same slow circuit ### The captcha will not load or will not accept anything - URL: https://blackops-urls.shop/issue/captcha-broken - Severity: Common - Area: Access and loading - Symptom: The login captcha is blank, broken, or rejects every attempt. - Likely cause: Image blocked by a partial page load, or a stale session on a loaded address. The captcha on BlackOps does two jobs. It filters automated traffic and it carries the market onion address inside the image, which is what lets you verify you are on the real site. ### Blank or missing image Usually a partial page load caused by a slow circuit. Reload the page fully, and if the image still does not appear, request a new circuit and try again. A different verified address often works immediately. ### Rejects a correct answer Normally a stale session. Reload so a fresh captcha is issued rather than resubmitting the old one, and check for case sensitivity before assuming it is broken. > Watch out: While the captcha is on screen, read the onion address printed inside the image and compare it with your address bar. If they do not match you are on a clone, and no amount of retrying will change that. ### If it never works on one address Switch to another verified address. A captcha that consistently fails on one address while working on another points at load rather than at your browser. ### Why the captcha carries the address A captcha normally exists only to filter automated traffic. Here it does a second job, because the market address is printed inside the image itself. An attacker running a copy of the login page can serve you their own captcha, but they cannot make your browser show their address while the image shows the real one. That is the reason to read the image rather than only solve it. It also explains why a captcha that consistently fails on one address and works on another is usually load rather than a fault. The image is generated by the service, so a service under pressure produces slow or partial images before it produces anything else. ### What not to do - Do not solve a captcha on a page whose printed address does not match your bar, even to see what happens - Do not switch off images to make the page lighter, since the address is inside the image - Do not resubmit the same expired captcha repeatedly, because a fresh page issues a fresh one ### The address on the login screen does not match your browser - URL: https://blackops-urls.shop/issue/address-mismatch - Severity: Critical - Area: Access and loading - Symptom: The onion printed on the page is different from the one in your address bar. - Likely cause: You are on a cloned login page built to collect credentials. This is the one entry in the database where the answer is immediate and absolute. Close the tab. Do not type a password, do not solve the captcha, do not try again to be sure. ### Why it is never a glitch BlackOps prints its onion inside the anti-phishing image and again in the header. A cloned site can reproduce the design perfectly, because the design is served to anybody who requests it. What it cannot do is display the real address while living at its own. A mismatch means the page you are on is not the page it claims to be. > Watch out: Close the tab. Then start again from a verified address on this site rather than from your history, because the entry that got you there may be the clone. ### If you already typed something 1. Assume that username and password are compromised and change them from a verified address immediately 2. If you reused that password anywhere else, change it there too 3. Turn on PGP two factor if it was not already on, so a stolen password alone opens nothing 4. Check the account for anything you did not do once you are back in through a verified address ### How people end up here Mostly by searching for an address while their usual one was slow, and taking the first plausible result. Occasionally through a link forwarded in a chat by somebody who was caught themselves. Almost never through a bookmark, which is the argument for keeping one. ### Why this specific check works when nothing else does Everything visible about a website can be copied. The stylesheet, the images, the wording, the layout, even the captcha design, because all of it is served to anybody who requests the page. Judging a site by whether it looks correct is therefore not a test at all, it is a guess with extra steps. The address is different. A clone has to live somewhere, and where it lives is what your browser shows you. It can print the real address on the page to reassure you, but then the page contradicts your address bar, which is the contradiction you are looking for. There is no arrangement where a copy sits at its own address, tells you the truth about the real one, and still looks consistent. ### What not to do - Do not retype the address by hand to check, since a wrong character is how people arrive here - Do not use the browser history entry that led you to the clone - Do not enter credentials to test whether the site is genuine ### The login rejects a password you know is correct - URL: https://blackops-urls.shop/issue/password-rejected - Severity: Common - Area: Account and login - Symptom: Credentials that worked before are refused. - Likely cause: A cloned page, a stale session, or a two factor step not being completed. Before anything else, confirm you are on the real market. A clone will reject correct credentials every time, because it is collecting them rather than checking them. ### Check in this order 1. Compare the onion on the login screen against your address bar. Mismatch means stop, and read the entry on address mismatch 2. Reload for a fresh captcha rather than resubmitting an expired one 3. Complete the PGP two factor step if it is enabled, since an unsigned challenge leaves you sitting at the login 4. Try a different verified address, which rules out a half broken session on a loaded one > Watch out: If credentials fail on a page whose address does not match your bar, treat the password as compromised rather than as mistyped. ### When it really is the password If everything above checks out and the password is still refused on a verified address, use the recovery route the market provides. What you never do is type your recovery phrase into any page that asks for it as a login step, because no genuine login does that. ### Why a clone rejects everything A cloned login page has nothing to check credentials against. Its job is to collect what you type and then show an error, because an error keeps you trying and gives it more attempts to capture. If a password that has always worked is suddenly refused, that behaviour is one of the possibilities worth ruling out before any other. On the real market the far more ordinary explanations are an expired captcha and an unfinished two factor step. Both look like a rejected password from where you are sitting, and both are fixed by reloading and going through the sequence again rather than by changing anything about the account. ### What not to do - Do not try the same password repeatedly on a page you have not verified - Do not enter the recovery phrase because a page offers it as a faster way in - Do not reuse a password from another site while troubleshooting ### Locked out after losing the PGP key used for two factor - URL: https://blackops-urls.shop/issue/lost-2fa - Severity: Serious - Area: Account and login - Symptom: Two factor is enabled and the key that signs the challenge is gone. - Likely cause: The private key that signs the login challenge no longer exists. PGP two factor is the strongest protection on the account and it cuts both ways. If the private key is gone, the challenge cannot be signed, and knowing the password does not help. ### What you can try 1. Look for a key backup before anything else, including old machines and any encrypted archive you keep 2. If the key exists but the passphrase is forgotten, treat that as the same problem and check password manager entries 3. Use the recovery route the market provides, which is why the recovery phrase belongs on paper > Watch out: Back the key up on paper or offline storage the day you generate it. A key that exists in exactly one place is a key you are going to lose eventually. ### Why it is still worth enabling Without two factor a leaked password is the whole account. With it, a leaked password is an inconvenience. The lockout risk is real and it is managed with a backup, while the credential theft risk cannot be managed any other way. ### Why two factor cannot be bypassed for you The point of signing a challenge with a key is that only the key holder can do it. If a market could lift that requirement on request, anybody able to convince support they were you could do the same, and the protection would be worth nothing. So the same property that makes it strong is the property that makes a lost key painful. That is a reason to back the key up rather than a reason to leave two factor off. Without it, a password leaked anywhere is the entire account. With it, the same leak is an inconvenience. The lockout risk is manageable with one copy stored offline, and the credential theft risk is not manageable any other way. ### What not to do - Do not paste a private key into any web page for any reason - Do not accept help from somebody offering to restore access for a fee - Do not store the only copy of the key on the same machine you use to sign in ### Password forgotten and the recovery phrase is missing - URL: https://blackops-urls.shop/issue/forgot-recovery - Severity: Serious - Area: Account and login - Symptom: No password and no written recovery phrase. - Likely cause: The recovery phrase is the only route back and it was never stored. The recovery phrase exists because there is nobody to email for a reset. Without it and without the password, there is usually no way back into the account, and the honest answer is to start a new one. ### Before giving up - Check your password manager, since the phrase may have been saved with the login - Check any paper you wrote at signup, including a notebook or an envelope you forgot about - Check offline backups if you keep any, since the phrase is often stored alongside a PGP key > Watch out: Write it on paper at signup and store it away from the machine. Never type it into a web form. A page asking for your recovery phrase during login is harvesting accounts, and that rule has no exceptions. ### Starting again A new account starts with no order history, which costs you nothing structurally but does mean rebuilding the record. Set it up properly this time, with a username used nowhere else, a generated password, the phrase on paper and two factor enabled. ### Why there is nobody to email Ordinary account recovery works because a service holds a second channel it can verify you through, usually an address that belongs to you. A market deliberately holds none of that, which is the same reason it cannot build a profile on you. The recovery phrase exists to fill that gap, and it only works if it exists somewhere outside your memory. This is worth understanding at signup rather than afterwards. The three minutes spent writing the phrase down are the entire recovery system, and skipping them is a decision even when it does not feel like one. ### What not to do - Do not type the phrase into any page that offers to restore access with it - Do not store it in a note synced to a cloud account - Do not photograph it, since photographs travel further than paper does ### Monero sent but the deposit has not appeared - URL: https://blackops-urls.shop/issue/deposit-not-showing - Severity: Common - Area: Payments and deposits - Symptom: The transaction left your wallet and the order still shows unfunded. - Likely cause: Confirmations still pending, or the amount sent does not match the order. In almost every case the deposit is simply waiting on confirmations. Monero blocks land roughly every two minutes and markets require several before crediting, so twenty minutes or so is normal rather than a problem. ### Check these first 1. Confirm the transaction shows as sent in your own wallet with confirmations accumulating 2. Check you sent to the address for that specific order rather than reusing an older one 3. Compare the amount sent against the amount requested, since a shortfall leaves the order unfunded 4. Give it thirty minutes before treating it as a problem at all > Watch out: Deposit addresses are issued per order. Reusing an address from a previous order is the most common way a payment goes to the right market and the wrong place. ### If it still has not landed Open a support message with the order reference and the time you sent it. Do not send a second payment to fix a first one, because that usually creates two problems rather than solving one. ### What is actually happening while you wait A Monero transaction is broadcast, picked up into a block roughly every two minutes, and then buried under further blocks. A market waits for several of those before crediting, because a payment with one confirmation is not yet settled. Twenty minutes of nothing visible is therefore the system working rather than a fault. Your own wallet shows the transaction and its confirmation count immediately, which is where to look first. If the wallet shows it moving and the order does not, the payment exists and the wait is normal. If the wallet shows nothing at all, the transaction never left, which is a different and much simpler problem. ### What not to do - Do not send a second payment because the first has not appeared yet - Do not reuse a deposit address from an earlier order - Do not cancel and re-place the order while a payment is in flight ### Sent the wrong amount for an order - URL: https://blackops-urls.shop/issue/wrong-amount - Severity: Common - Area: Payments and deposits - Symptom: The deposit is short or larger than the order requires. - Likely cause: Network fee deducted from the sent amount, or a mistyped figure. Most shortfalls are not typing errors. They happen when the wallet deducts the network fee from the amount you entered rather than adding it on top, so slightly less arrives than the order expects. ### If you sent too little 1. Do not send a second payment blindly, since that can create a second unmatched deposit 2. Open a support message with the order reference and the exact amount sent 3. Wait for instructions rather than improvising, because the order is recoverable and a guessed fix may not be ### If you sent too much Usually the simpler case. The surplus normally lands on your balance, and you withdraw it. Raise it with support if it does not appear once confirmations complete. > Watch out: Set the fee to be added on top of the amount rather than taken out of it, or send a very small amount over the requested figure. That single wallet setting prevents most of these. ### Why fees cause most of these Wallets differ on one small setting. Some treat the figure you type as the amount to leave your balance, deducting the network fee from it, so slightly less arrives than you entered. Others add the fee on top, so the exact figure arrives. Neither is wrong, but the first quietly produces a shortfall on every order unless you account for it. The amounts involved are tiny, which is exactly why it catches people. An order sits unfunded over a difference smaller than the rounding on the price, and the cause is a wallet preference rather than anything either party did. ### What not to do - Do not top up with a second payment before asking, since two partial deposits are harder to reconcile than one - Do not assume a shortfall is theft, because the coin is on the chain and visible - Do not round the amount down to something tidier than the figure requested ### Order funded but stuck in pending - URL: https://blackops-urls.shop/issue/order-stuck - Severity: Common - Area: Orders and disputes - Symptom: Escrow is funded and the order has not moved for days. - Likely cause: The vendor has not marked dispatch, which is often just their schedule. A funded order sitting still normally means the vendor has not marked it as dispatched. That is not automatically a problem, since sellers batch their work and a stated dispatch window may not have passed yet. ### Steps in order 1. Re-read the listing for the stated dispatch window and count from when the order was funded, not when you placed it 2. Send one short polite message with the order reference asking for a dispatch update 3. Wait for the window plus a reasonable margin before escalating 4. Open a dispute if the window has clearly passed with no response > Watch out: Never confirm receipt to move things along. Confirming releases escrow to the vendor and removes your dispute route, which turns a slow order into an unprotected one. ### What escrow is doing meanwhile Your payment is sitting in 2 of 3 multisig and neither the vendor nor the market can move it alone. Time passing costs you patience rather than money, which is exactly why waiting is safe and confirming early is not. ### What a vendor day looks like Most sellers batch their work. Orders that arrive after a cutoff wait for the next run, and a stated dispatch window is written around that rhythm rather than around individual orders. An order sitting still for a day inside a stated two day window is not late, it is simply not its turn yet. This is why counting from the funding time matters. Escrow funds when confirmations complete, not when you clicked buy, and on a slow network that gap can be most of an hour. People frequently believe an order is a day older than it is. ### What not to do - Do not confirm receipt to encourage the vendor, since it removes your protection entirely - Do not send repeated messages, because a queue of them slows a reply rather than speeding it - Do not cancel and reorder while escrow is funded on the first order ### The vendor has stopped responding - URL: https://blackops-urls.shop/issue/vendor-silent - Severity: Serious - Area: Orders and disputes - Symptom: Messages go unanswered after an order was funded. - Likely cause: Vendor inactive, overloaded, or no longer operating. Silence for a day or two is common. Silence past the stated dispatch window with no explanation is a dispute, and the escrow exists precisely for this. ### Before opening a dispute - Send one clear message with the order reference and a specific question rather than several vague ones - Check the vendor profile for recent activity, since a seller absent from everything is different from one ignoring you - Note the dates, because a dispute is decided on what you can show > Watch out: Keep everything inside the market message system. A conversation moved to an outside channel cannot be cited in a dispute, which is the main reason to refuse when asked. ### Reducing the odds next time Read recent feedback rather than lifetime totals before ordering, since a profile can look excellent while the last month has been poor. Start small with any seller you have not used. ### Silence is not always the same thing A seller who is answering other buyers and ignoring you is behaving differently from one who has stopped appearing anywhere. The vendor profile usually shows recent activity, and that single check tells you whether you are dealing with a slow week or an absent operation. It also changes what a dispute looks like, because staff can see the same pattern. Sellers also disappear for reasons that have nothing to do with your order. What matters from your side is the record, which is why dates and a clear order reference are worth more in this situation than anything you write about how the exchange felt. ### What not to do - Do not move the conversation to an outside channel because it might get a faster reply - Do not confirm receipt in the hope that it prompts contact - Do not leave feedback describing the dispute before it has been decided ### A dispute is open and nothing is happening - URL: https://blackops-urls.shop/issue/dispute-stalled - Severity: Serious - Area: Orders and disputes - Symptom: The dispute was raised and there has been no visible movement. - Likely cause: Arbitration is queued, or the submitted case lacks dates and references. Disputes are read by people working through a queue. Movement is often slower than it feels, and the strongest thing you can do is make your case easy to read. ### What decides it Whoever is deciding has two accounts of the same order, whatever the market recorded, and both parties histories. They are looking for which version fits the record. Dates, order references and consistency do that work. Volume and tone do not. ### Write it like this 1. Open with the order reference and the key dates 2. State plainly what was ordered, what arrived and when 3. Quote the listing terms where they support you 4. Say what outcome you are asking for 5. Stop there, because length reads as anxiety rather than evidence > Watch out: Everything in the market message system counts. Anything discussed outside it effectively does not exist for the dispute, which is why order talk belongs on the market. ### If it stays frozen Add a short factual follow up rather than a longer version of the same case. Escrow is holding the funds in the meantime, so the delay costs time rather than money. ### How the deciding vote works Escrow needs two of three keys. In a normal order those are yours and the vendor. In a dispute the market key becomes the tiebreaker, which is the only point at which the market has any say over the money. It is a narrow power and it is the reason arbitration exists at all rather than the market simply refunding whoever complains loudest. Because it is a judgement between two accounts of the same order, the material that helps is the material that can be checked. Dates that line up, an order reference, listing terms quoted accurately. The material that does not help is a description of how unfair the situation feels, however true that is. ### What not to do - Do not submit the same case again in longer form while waiting - Do not threaten feedback as leverage, since it reads as pressure rather than evidence - Do not confirm receipt to close a dispute you think is going badly ## Guides ### First order on BlackOps, start to finish - URL: https://blackops-urls.shop/guide/first-order - Topic: Getting started - Summary: The whole path from a clean Tor Browser to a confirmed delivery on BlackOps, in the order you actually do it, with the mistakes that catch people marked out. Everything in the database is a thing that can go wrong. This is the path when nothing does, which is most of the time. ### 1. Get Tor Browser properly Download it only from the Tor Project site, verify the signature on the first install, and set the security level to Safest. An ordinary browser cannot open an onion address at all, and a copy from a forwarded link is not one to trust. ### 2. Open a verified address and check it Copy an address from this site rather than typing it. When the login screen appears, compare the onion printed on the page against your address bar. They match or you close the tab, and that check is the single most valuable habit here. ### 3. Set the account up once, properly A username used nowhere else, a long generated password from a local manager, the recovery phrase written on paper, and PGP two factor switched on. Ten minutes now, and a leaked password later stops being the end of the account. ### 4. Fund with Monero Hold the coin in your own wallet first rather than sending straight from an exchange. Open the order, copy its deposit address, send the exact amount with the fee added on top, and expect roughly twenty minutes for confirmations. ### 5. Read the vendor before you commit Recent feedback rather than lifetime totals, and how they answered complaints rather than how many stars they have. Start small with anybody untested. ### 6. Confirm only on delivery When the package arrives and matches, confirm receipt to release escrow. If it does not arrive or arrives wrong, open a dispute instead. Never confirm early to be polite or to speed anything up. ### What the first order is really teaching you The point of a first order is not the goods, it is finding out whether your process works. Did the address check become automatic. Did the deposit land the first time. Did the vendor do what the listing said. A small order answers all of that for the price of a small order, and a large one answers exactly the same questions for considerably more. That is why capping the first few is worth more than any other precaution here. Nobody loses money on their fifth order with a seller they have tested, and the database entries on this site are almost entirely populated by things that go wrong on a first attempt. ### Timing, honestly Expect the whole thing to be slower than an ordinary online purchase. Pages load through several relays, confirmations take around twenty minutes, and a vendor works to a dispatch window rather than to your schedule. None of that is a problem unless you treat it as one and start intervening, which is how people confirm orders early or send duplicate deposits. ### Funding an order with Monero without mistakes - URL: https://blackops-urls.shop/guide/monero-deposit - Topic: Payments - Summary: How to buy Monero, hold it in a wallet you control and fund a BlackOps order so the deposit lands the first time without a shortfall or a missing payment. BlackOps settles in Monero only. There is no Bitcoin option and no swap running behind the scenes, so the whole payment path runs through one coin. ### Getting the coin Buy on an exchange, trade peer to peer, or swap from a coin you already hold. Each attaches a different amount of identity at the point of purchase, and the right choice depends on what the coin is for. ### Hold it yourself first Move the Monero into a wallet you control before it goes anywhere near an order. Feather on desktop and Cake on a phone both route over Tor and both are straightforward. Whichever you pick, write the recovery seed on paper, because the seed is the wallet. ### The deposit itself 1. Open the order and copy the deposit address it issues for that order specifically 2. Set your wallet to add the network fee on top rather than take it out of the amount 3. Send, then wait for confirmations, which normally take around twenty minutes 4. Withdraw anything left over once the order completes rather than leaving a balance > Watch out: Two mistakes cause most deposit problems: reusing an older deposit address, and letting the wallet deduct the fee so slightly too little arrives. Both are avoidable in the wallet before you press send. ### Why the coin sits in your wallet first Sending straight from the place you bought the coin to the market draws a line between an identity checked account and an order. Moving it into a wallet you control first breaks that line, because what leaves your wallet is not traceable back through the exchange in the same way. It costs one extra step and a few minutes of waiting. It also gives you somewhere to put change. Orders rarely use a round number, and having a wallet you control means the remainder comes back somewhere sensible rather than sitting on the market waiting to become somebody else problem. ### The seed matters more than the software Every wallet worth using hands you a recovery seed at creation. Those words are the wallet. The application is replaceable, the machine is replaceable, the words are not. Write them on paper before you put anything real into the wallet, store them away from the device, and never type them into a page that asks. No legitimate service ever needs them. ### Setting up an account that survives a leak - URL: https://blackops-urls.shop/guide/account-security - Topic: Security - Summary: The account setup that makes a stolen BlackOps password useless, and the storage habits that keep you from locking yourself out. Account setup is cheap security. It takes ten minutes once and then protects the account for its whole life, which is a better return than anything else you can do here. ### A name that connects to nothing Not a variation of a handle from a forum, not something close to an old market account. Reuse is the single most common thread in people being identified, and it costs nothing to avoid at the start while being impossible to fix later. ### A password you did not invent Generate a long one in a local password manager. Invented passwords are shorter and more predictable than they feel, and a reused one means a breach somewhere unrelated becomes a breach here. ### Two factor, and its backup Turn PGP two factor on immediately so a stolen password alone opens nothing. Then back the key up offline the same day, because the database entry on lost keys exists for people who did the first part and skipped the second. ### The recovery phrase On paper, stored away from the machine, never typed into a web form. Any page asking for it during login is collecting accounts, without exception. ### Small balances Not strictly security setup but it belongs here. Deposit what the order needs and withdraw the rest, because funds sitting on any market are exposed to whatever happens to that market. ### Why reuse is the mistake that cannot be undone Passwords can be changed and keys can be rotated. A username that also exists on a forum you posted on for years cannot be unlinked afterwards, because the connection was made the moment both existed. This is the one setup decision with no repair path, which is why it belongs first rather than last. The same logic applies to writing style, timing patterns and anything else that travels between accounts, though those matter far less than the obvious case of literally reusing a name. Pick something with no history and keep it for this and nothing else. ### What good storage looks like - Password in a local manager, not in a browser synced to an account - Recovery phrase on paper, in a place you would still find it in six months - PGP key backed up offline the day you generate it, not eventually - Nothing about any of it in a note that syncs to a cloud service ### How escrow protects an order, and how people give it away - URL: https://blackops-urls.shop/guide/escrow-explained - Topic: Orders - Summary: What 2 of 3 multisig escrow actually does on BlackOps, how a dispute is weighed and decided, and the single action that removes the whole protection at once. Escrow is why somebody you have never met ships before being paid. On BlackOps it is 2 of 3 multisig, which means the payment sits in an address needing two of three keys to move. ### Who holds what You hold one key, the vendor holds one, the market holds one. The vendor can see the order is funded and cannot reach the money, and the market cannot quietly reassign it. That split is the whole protection. ### The normal path Fund the order, the coin locks into escrow, the vendor ships, and when the package arrives and matches you confirm receipt. Your key with the vendor key releases the payment and the order closes. ### When it goes wrong Open a dispute instead of confirming. The market key becomes the deciding vote and staff weigh what each side shows against the vendor record. A short factual case with dates and an order reference beats a long argument every time. > Watch out: Finalising early releases the payment before the goods arrive and deletes the dispute route in the same click. On a seller you have not tested there is no version of this that is worth the risk, whatever reason is offered. ### What escrow does not cover Escrow protects the payment attached to an order. It does nothing for a balance you left on the market outside one, which is the largest single category of loss around markets generally. Deposit for the order in front of you and withdraw the rest, and the protection you are relying on actually covers the money you have at risk. It also does not make a seller reliable. A vendor can be perfectly honest and still ship late, or ship the wrong thing, and escrow only gives you a route to argue about it afterwards. Reading a seller record before ordering is the part that reduces how often you need that route at all. ### Why early release is asked for Sellers ask because escrow ties up their working capital until you confirm. That is a real cost to them and an understandable request from an established vendor with hundreds of clean orders behind them. From a young shop, the same request is the standard opening move of somebody who does not intend to ship. Since you cannot tell the difference reliably, treating it as a blanket policy is simpler and costs you nothing. ### Switching addresses without walking into a clone - URL: https://blackops-urls.shop/guide/switching-address - Topic: Access - Summary: Why BlackOps runs several onion addresses, what stays the same when you switch, and the search that costs people their accounts. BlackOps publishes several onion addresses and all of them open the same market. Same account, same balance, same open orders behind each one. ### Why more than one A hidden service absorbs floods. One address means an attack closes the market for everybody until it passes. Several means the attacker has to hold all of them at once, which is a much harder job, and a slow address becomes an inconvenience instead of an outage. ### What switching changes Nothing you care about. You are walking through a different door into the same building, so an order funded on one address is the same order on another. There is no migration and nothing to transfer. ### The dangerous moment Not the outage, the search that follows it. Somebody finds their usual address quiet, looks for a replacement, and takes whatever a result offers. That sequence causes almost every phishing loss around markets like this. > Watch out: Bookmark a verified source so the alternative is already in front of you. Then the outage becomes boring, which is exactly what you want it to be. ### Why an address changes at all Operators rotate addresses to spread load and to make a sustained flood harder to maintain. A target that moves is more expensive to attack than one that does not. From the outside this looks like instability and is closer to the opposite, since a market with only one address has nothing to rotate and nowhere to send you when that address is hit. It also means an address you saved a long time ago may be retired rather than fake. The safe habit is to check any stored address against a verified source before using it, rather than assuming either that it still works or that it has been stolen. ### Bookmarks beat memory Fifty six characters is beyond what anybody reliably recalls, and partial recall is worse than none, because a nearly correct address is exactly what a lookalike is registered to catch. Save a verified source, use it every time, and the question of what the address is stops being something you have to answer under pressure. ## Questions and answers **What is the current BlackOps URL?** There is no single permanent address and nothing on the ordinary web. BlackOps publishes several onion addresses that all open the same market. Copy one from the addresses block on this page and confirm it on the login screen before typing anything. **Why will the site not load for me?** Usually a tired Tor circuit or a flood on that one address. Request a new circuit, restart Tor Browser if that fails, then try another verified address. The database entry on loading problems walks through it. **Which coin does BlackOps accept?** Monero only. There is no Bitcoin option and no background swap, so the whole payment path runs through one coin. **How do I know the page is real?** Compare the onion printed on the login screen against your browser address bar. A clone can copy the design perfectly and cannot show the real address while living at its own. If they differ, close the tab. **My deposit has not appeared. Is it lost?** Almost certainly not. Monero confirmations take around twenty minutes and markets wait for several before crediting. Check you used the address issued for that specific order before treating it as a problem. **The vendor is not replying. What now?** Wait out the stated dispatch window, send one clear message with the order reference, then open a dispute if the window has clearly passed. Do not confirm receipt to speed things up. **Should I ever confirm an order early?** No, not on a seller you have not tested. Confirming releases escrow and removes the dispute route at the same moment, which turns a protected order into an unprotected one. **I lost my PGP key with two factor enabled.** Look for a backup first, including old machines and encrypted archives. Back the key up offline the day you create it, because a key that exists in one place is one you will eventually lose. **Does this site take payments or track visitors?** No. It publishes verified addresses and a database of fixes. There is no account, no payment, no advertising and nothing collected about visitors, and it is not the market itself. **Will a login ever ask for my recovery phrase?** Never. A page asking for it is harvesting accounts. Store the phrase on paper, never type it into a web form, and treat any request for it as proof the page is fake.