Nexus Loss Table Ranked by expected cost, not by how frightening it sounds
Table › How money goes

Nexus addresses

Three published addresses for the same market. Copy rather than retype.

nexusb2l73qzjn4slhyfxa3jvpolw7fomiz5sgyyefnsdhikaqgborqd.onion
nexusma2iqgauqqvjcgds4ckv5xbf272tkfagq4epojjhsgleqpwxiqd.onion
nexusabcdrwy7632jfmkfu3f6u7usyw2xn2mcfiljunz6zsj4p5vioqd.onion

This list is published, not monitored. An address that opens is not an address that is genuine.

An address swapped on your own machine

The only entry here that is inside rather than outside, and the only one the main defence on this site does nothing about.

How often
Uncommon
Typical size
One payment, in full
Recoverable
Never
Cost to prevent
Three seconds
Why the main defence misses itChecking a signature establishes that the destination you reached is genuine. It says nothing about what your own machine did with a string afterwards. This check assumes a trustworthy local machine and cannot establish one.

What is happening

Something running locally watches for anything address shaped and replaces it between the copy and the paste. It costs nothing to run against many machines at once, so a low success rate is still worth somebody's while, which is why this has existed unchanged for years and will continue to.

The check that catches it

Compare the first and last several characters of what actually landed in the field against the source. The ends, not the middle, because a substitution replaces the whole string rather than resembling it.

SituationWhich part to compare
An address from a page or a messageThe middle. A forgery resembles the original and differs where reading stops.
What appeared after you pastedThe ends. A substitution replaces everything.
Either, done properlyPaste both strings somewhere that reports an exact match.

This is the only place on the site where checking the ends is the right check, and it applies to payment destinations as much as to addresses in a browser bar.

Where it comes from

If a payment already went

It is not recoverable, and the machine is the problem rather than the platform. Treat anything else on that machine as suspect, including saved wallet files, and do not repeat the payment from the same system. This is one of the few entries where the honest answer is that the loss is final and the useful action is preventing the next one.

Why this one breaks the site's own model

Everything else here assumes your machine reports honestly what it received and what it sent. Signature checks, address comparisons and careful reading all run on that machine and are only as reliable as it is. If the machine is lying, the checks return whatever it wants them to return.

That is a genuine hole rather than an oversight, and it is why the habits page states plainly that nothing in it closes this entry. Advice that claimed otherwise would be selling comfort.

What raises the odds

SituationWhy it matters
Software installed for this activity specificallyA category with a strong incentive to be malicious and a weak norm of verification
Anything obtained outside official channelsIncluding repacks, mirrors and helpful reuploads
A machine shared with other peopleTheir installs are your exposure
A machine used for years without a rebuildAccumulation, rather than any single decision

The two habits that reduce it

Check the ends of every destination after pasting, every time, including the small payments where it feels excessive. And keep the number of things installed on the machine used for this small, because every install is a decision to trust somebody, and the useful question is not whether a given piece of software is malicious but how many such decisions you are currently carrying.