OPERATING MANUAL
Mandatory reading for all new operatives. Failure to follow these protocols may result in loss of funds or compromised identity.
SECURE ENVIRONMENT INITIALIZATION
Before accessing any Darknet Market, you must secure your network perimeter. Standard browsers (Chrome, Safari) leak your IP address.
- Download Tor Browser: Only from the official project site. Never use third-party bundles.
- Security Level: Go to
Settings > Privacy & Securityand set the security level to "Safer". This disables JavaScript on non-HTTPS sites, which is critical for Drughub security. - Window Size: Do not maximize your Tor window. This prevents "fingerprinting" based on your screen resolution.
ACQUIRING MONERO (XMR)
Drughub Market operates exclusively on Monero. Bitcoin (BTC) is a transparent ledger and is no longer safe for darkweb transactions.
The Exchange Protocol:
- Fiat to Crypto: Buy Litecoin (LTC) or Bitcoin (BTC) on a regulated exchange (e.g., Coinbase, Kraken).
- The Swap: Use a non-KYC exchange (like Trocador or MajesticBank) to swap your BTC/LTC into Monero (XMR).
- The Wallet: Send the XMR to your personal wallet first (e.g., Cake Wallet or Monero GUI).
- The Deposit: Only send from your personal wallet to your unique Drughub deposit address. Never send directly from an exchange.
COMMUNICATION SECURITY (PGP)
Pretty Good Privacy (PGP) is non-negotiable. You must use it to encrypt your shipping address and enable 2FA Login.
Required Software:
Windows users should use Kleopatra (Gpg4win). MacOS users should use GPG Suite.
1. Copy the Vendor's Public Key into Kleopatra. 2. Type your address in Notepad: "John Doe, 123 Main St..." 3. Copy text -> Tools -> Clipboard -> Encrypt. 4. Select Vendor's Key -> Click Next. 5. Paste the output block into the order form.
Never send your address in plain text. If the market is seized, your data will be exposed.
FINALIZING THE TRANSACTION
Once your wallet is funded and PGP is set, you are ready to place an order on Drughub.
The Escrow Lifecycle:
When you click "Buy", your XMR moves to a multisig Escrow wallet. The vendor can see the order but cannot touch the funds.
- Processing: Vendor accepts order and ships.
- In Transit: You wait for delivery. Auto-finalize timer is set to 14 days.
- Finalize: Once received, mark the order as "Finalized" to release funds to the vendor.
- Dispute: If the package does not arrive, click "Dispute" before the timer runs out.
MOBILE PROTOCOLS (ANDROID)
While a desktop environment (Tails OS or Linux) is recommended for maximum security, Drughub Market is fully responsive for mobile access. iOS (iPhone) is strictly prohibited due to closed-source telemetry.
Android Configuration:
- Browser: Install Tor Browser for Android directly from the F-Droid repository or .apk download. Do not trust Google Play Store versions blindly.
- Wallet: Use Cake Wallet or Monerujo. These allow you to manage XMR seeds locally without relying on a custodial server.
- Input Hygiene: Disable "Predictive Text" and "Gboard Cloud Sync" in your keyboard settings to prevent your typing history (search queries, passwords) from being uploaded to Google servers.
DECRYPTING 2FA CHALLENGES
Upon logging in, you may be presented with an encrypted PGP block. This is a 2FA Challenge. You must prove you own the PGP key linked to your account.
1. Copy the entire PGP block starting with "-----BEGIN PGP MESSAGE-----". 2. Open Kleopatra (or GPG Suite). 3. Go to "Notepad" or "Clipboard" tab. 4. Paste the block and click "Decrypt/Verify". 5. Enter your PGP passphrase. 6. Copy the revealed 6-digit code (e.g., 849201) back into the website.
If you lose your private PGP key, you will permanently lose access to your account and wallet. Support cannot reset PGP keys.
TROUBLESHOOTING DEPOSITS
If your Monero (XMR) deposit has not appeared in your balance after 60 minutes, follow this diagnostic protocol before contacting support.
Checklist:
- Confirmations: Monero requires 10 confirmations on the blockchain. Check your transaction ID (TXID) on a block explorer like XMRChain.net (via Tor).
- Phishing Check: Did you verify the URL? If you deposited funds on a phishing link, the money is gone. Always verify the PGP signature in the Access Section.
- Sync Status: If using a local wallet, ensure your node is fully synchronized with the network height.
WHY FOLLOW THE MANUAL?
The Darknet is unforgiving. One mistake with Javascript settings or a leaked IP can compromise your OpSec. This guide is designed to mitigate risks associated with market volatility and phishing.
By using Monero and PGP 2FA, you render yourself invisible to blockchain analysis and account takeovers. Review the OPSEC section for advanced threat modeling.